Google Cloud IAM
Identity and Access Management controls authentication and authorization for Google Cloud resources and service accounts.
Authentication
| Method | Kind | Status | Details |
|---|---|---|---|
| OAuth 2.0 | oauth2 | available | — |
Call a tool
import { createClient } from "@open-connector/sdk";const oc = createClient({ baseUrl: "https://api.openconnector.dev", apiKey: process.env.OPEN_CONNECTOR_API_KEY!,});const result = await oc.executeTool({ slug: "GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY", connectedAccountId: "conn_...", arguments: { /* match this tool's input schema */ },});import Composio from "@composio/client";const composio = new Composio({ baseURL: "https://api.openconnector.dev/composio", apiKey: process.env.OPEN_CONNECTOR_API_KEY!,});const result = await composio.tools.execute("GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY", { connected_account_id: "conn_...", arguments: { /* match this tool's input schema */ },});oc tools execute GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY --data '{ }'Tool catalog
Available tools
19 callable operations
Iam IamPolicies LintPolicyGOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICYLints, or validates, an IAM policy. Currently checks the google.iam.v1.Binding.condition field, which contains a condition expression for a role binding. Successful calls to this method always return an HTTP `200 OK` status code, even if the linter detects an issue in the IAM policy.Connection1 scope
Lints, or validates, an IAM policy. Currently checks the google.iam.v1.Binding.condition field, which contains a condition expression for a role binding. Successful calls to this method always return an HTTP `200 OK` status code, even if the linter detects an issue in the IAM policy.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_LISTLists all non-deleted WorkforcePools under the specified parent. If `show_deleted` is set to `true`, then deleted pools are also listed.Connection1 scope
Lists all non-deleted WorkforcePools under the specified parent. If `show_deleted` is set to `true`, then deleted pools are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools Providers ScimTenants ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_PROVIDERS_SCIM_TENANTS_LISTGemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTenants in a WorkforcePoolProvider. If `show_deleted` is set to `true`, then deleted SCIM tenants are also listed.Connection1 scope
Gemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTenants in a WorkforcePoolProvider. If `show_deleted` is set to `true`, then deleted SCIM tenants are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools Providers ScimTenants Tokens ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_PROVIDERS_SCIM_TENANTS_TOKENS_LISTGemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTokenss in a WorkforcePoolProviderScimTenant. If `show_deleted` is set to `true`, then deleted SCIM tokens are also listed.Connection1 scope
Gemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTokenss in a WorkforcePoolProviderScimTenant. If `show_deleted` is set to `true`, then deleted SCIM tokens are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Permissions QueryTestablePermissionsGOOGLE_CLOUD_IAM_PERMISSIONS_QUERY_TESTABLE_PERMISSIONSLists every permission that you can test on a resource. A permission is testable if you can check whether a principal has that permission on the resource.Connection1 scope
Lists every permission that you can test on a resource. A permission is testable if you can check whether a principal has that permission on the resource.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations OauthClients ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_OAUTH_CLIENTS_LISTLists all non-deleted OauthClients in a project. If `show_deleted` is set to `true`, then deleted OauthClients are also listed.Connection1 scope
Lists all non-deleted OauthClients in a project. If `show_deleted` is set to `true`, then deleted OauthClients are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools GetIamPolicyGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_GET_IAM_POLICYGets the IAM policy of a WorkloadIdentityPool.Connection1 scope
Gets the IAM policy of a WorkloadIdentityPool.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_LISTLists all non-deleted WorkloadIdentityPools in a project. If `show_deleted` is set to `true`, then deleted pools are also listed.Connection1 scope
Lists all non-deleted WorkloadIdentityPools in a project. If `show_deleted` is set to `true`, then deleted pools are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_LISTLists all non-deleted WorkloadIdentityPoolNamespaces in a workload identity pool. If `show_deleted` is set to `true`, then deleted namespaces are also listed.Connection1 scope
Lists all non-deleted WorkloadIdentityPoolNamespaces in a workload identity pool. If `show_deleted` is set to `true`, then deleted namespaces are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ManagedIdentities ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_MANAGED_IDENTITIES_LISTLists all non-deleted WorkloadIdentityPoolManagedIdentitys in a namespace. If `show_deleted` is set to `true`, then deleted managed identities are also listed.Connection1 scope
Lists all non-deleted WorkloadIdentityPoolManagedIdentitys in a namespace. If `show_deleted` is set to `true`, then deleted managed identities are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ManagedIdentities ListAttestationRulesGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_MANAGED_IDENTITIES_LIST_ATTESTATION_RULESList all AttestationRule on a WorkloadIdentityPoolManagedIdentity.Connection1 scope
List all AttestationRule on a WorkloadIdentityPoolManagedIdentity.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Providers Keys ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_PROVIDERS_KEYS_LISTLists all non-deleted WorkloadIdentityPoolProviderKeys in a project. If show_deleted is set to `true`, then deleted pools are also listed.Connection1 scope
Lists all non-deleted WorkloadIdentityPoolProviderKeys in a project. If show_deleted is set to `true`, then deleted pools are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Providers ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_PROVIDERS_LISTLists all non-deleted WorkloadIdentityPoolProviders in a WorkloadIdentityPool. If `show_deleted` is set to `true`, then deleted providers are also listed.Connection1 scope
Lists all non-deleted WorkloadIdentityPoolProviders in a WorkloadIdentityPool. If `show_deleted` is set to `true`, then deleted providers are also listed.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools TestIamPermissionsGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_TEST_IAM_PERMISSIONSReturns the caller's permissions on a WorkloadIdentityPoolConnection1 scope
Returns the caller's permissions on a WorkloadIdentityPool
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Roles ListGOOGLE_CLOUD_IAM_PROJECTS_ROLES_LISTLists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.Connection1 scope
Lists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects ServiceAccounts Keys ListGOOGLE_CLOUD_IAM_PROJECTS_SERVICE_ACCOUNTS_KEYS_LISTLists every ServiceAccountKey for a service account.Connection1 scope
Lists every ServiceAccountKey for a service account.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects ServiceAccounts ListGOOGLE_CLOUD_IAM_PROJECTS_SERVICE_ACCOUNTS_LISTLists every ServiceAccount that belongs to a specific project.Connection1 scope
Lists every ServiceAccount that belongs to a specific project.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Roles ListGOOGLE_CLOUD_IAM_ROLES_LISTLists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.Connection1 scope
Lists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Roles QueryGrantableRolesGOOGLE_CLOUD_IAM_ROLES_QUERY_GRANTABLE_ROLESLists roles that can be granted on a Google Cloud resource. A role is grantable if the IAM policy for the resource can contain bindings to the role.Connection1 scope
Lists roles that can be granted on a Google Cloud resource. A role is grantable if the IAM policy for the resource can contain bindings to the role.
Authentication
Connected account requiredScopes
https://www.googleapis.com/auth/cloud-platformTags