Google Cloud IAM
Identity and Access Management controls authentication and authorization for Google Cloud resources and service accounts.
认证方式
| 方式 | 底层类型 | 状态 | 说明 |
|---|---|---|---|
| OAuth 2.0 | oauth2 | available | — |
调用示例
import { createClient } from "@open-connector/sdk";const oc = createClient({ baseUrl: "https://api.openconnector.dev", apiKey: process.env.OPEN_CONNECTOR_API_KEY!,});const result = await oc.executeTool({ slug: "GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY", connectedAccountId: "conn_...", arguments: { /* match this tool's input schema */ },});import Composio from "@composio/client";const composio = new Composio({ baseURL: "https://api.openconnector.dev/composio", apiKey: process.env.OPEN_CONNECTOR_API_KEY!,});const result = await composio.tools.execute("GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY", { connected_account_id: "conn_...", arguments: { /* match this tool's input schema */ },});oc tools execute GOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICY --data '{ }'Tool 目录
可用 Tools
19 个可调用操作
Iam IamPolicies LintPolicyGOOGLE_CLOUD_IAM_IAM_POLICIES_LINT_POLICYLints, or validates, an IAM policy. Currently checks the google.iam.v1.Binding.condition field, which contains a condition expression for a role binding. Successful calls to this method always return an HTTP `200 OK` status code, even if the linter detects an issue in the IAM policy.需要连接1 scope
Lints, or validates, an IAM policy. Currently checks the google.iam.v1.Binding.condition field, which contains a condition expression for a role binding. Successful calls to this method always return an HTTP `200 OK` status code, even if the linter detects an issue in the IAM policy.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_LISTLists all non-deleted WorkforcePools under the specified parent. If `show_deleted` is set to `true`, then deleted pools are also listed.需要连接1 scope
Lists all non-deleted WorkforcePools under the specified parent. If `show_deleted` is set to `true`, then deleted pools are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools Providers ScimTenants ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_PROVIDERS_SCIM_TENANTS_LISTGemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTenants in a WorkforcePoolProvider. If `show_deleted` is set to `true`, then deleted SCIM tenants are also listed.需要连接1 scope
Gemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTenants in a WorkforcePoolProvider. If `show_deleted` is set to `true`, then deleted SCIM tenants are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Locations WorkforcePools Providers ScimTenants Tokens ListGOOGLE_CLOUD_IAM_LOCATIONS_WORKFORCE_POOLS_PROVIDERS_SCIM_TENANTS_TOKENS_LISTGemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTokenss in a WorkforcePoolProviderScimTenant. If `show_deleted` is set to `true`, then deleted SCIM tokens are also listed.需要连接1 scope
Gemini Enterprise only. Lists all non-deleted WorkforcePoolProviderScimTokenss in a WorkforcePoolProviderScimTenant. If `show_deleted` is set to `true`, then deleted SCIM tokens are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Permissions QueryTestablePermissionsGOOGLE_CLOUD_IAM_PERMISSIONS_QUERY_TESTABLE_PERMISSIONSLists every permission that you can test on a resource. A permission is testable if you can check whether a principal has that permission on the resource.需要连接1 scope
Lists every permission that you can test on a resource. A permission is testable if you can check whether a principal has that permission on the resource.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations OauthClients ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_OAUTH_CLIENTS_LISTLists all non-deleted OauthClients in a project. If `show_deleted` is set to `true`, then deleted OauthClients are also listed.需要连接1 scope
Lists all non-deleted OauthClients in a project. If `show_deleted` is set to `true`, then deleted OauthClients are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools GetIamPolicyGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_GET_IAM_POLICYGets the IAM policy of a WorkloadIdentityPool.需要连接1 scope
Gets the IAM policy of a WorkloadIdentityPool.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_LISTLists all non-deleted WorkloadIdentityPools in a project. If `show_deleted` is set to `true`, then deleted pools are also listed.需要连接1 scope
Lists all non-deleted WorkloadIdentityPools in a project. If `show_deleted` is set to `true`, then deleted pools are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_LISTLists all non-deleted WorkloadIdentityPoolNamespaces in a workload identity pool. If `show_deleted` is set to `true`, then deleted namespaces are also listed.需要连接1 scope
Lists all non-deleted WorkloadIdentityPoolNamespaces in a workload identity pool. If `show_deleted` is set to `true`, then deleted namespaces are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ManagedIdentities ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_MANAGED_IDENTITIES_LISTLists all non-deleted WorkloadIdentityPoolManagedIdentitys in a namespace. If `show_deleted` is set to `true`, then deleted managed identities are also listed.需要连接1 scope
Lists all non-deleted WorkloadIdentityPoolManagedIdentitys in a namespace. If `show_deleted` is set to `true`, then deleted managed identities are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Namespaces ManagedIdentities ListAttestationRulesGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_NAMESPACES_MANAGED_IDENTITIES_LIST_ATTESTATION_RULESList all AttestationRule on a WorkloadIdentityPoolManagedIdentity.需要连接1 scope
List all AttestationRule on a WorkloadIdentityPoolManagedIdentity.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Providers Keys ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_PROVIDERS_KEYS_LISTLists all non-deleted WorkloadIdentityPoolProviderKeys in a project. If show_deleted is set to `true`, then deleted pools are also listed.需要连接1 scope
Lists all non-deleted WorkloadIdentityPoolProviderKeys in a project. If show_deleted is set to `true`, then deleted pools are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools Providers ListGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_PROVIDERS_LISTLists all non-deleted WorkloadIdentityPoolProviders in a WorkloadIdentityPool. If `show_deleted` is set to `true`, then deleted providers are also listed.需要连接1 scope
Lists all non-deleted WorkloadIdentityPoolProviders in a WorkloadIdentityPool. If `show_deleted` is set to `true`, then deleted providers are also listed.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Locations WorkloadIdentityPools TestIamPermissionsGOOGLE_CLOUD_IAM_PROJECTS_LOCATIONS_WORKLOAD_IDENTITY_POOLS_TEST_IAM_PERMISSIONSReturns the caller's permissions on a WorkloadIdentityPool需要连接1 scope
Returns the caller's permissions on a WorkloadIdentityPool
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects Roles ListGOOGLE_CLOUD_IAM_PROJECTS_ROLES_LISTLists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.需要连接1 scope
Lists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects ServiceAccounts Keys ListGOOGLE_CLOUD_IAM_PROJECTS_SERVICE_ACCOUNTS_KEYS_LISTLists every ServiceAccountKey for a service account.需要连接1 scope
Lists every ServiceAccountKey for a service account.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Projects ServiceAccounts ListGOOGLE_CLOUD_IAM_PROJECTS_SERVICE_ACCOUNTS_LISTLists every ServiceAccount that belongs to a specific project.需要连接1 scope
Lists every ServiceAccount that belongs to a specific project.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Roles ListGOOGLE_CLOUD_IAM_ROLES_LISTLists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.需要连接1 scope
Lists every predefined Role that IAM supports, or every custom role that is defined for an organization or project.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags
Iam Roles QueryGrantableRolesGOOGLE_CLOUD_IAM_ROLES_QUERY_GRANTABLE_ROLESLists roles that can be granted on a Google Cloud resource. A role is grantable if the IAM policy for the resource can contain bindings to the role.需要连接1 scope
Lists roles that can be granted on a Google Cloud resource. A role is grantable if the IAM policy for the resource can contain bindings to the role.
认证
需要 Connected AccountScopes
https://www.googleapis.com/auth/cloud-platformTags