Stay organized with collections Save and categorize content based on your preferences.
gcloud beta auth application-default print-access-token
[--lifetime
=LIFETIME
] [--scopes
=SCOPE
,[SCOPE
,…]] [GCLOUD_WIDE_FLAG …
]
(BETA)
gcloud beta auth application-default print-access-token generates and prints an access token for the current Application Default Credential (ADC). The ADC can be specified either by using gcloud auth application-default login
, gcloud auth login --cred-file=/path/to/cred/file --update-adc
, or by setting the GOOGLE_APPLICATION_CREDENTIALS
environment variable.
The access token generated by gcloud beta auth application-default print-access-token is useful for manually testing APIs via curl or similar tools.
In order to print details of the access token, such as the associated account and the token's expiration time in seconds, run:
curl -H "Content-Type: application/x-www-form-urlencoded" -d "access_token=$(gcloud auth application-default print-access-token)" https://www.googleapis.com/oauth2/v1/tokeninfo
Note that token itself may not be enough to access some services. If you use the token with curl or similar tools, you may see permission errors similar to "Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell". If it happens, you may need to provide a quota project in the "X-Goog-User-Project" header. For example,
curl -H "X-Goog-User-Project: your-project" -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" foo.googleapis.com
The identity that granted the token must have the serviceusage.services.use permission on the provided project. See https://cloud.google.com/apis/docs/system-parameters for more information.
--lifetime
=LIFETIME
constraints/iam.allowServiceAccountCredentialLifetimeExtension
must be set if you want to extend the lifetime beyond 3600 seconds. Note that this flag is for service account impersonation only, so it only works when either --impersonate-service-account
flag or auth/impersonate_service_account
property is set.
--scopes
=SCOPE
,[SCOPE
,…]
For end-user accounts, the provided scopes must be from [openid
, https://www.googleapis.com/auth/userinfo.email
, https://www.googleapis.com/auth/cloud-platform
, https://www.googleapis.com/auth/sqlservice.login
], or the scopes previously specified through gcloud auth application-default login --scopes
.
--access-token-file
, --account
, --billing-project
, --configuration
, --flags-file
, --flatten
, --format
, --help
, --impersonate-service-account
, --log-http
, --project
, --quiet
, --trace-token
, --user-output-enabled
, --verbosity
.
Run $ gcloud help
for details.
gcloud auth application-default print-access-token
gcloud alpha auth application-default print-access-token
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-05-07 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-05-07 UTC."],[],[]]
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4