gcloud auth
Stay organized with collections
Save and categorize content based on your preferences.
- NAME
-
- gcloud auth - manage oauth2 credentials for the Google Cloud CLI
- SYNOPSIS
-
-
gcloud authGROUP|COMMAND[GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
The
gcloud authcommand group lets you grant and revoke authorization to Google Cloud CLI (gcloudCLI) to access Google Cloud. Typically, when scripting Google Cloud CLI tools for use on multiple machines, usinggcloud auth activate-service-accountis recommended.For information about authorization and credential types, see Authorizing the gcloud CLI. For information about authorizing a service account, see Authorizing with a service account.
After running
gcloud authcommands, you can run other commands with--account=to authenticate the command with the credentials of the specified account. For information aboutACCOUNT--accountand othergcloudCLI global flags, see the gcloud CLI overview.See
$ gcloud topic client-certificateto learn how to use Mutual TLS when using gcloud. Mutual TLS can be used for certificate based access with gcloud. - EXAMPLES
-
To authenticate a user account with
gcloudand minimal user output, run:gcloudauthlogin --briefTo list all credentialed accounts and identify the current active account, run:
gcloudauthlistTo revoke credentials for a user account (like logging out), run:
gcloudauthrevoketest@gmail.com - GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--help.Run
$ gcloud helpfor details. - GROUPS
-
is one of the following:GROUPapplication-default- Manage your active Application Default Credentials.
enterprise-certificate-config- Manage enterprise certificate configurations.
- COMMANDS
-
is one of the following:COMMANDactivate-service-account- Authorize access to Google Cloud with a service account.
configure-docker-
Register
gcloudas a Docker credential helper. list- Lists credentialed accounts.
login- Authorize gcloud to access the Cloud Platform with Google user credentials.
print-access-token- Print an access token for the specified account.
print-identity-token- Print an identity token for the specified account.
revoke- Revoke access credentials for an account.
- NOTES
-
These variants are also available:
gcloudalphaauthgcloudbetaauth