If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/docs/authentication/tokens - Tokens overview  |  Authentica.

site address: docs.cloud.google.com/docs/authentication/tokens redirected to: docs.cloud.google.com/docs/authentication/tokens

site title: Tokens overview     Authentication     Google Cloud Documentation

Our opinion (on Tuesday 21 July 2026 10:59:00 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=Learn about the types of tokens that Google Cloud issues, their purpose, and how they are used.;

Headings (most frequently used words):

and, authentication, tokens, overview, stay, organized, with, collections, save, categorize, content, based, on, your, preferences, user, workload, authorization, servers, what, next, products, pricing, support, resources, engage,

Text of the page (most frequently used words):
the (76), google (46), and (41), cloud (39), client (27), user (24), #authentication (23), principal (18), authorization (17), identity (17), cli (15), with (14), workload (14), using (13), gcloud (13), for (12), token (12), api (12), authenticate (11), account (10), following (10), server (10), application (10), overview (10), service (9), apis (9), other (8), use (8), that (8), thumb (7), iam (7), behalf (7), this (6), servers (6), services (6), management (6), tokens (6), they (6), libraries (6), manage (5), code (5), resources (5), information (5), need (5), their (5), access (5), com (5), sdk (5), development (5), português (4), español (4), down (4), are (4), who (4), authenticates (4), has (4), similar (4), can (4), pool (4), workforce (4), credentials (4), federation (4), identifier (4), clients (4), act (4), interact (4), tools (4), keys (4), sign (3), samples (3), all (3), products (3), more (3), content (3), types (3), regions (3), global (3), from (3), security (3), because (3), specific (3), issue (3), which (3), own (3), data (3), storage (3), instead (3), you (3), console (3), based (3), guides (3), default (3), environment (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), terms (2), site (2), about (2), youtube (2), started (2), support (2), pricing (2), see (2), understand (2), last (2), updated (2), 2026 (2), utc (2), licensed (2), under (2), its (2), license (2), send (2), feedback (2), read (2), available (2), any (2), not (2), both (2), oauth (2), type (2), shared (2), different (2), properties (2), used (2), facilities (2), googleapis (2), locations (2), subject (2), pool_id (2), referred (2), workloads (2), users (2), authorize (2), must (2), work (2), interacts (2), rely (2), involves (2), parties (2), authenticating (2), authorizing (2), step (2), encodes (2), example (2), might (2), without (2), human (2), provider (2), request (2), directly (2), when (2), don (2), document (2), want (2), how (2), works (2), your (2), documentation (2), languages (2), frameworks (2), infrastructure (2), costs (2), usage (2), observability (2), monitoring (2), networking (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), pipelines (2), compute (2), hosting (2), managing (2), best (2), practices (2), configure (2), get (2), methods (2), cross (2), product (2), reference (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, events, blog, engage, training, certification, architecture, center, getting, github, system, status, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, otherwise, noted, page, details, java, registered, trademark, oracle, affiliates, developers, policies, apache, creative, commons, attribution, signing, what, next, optimize, reliability, whenever, possible, select, accessed, however, contain, deployments, region, metadata, sts, consumer, managed, saml, principals, split, uses, two, one, table, describes, related, such, shares, include, provided, openid, connect, projects, workloadidentitypools, subject_attribute_value, project_name, serviceaccount, project, gserviceaccount, authenticated, also, but, identifiers, than, acting, unattended, unlike, combines, into, single, only, some, scheduled, job, bigquery, being, involved, workforcepools, raha, altostrat, external, alex, themselves, acts, assurance, allowed, makes, requests, check, have, permission, passed, through, form, included, each, web, desktop, utility, like, curl, know, process, selecting, right, obtaining, refreshing, those, handled, automatically, cover, multiple, intended, people, learn, implement, save, categorize, preferences, stay, organized, collections, home, uninstalling, components, packages, scripting, commands, cheat, sheet, develop, enable, accessibility, features, configurations, behind, proxy, firewall, initialize, cases, reauthentication, verification, requirement, troubleshoot, adc, setup, premises, another, containerized, resource, attached, local, set, impersonation, rest, ways, homebrew, installer, versioned, archives, snap, package, migrate, stable, image, docker, installation, install, explained, discover, start, free, skip, main,


Text of the page (random words):
tokens overview authentication google cloud documentation skip to main content technology areas close ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage cross product tools close access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools console english deutsch español español américa latina français indonesia italiano português português brasil עברית 中文 简体 中文 繁體 日本語 한국어 sign in google cloud sdk authentication start free overview guides reference resources technology areas more overview guides reference resources cross product tools more console discover google cloud sdk overview gcloud cli overview cloud client libraries overview client libraries and cloud apis explained get started install the gcloud cli other installation methods using docker overview migrate to the stable image using a snap package using versioned archives using the installer using homebrew authenticate to google cloud authentication methods at google ways to authenticate authenticate for using client libraries authenticate for using rest authenticate by using service account impersonation application default credentials set up application default credentials overview local development environment resource with an attached service account containerized environment on premises or another cloud provider cloud based development environment how application default credentials works troubleshoot your adc setup api keys use api keys to access apis manage api keys best practices for managing api keys get an id token tokens overview token types 2 step verification requirement reauthentication authentication use cases identity management products configure the gcloud cli initialize the gcloud cli authenticate for the gcloud cli configure the gcloud cli for use behind a proxy or firewall manage gcloud cli configurations manage gcloud cli properties enable accessibility features develop gcloud cli cheat sheet scripting gcloud cli commands client libraries best practices manage packages in gcloud cli managing gcloud cli components uninstalling the gcloud cli ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation application development google cloud sdk authentication guides send feedback tokens overview stay organized with collections save and categorize content based on your preferences this document and the token types document cover the multiple tokens used by google cloud for authentication and authorization they re intended for people who want to learn how token based authentication works or who want to implement authentication without using the cloud client libraries you don t need to know this information when you interact with google cloud apis using the cloud client libraries the google cloud console or the google cloud cli the process of selecting the right type of token and obtaining and refreshing those tokens is handled automatically for you user authentication when human users interact with google cloud they don t interact with google cloud apis directly instead they use a client to act on their behalf the client that they use might be a web application a desktop application or a utility like the google cloud cli or curl because the client makes requests and not the user google cloud can t request identity information from the user directly to check if they have permission to use an api instead this identity is passed to the api through the client in the form of a token which is included in each api request a user authentication token encodes the following information the identity of the user the identity of the client assurance that the client is allowed to act on behalf of the user authenticating the user and authorizing the client involves the following parties a user a client that acts on behalf of the user an authorization server which google apis rely on to authenticate the client a google cloud api that the client interacts with clients can t issue tokens themselves instead they must work with an authorization server to do the following authenticate the user authenticate the client authorize the client to act on the user s behalf issue a token to the client a user who authenticates by signing in to their google account is a user principal the principal has a principal identifier similar to the following user alex example com a user who authenticates using workforce identity federation and an external identity provider is a workforce identity pool principal the principal has a principal identifier similar to the following principal iam googleapis com locations global workforcepools pool_id subject raha altostrat com workload authentication some clients need to interact with google apis on their own behalf for example a scheduled job might need to read data from bigquery or cloud storage without any human user being involved clients that act unattended and on their own behalf are referred to as workloads unlike user authentication workload authentication combines authenticating the user and authorizing the client into a single step because of this a workload authentication token encodes the identity of only the client workload authentication and authorization involves the following parties a workload acting as both a client and a user and on its own behalf an authorization server which google apis rely on to authenticate the client a google cloud api that the client interacts with to access google cloud apis clients must work with an authorization server to do the following authenticate the client authorize the client issue a token to the client an authenticated workload is also referred to as a principal but workloads use different principal identifiers than users a workload that authenticates using a service account is a service account principal the principal has a principal identifier similar to the following serviceaccount my service account my project iam gserviceaccount com a workload that authenticates using workload identity federation is a workload identity pool principal the principal has a principal identifier similar to the following principal iam googleapis com projects project_name locations global workloadidentitypools pool_id subject subject_attribute_value authorization servers google cloud shares specific authentication and authorization facilities with other google services shared facilities include sign in with google and the openid connect and oauth 2 0 services provided by google identity other authentication related services such as workload identity federation and workforce identity federation are specific to google cloud and can t be used for other google services because of this split google cloud uses two authorization servers one is shared with other google services and the other is specific to google cloud the following table describes the different servers and their properties authorization server authentication type authentication apis principals google authorization server user authentication workload authentication google oauth 2 0 api saml user managed user user consumer account service account google cloud identity and access management iam authorization server user authentication workload authentication security token service sts api iam service account credentials api metadata servers workforce identity pool principal workload identity pool principal service account the authorization servers are global services and can be accessed from any google cloud region however not all regions contain deployments of both authorization servers the google authorization server is available in select regions the google cloud iam authorization server is available in all regions to optimize reliability use the google cloud iam authorization server whenever possible what s next read about token types send feedback except as otherwise noted the content of this page is licensed under the creative commons attribution 4 0 license and code samples are licensed under the apache 2 0 license for details see the google developers site policies java is a registered trademark of oracle and or its affiliates last updated 2026 07 21 utc need to tell us more easy to understand easytounderstand thumb up solved my problem solvedmyproblem thumb up other otherup thumb up hard to understand hardtounderstand thumb down incorrect information or sample code incorrectinformationorsamplecode thumb down missing the information samples i need missingtheinformationsamplesineed thumb down other otherdown thumb down last updated 2026 07 21 utc products and pricing see all products google cloud pricing google cloud marketplace contact sales support community forums support release notes system status resources github getting started with google cloud code samples cloud architecture center training and certification engage blog events x twitter google cloud on youtube google cloud tech on youtube about google privacy site terms google cloud terms manage cookies our third decade of climate action join us sign up for the google cloud newsletter subscribe english deutsch español español américa latina français indonesia italiano português português brasil עברית 中文 简体 中文 繁體 日本語 한국어
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • Google Cloud Documentatio...
  • A relationship diagram of...
  • A relationship diagram of...

Verified site has: 75 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
location htt????/docs.cloud.google.com/docs/authentication/tokens
x-cloud-trace-context 7a93d2d7e72ae2eaabcd0943e1788182
date Tue, 21 Jul 2026 10:58:59 GMT
content-type text/html
server Google Frontend
Content-Length 0
Connection close
HTTP/2 200
last-modified Tue, 21 Jul 2026 04:34:04 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-zorFmFsoxJ1xSkpR7dX+CwLnaZhPqf unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context 8cd4f28ba942326bfa3502772724e16c
date Tue, 21 Jul 2026 10:58:59 GMT
server Google Frontend
content-length 21812
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Tokens overview  |  Authentication  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Tokens overview  |  Authentication  |  Google Cloud Documentation"
name="description" content="Learn about the types of tokens that Google Cloud issues, their purpose, and how they are used."
property="og:description" content="Learn about the types of tokens that Google Cloud issues, their purpose, and how they are used."
property="og:url" content="htt????/docs.cloud.google.com/docs/authentication/tokens"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size21812
load time (s)0.500065
redirect count1
speed download43624
server IP 142.251.39.206
* all occurrences of the string "http://" have been changed to "htt???/"