If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: docs.cloud.google.com/iam/docs/create-service-agents - Create and grant roles to serv.

site address: docs.cloud.google.com/iam/docs/create-service-agents redirected to: docs.cloud.google.com/iam/docs/create-service-agents

site title: Create and grant roles to service agents     Identity and Access Management (IAM)     Google Cloud Documentation

Our opinion (on Monday 20 July 2026 12:57:22 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:
description=How to create a service agent and grant it IAM roles.;

Headings (most frequently used words):

windows, linux, macos, or, cloud, shell, powershell, curl, service, and, roles, to, agents, gcloud, rest, cmd, exe, apis, explorer, browser, create, grant, required, console, terraform, stay, organized, with, collections, save, categorize, content, based, on, your, preferences, before, you, begin, identify, trigger, agent, creation, what, next, products, pricing, support, resources, engage, permissions,

Text of the page (most frequently used words):
the (334), #service (203), for (134), you (125), and (111), #agents (90), roles (78), that (76), gcloud (72), create (60), access (59), agent (59), cloud (56), role (49), grant (48), following (48), use (47), com (46), google (43), your (42), command (38), googleapis (37), account (37), policy (36), request (36), list (35), auth (35), identity (34), project (33), resource (33), with (31), iam (31), using (29), projects (29), can (28), each (28), services (28), response (27), 123456789012 (26), aiplatform (25), this (24), resource_type (24), endpoint (23), manage (22), policies (22), running (22), organization (22), terraform (21), allow (21), are (20), resource_id (20), api (20), example (20), resources (19), need (19), accounts (19), workload (19), cli (18), type (18), folder (18), granted (18), principal (18), all (17), user (17), active (17), want (17), execute (16), json (16), data (16), code (15), identities (15), method (15), headers (15), https (15), federation (15), page (14), note (14), token (14), automatically (14), organizations (14), folders (14), permissions (14), global (14), get (14), required (13), shell (13), created (13), workloadidentity (13), available (13), content (12), which (12), any (12), have (12), these (12), name (12), see (11), information (11), send (11), reference (11), application (11), expand (11), windows (11), like (11), before (11), custom (11), email (11), locations (11), body (10), apis (10), cred (10), print (10), authorization (10), bearer (10), assumes (10), logged (10), check (10), currently (10), login (10), init (10), curl (10), one (10), make (10), configuration (10), address (10), enable (10), workforce (10), samples (9), other (9), best (9), practices (9), version (9), contains (9), post (9), logs (9), ids (9), value (9), binding (9), serviceaccount (9), apply (9), console (9), will (9), where (9), resourcemanager (9), troubleshoot (9), configure (9), more (8), view (8), api_version (8), powershell (8), linux (8), macos (8), replacements (8), then (8), add (8), gcp (8), gserviceaccount (8), identify (8), creation (8), google_workload_identity_service_agent (8), operations (8), serviceproducers (8), state (8), level (8), usage (8), keys (8), pam (8), overview (8), about (7), thumb (7), managed (7), them (7), not (7), setiampolicy (7), select (7), granting (7), getiampolicy (7), trigger (7), run (7), permission (7), operation (7), also (7), serviceusage (7), limit (7), management (7), audit (7), 2026 (6), workloads (6), should (6), explorer (6), click (6), cloudresourcemanager (6), save (6), options (6), numeric (6), bigquery (6), default (6), condition (6), manager (6), job (6), container (6), serviceproducer (6), lists (6), from (6), number (6), endpoints (6), expression (6), their (6), admin (6), security (6), tools (6), oauth (6), logging (6), credentials (6), updated (5), learn (5), tool (5), invoke (5), webrequest (5), charset (5), utf (5), uri (5), object (5), named (5), into (5), http (5), url (5), alphanumeric (5), grants (5), primary (5), documentation (5), product (5), might (5), false (5), creating (5), record (5), generateserviceagents (5), filter (5), predefined (5), pipelines (5), temporary (5), boundary (5), functions (5), authenticate (5), português (4), español (4), understand (4), down (4), how (4), copy (4), right (4), requests (4), file (4), strings (4), rest (4), plan (4), after (4), target (4), member (4), associated (4), role_name (4), multiple (4), time (4), typically (4), don (4), specific (4), operation_name (4), resource_numeric_id (4), generate (4), ask (4), next_page_token (4), page_size (4), optional (4), storage (4), deny (4), short (4), lived (4), credential (4), elevated (4), delete (4), providers (4), users (4), microsoft (4), entra (4), sign (3), architecture (3), getting (3), system (3), products (3), under (3), details (3), control (3), returned (3), open (3), panel (3), opens (3), side (3), interact (3), complete (3), fields (3), browser (3), set (3), whose (3), write (3), members (3), vertex (3), bindings (3), owner (3), when (3), read (3), errors (3), section (3), google_project (3), remove (3), cmd (3), exe (3), below (3), needs (3), choose (3), function (3), based (3), those (3), some (3), because (3), aren (3), metadata (3), operationmetadata (3), createtime (3), 03t23 (3), verb (3), passthroughlro (3), requestedcancellation (3), apiversion (3), done (3), listed (3), field (3), identified (3), location (3), review (3), names (3), pagination (3), pagesize (3), pagetoken (3), results (3), quotes (3), contain (3), help (3), guides (3), networking (3), compute (3), monitor (3), scim (3), tags (3), related (3), key (3), gke (3), groups (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), terms (2), site (2), youtube (2), events (2), started (2), status (2), support (2), pricing (2), missing (2), last (2), utc (2), otherwise (2), licensed (2), license (2), feedback (2), explore (2), principals (2), next (2), store (2), paste (2), contenttype (2), infile (2), calling (2), already (2), project_number (2), customcodeserviceagent (2), policy_version (2), current (2), modify (2), pattern (2), update (2), execution (2), google_project_iam_member (2), added (2), service_agents (2), project_id (2), wanted (2), could (2), provider (2), basic (2), commands (2), search (2), must (2), they (2), properly (2), creates (2), necessary (2), 1775258415970 (2), 64e968f44b91a (2), 28fcf2f5 (2), 38367cfe (2), 982631253z (2), serviceagents (2), serviceagent (2), vtc (2), trainingclusterserviceagent (2), truncated (2), completed (2), return (2), were (2), was (2), 1775250941060 (2), 64e94d1baa76d (2), 1aa958f3 (2), 07b2ea9c (2), placeholder (2), skip (2), find (2), titles (2), greater (2), than (2), size (2), start (2), previous (2), include (2), maximum (2), quoting (2), filters (2), sandbox (2), but (2), library (2), through (2), repository (2), let (2), actual (2), resolve (2), revoke (2), prevent (2), revoked (2), sdk (2), languages (2), frameworks (2), infrastructure (2), costs (2), observability (2), monitoring (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), hosting (2), development (2), error (2), messages (2), patterns (2), integration (2), controls (2), optimize (2), test (2), migrate (2), restrict (2), settings (2), entitlements (2), edit (2), conditions (2), conditional (2), types (2), legged (2), disable (2), integrate (2), pools (2), libraries (2), deployment (2), federate (2), load (2), applications (2), federated (2), oidc (2), saml (2), okta (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, blog, engage, training, certification, center, github, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, its, affiliates, developers, apache, creative, commons, attribution, act, ways, what, treat, sent, representation, format, has, platform, etag, bwwkmjvelug, requestedpolicyversion, specify, most, recent, specifying, shows, looks, good, ensures, without, known, would, targeted, for_each, try, prefaced, 0123456789012, instead, follow, principle, least, privilege, includes, only, perform, give, enter, person_add, asked, addresses, endtime, 315225515z, true, generateserviceagentsresponse, containing, ongoing, indicting, 03t21, 367155118z, parent, provisioned, once, during, step, manually, keep, track, programmatically, provide, know, unique, organization_number, folder_number, indicates, determine, triggering, earlier, specified, ended, 200, retrieve, uses, replace, single, double, nested, escape, inner, unlimited, expressions, topic, additional, methods, able, long, exact, organizationadmin, folderadmin, projectiamadmin, viewer, serviceusageviewer, administrator, likely, serviceusageadmin, begin, refer, stores, copies, appear, stored, inconsistency, incorrectly, proactively, drift, between, doesn, ensure, declarative, framework, option, useful, strategies, asking, lets, hasn, been, yet, sometimes, behalf, categorize, preferences, stay, organized, collections, home, withcond, insights, history, analyze, privileged, secure, vpc, intelligence, securely, exfiltration, interfaces, restore, downscoped, boundaries, approve, withdraw, remediate, excessive, entitlement, export, setup, lint, limits, conditionally, changes, auditing, billing, grantable, suggestions, gemini, assistance, change, propagation, inheritance, own, deploy, built, managing, upload, public, rotation, download, customers, 509, certificates, kubernetes, directory, aws, azure, external, balancers, balancing, gce, engine, attach, undelete, authentication, impersonation, obtain, power, pingone, aic, pingfederate, large, provisioning, client, discover, free, main,


Text of the page (random words):
ices is greater than the page size the response also contains a pagination token the api endpoint is the value in the name field for each api endpoint that you will use make a list of the resources where you need to create that endpoint s service agents on the service agent reference page search for each api endpoint to find all service agents for that endpoint some endpoints might not have associated service agents you can skip triggering service agent creation for these endpoints for each of the endpoint s service agents use the service agent s email address to determine where you need to create the service agent the placeholder in a service agent s email address indicates where you need to create the service agent placeholder where to create the service agent project_number each project where you will use the service folder_number each folder where you will use the service organization_number each organization where you will use the service for each endpoint record each unique resource where you need to create service agents for that endpoint trigger service agent creation after you know which service agents you need to create you can ask google cloud to create them when you ask google cloud to create service agents you provide it with a service and a resource then google cloud creates all service agents for that service and that resource during this step if you re using the gcloud cli or the rest api you can also create a list of the roles that need to be granted to each service agent you ll use this information to grant roles to the service agents if you re using terraform then you don t need to manually keep track of the required roles because you can reference the roles programmatically gcloud use the gcloud workload identity service agents generate command to create service agents for each endpoint and resource that you identified in identify service agents to create each time you run the command review the response for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents before using any of the command data below make the following replacements endpoint the endpoint of the api that you want to create service agents for for example aiplatform googleapis com resource_type the type of resource that you want to create service agents for use project folder or organization resource_id the numeric id of the google cloud project folder or organization that you want to create service agents for for example 123456789012 you can create service agents for one resource at a time if you need to create service agents for multiple resources run the command once for each resource execute the following command linux macos or cloud shell gcloud workload identity service agents generate service endpoint location global resource_type resource_id windows powershell gcloud workload identity service agents generate service endpoint location global resource_type resource_id windows cmd exe gcloud workload identity service agents generate service endpoint location global resource_type resource_id the response contains a list of all of the service agents that were created for each service agent the response lists the resource it was created for the email address of the service agent the service that the service agent is associated with and the state of the service agent if the service agent is typically granted a specific role the response also lists that role the listed role is not automatically granted to the service agent for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents the following is a truncated example of the response for creating service agents for aiplatform googleapis com provisioned service agents for aiplatform googleapis com under projects 123456789012 container projects 123456789012 principal serviceaccount service 123456789012 gcp sa aiplatform iam gserviceaccount com role roles aiplatform serviceagent serviceproducer aiplatform googleapis com state active container projects 123456789012 principal serviceaccount service 123456789012 gcp ri aiplatform iam gserviceaccount com serviceproducer aiplatform googleapis com state active container projects 123456789012 principal serviceaccount service 123456789012 gcp sa vertex vtc iam gserviceaccount com role roles aiplatform trainingclusterserviceagent serviceproducer aiplatform googleapis com state active terraform to learn how to apply or remove a terraform configuration see basic terraform commands for more information see the terraform provider reference documentation use the google_workload_identity_service_agent resource to trigger service agent creation for each endpoint and resource that you identified in identify service agents to create for example if you wanted to create all project level service agents for bigquery for the default project you could add the following code to your terraform configuration data google_project default create all project level bigquery googleapis com service agents resource google_workload_identity_service_agent primary parent projects data google_project default number locations global serviceproducers bigquery googleapis com rest for each endpoint that you need to create service agents for do the following create service agents for each resource that you identified in identify service agents to create before using any of the request data make the following replacements resource_type the type of resource that you want to create service agents for use projects folders or organizations resource_numeric_id the numeric id of the google cloud project folder or organization that you want to create service agents for for example 123456789012 you can create service agents for one resource at a time if you need to create service agents for multiple resources send one request for each resource endpoint the endpoint of the api that you want to create a service agent for for example aiplatform googleapis com http method and url post https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents to send your request expand one of these options curl linux macos or cloud shell note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login or by using cloud shell which automatically logs you into the gcloud cli you can check the currently active account by running gcloud auth list execute the following command curl x post h authorization bearer gcloud auth print access token h content type application json charset utf 8 d https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents powershell windows note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login you can check the currently active account by running gcloud auth list execute the following command cred gcloud auth print access token headers authorization bearer cred invoke webrequest method post headers headers uri https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents select object expand content the response contains an operation indicting the status of your request for example name projects 123456789012 locations global operations operation 1775250941060 64e94d1baa76d 1aa958f3 07b2ea9c metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t21 15 41 367155118z target projects 123456789012 locations global serviceproducers bigquery googleapis com verb passthroughlro requestedcancellation false apiversion v1 done false get the response from the completed operation for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents before using any of the request data make the following replacements operation_name the name of a generateserviceagents operation copy this value from the name field of a serviceproducers generateserviceagents response for example projects 123456789012 locations global operations operation 1775250941060 64e94d1baa76d 1aa958f3 07b2ea9c project_id your google cloud project id project ids are alphanumeric strings like my project http method and url get https workloadidentity googleapis com v1 operation_name to send your request expand one of these options curl linux macos or cloud shell note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login or by using cloud shell which automatically logs you into the gcloud cli you can check the currently active account by running gcloud auth list execute the following command curl x get h authorization bearer gcloud auth print access token https workloadidentity googleapis com v1 operation_name powershell windows note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login you can check the currently active account by running gcloud auth list execute the following command cred gcloud auth print access token headers authorization bearer cred invoke webrequest method get headers headers uri https workloadidentity googleapis com v1 operation_name select object expand content apis explorer browser open the method reference page the apis explorer panel opens on the right side of the page you can interact with this tool to send requests complete any required fields and click execute ongoing operations return a response like the following name projects 123456789012 locations global operations operation 1775258415970 64e968f44b91a 28fcf2f5 38367cfe metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t23 20 15 982631253z target projects 123456789012 locations global serviceproducers aiplatform googleapis com verb passthroughlro requestedcancellation false apiversion v1 done false completed operations return a response containing a list of service agents that were created for each service agent the response lists the resource it was created for the email address of the service agent the service that the service agent is associated with and the state of the service agent if the service agent is typically granted a specific role the response also lists that role the listed role is not automatically granted to the service agent for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents the following is a truncated example of the response for creating service agents for aiplatform googleapis com name projects 123456789012 locations global operations operation 1775258415970 64e968f44b91a 28fcf2f5 38367cfe metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t23 20 15 982631253z endtime 2026 04 03t23 20 17 315225515z target projects 123456789012 locations global serviceproducers aiplatform googleapis com verb passthroughlro requestedcancellation false apiversion v1 done true response type type googleapis com google cloud workloadidentity v1 generateserviceagentsresponse serviceagents container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp sa aiplatform iam gserviceaccount com role roles aiplatform serviceagent state active container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp ri aiplatform iam gserviceaccount com state active container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp sa vertex vtc iam gserviceaccount com role roles aiplatform trainingclusterserviceagent state active grant roles to service agents after google cloud creates the necessary service agents for your projects folders and organizations you use the service agents email addresses to grant them roles if you asked google cloud to create service agents you must grant those service agents the roles that they are typically granted automatically if you don t some services might not function properly this is because service agents that are created at a user s request aren t automatically granted roles console use the list of roles and service agents that you created in trigger service agent creation to identify which service agents need to be granted roles for each service agent that needs a role do the following in the google cloud console go to the iam page go to iam select a project folder or organization that you created the service agent for click person_add grant access then enter the service agent s email address click select a role then search for a role to grant based on the following the role name the google cloud product that you want to grant access to the permission that you want to give the job function to perform to follow the principle of least privilege choose a role that includes only the permissions that your principal needs click save the service agent is granted the role on the resource gcloud use the list of roles and service agents that you created in trigger service agent creation to identify which service agents need to be granted roles for each service agent that needs a role use the add iam policy binding command to grant the role to the service agent note to grant roles to multiple service agents at a time use the read modify write pattern instead of the add iam policy binding command before using any of the command data below make the following replacements resource_type the resource type that you want to manage access to use projects resource manager folders or organizations resource_id your google cloud project folder or organization id project ids are alphanumeric like my project folder and organization ids are numeric like 123456789012 principal the email address of the service agent that you want to grant access to prefaced by serviceaccount for example serviceaccount service 0123456789012 gcp sa aiplatform cc iam gserviceaccount com role_name the name of the role that you want to grant to the service agent execute the following command linux macos or cloud shell gcloud resource_type add iam policy binding resource_id member principal role role_name condition condition windows powershell gcloud resource_type add iam policy binding resource_id member principal role role_name condition condition windows cmd exe gcloud resource_type add iam policy binding ...
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • Google Cloud Documentatio...

Verified site has: 209 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
201-205 206-209


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
location htt????/docs.cloud.google.com/iam/docs/create-service-agents
x-cloud-trace-context 67654afad1926e34e5b88d02f492d577
date Mon, 20 Jul 2026 12:57:21 GMT
content-type text/html
server Google Frontend
Content-Length 0
Connection close
HTTP/2 200
last-modified Fri, 17 Jul 2026 15:09:26 GMT
content-type text/html; charset=utf-8
vary Cookie
vary Accept-Encoding
content-security-policy base-uri self ; object-src none ; script-src strict-dynamic unsafe-inline https: http: nonce-DfbnkgewTKSk3oJb+pWqnTL5YlIMa4 unsafe-eval ; frame-ancestors self htt????/developers.google.com/_d/analytics-iframe; report-uri htt????/csp.withgoogle.com/csp/devsite/v2
strict-transport-security max-age=63072000; includeSubdomains; preload
x-xss-protection 0
x-content-type-options nosniff
cache-control no-cache, must-revalidate
expires 0
pragma no-cache
content-encoding gzip
x-cloud-trace-context 961199e096ecf237bba50a2bcfb35407
date Mon, 20 Jul 2026 12:57:22 GMT
server Google Frontend
content-length 38328
alt-svc h3= :443 ; ma=2592000,h3-29= :443 ; ma=2592000

Meta Tags

title="Create and grant roles to service agents  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
name="google-signin-client-id" content="721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com"
name="google-signin-scope" content="profile email htt????/www.googleapis.com/auth/developerprofiles htt????/www.googleapis.com/auth/developerprofiles.award htt????/www.googleapis.com/auth/devprofiles.full_control.firstparty"
property="og:site_name" content="Google Cloud Documentation"
property="og:type" content="website"
name="theme-color" content="#1a73e8"
charset="utf-8"
content="IE=Edge" http-equiv="X-UA-Compatible"
name="viewport" content="width=device-width, initial-scale=1"
property="og:title" content="Create and grant roles to service agents  |  Identity and Access Management (IAM)  |  Google Cloud Documentation"
name="description" content="How to create a service agent and grant it IAM roles."
property="og:description" content="How to create a service agent and grant it IAM roles."
property="og:url" content="htt????/docs.cloud.google.com/iam/docs/create-service-agents"
property="og:image" content="htt????/docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png"
property="og:image:width" content="1200"
property="og:image:height" content="630"
property="og:locale" content="en"
name="twitter:card" content="summary_large_image"

Load Info

page size38328
load time (s)0.598285
redirect count1
speed download64093
server IP 142.251.39.206
* all occurrences of the string "http://" have been changed to "htt???/"