openapi: 3.1.0 info: title: Google Cloud IAM Permissions Service Account Keys API description: The Cloud IAM API enables management of identity and access control policies, service accounts, roles, and permissions for Google Cloud resources. version: 1.0.0 contact: name: Google Cloud url: https://cloud.google.com/iam servers: - url: https://iam.googleapis.com/v1 description: Google Cloud IAM Production tags: - name: Service Account Keys paths: /projects/{projectId}/serviceAccounts/{serviceAccountEmail}/keys: get: operationId: listServiceAccountKeys summary: Google Cloud IAM List service account keys description: Lists every key for a service account. tags: - Service Account Keys parameters: - name: projectId in: path required: true schema: type: string - name: serviceAccountEmail in: path required: true schema: type: string responses: '200': description: Successful response content: application/json: schema: type: object properties: keys: type: array items: $ref: '#/components/schemas/ServiceAccountKey' post: operationId: createServiceAccountKey summary: Google Cloud IAM Create a service account key description: Creates a new key for a service account. tags: - Service Account Keys parameters: - name: projectId in: path required: true schema: type: string - name: serviceAccountEmail in: path required: true schema: type: string requestBody: required: true content: application/json: schema: type: object properties: privateKeyType: type: string enum: - TYPE_UNSPECIFIED - TYPE_PKCS12_FILE - TYPE_GOOGLE_CREDENTIALS_FILE keyAlgorithm: type: string enum: - KEY_ALG_UNSPECIFIED - KEY_ALG_RSA_1024 - KEY_ALG_RSA_2048 responses: '200': description: Successful response content: application/json: schema: $ref: '#/components/schemas/ServiceAccountKey' components: schemas: ServiceAccountKey: type: object properties: name: type: string description: Resource name of the key. privateKeyType: type: string description: Type of the private key data. keyAlgorithm: type: string description: Algorithm and size of the key. privateKeyData: type: string description: Private key data (base64-encoded). validAfterTime: type: string format: date-time description: Timestamp after which the key is valid. validBeforeTime: type: string format: date-time description: Timestamp before which the key is valid. keyOrigin: type: string description: Origin of the key. keyType: type: string description: Type of the key. securitySchemes: oauth2: type: oauth2 flows: authorizationCode: authorizationUrl: https://accounts.google.com/o/oauth2/auth tokenUrl: https://oauth2.googleapis.com/token scopes: https://www.googleapis.com/auth/iam: Manage IAM resources https://www.googleapis.com/auth/cloud-platform: Full access to Google Cloud