Resource: Authorization
Discovery Engine Authorization resource.
| JSON representation |
|---|
{
"name": string,
"displayName": string,
// The following is a list of mutually exclusive fields. At most one of the
// fields will be set in a response:
"serverSideOauth2": {
object ( |
| Fields | |
|---|---|
name |
Identifier. Resource name of the authorization. Format: It must be a UTF-8 encoded string with a length limit of 1024 characters. |
displayName |
Required. The display name of the authorization. It must be a UTF-8 encoded string with a length limit of 128 characters. |
| The authorization configuration. The following is a list of mutually exclusive fields. At most one of the fields will be set in a response: | |
serverSideOauth2 |
Server-side OAuth2 configuration. |
| End of mutually exclusive fields. | |
ServerSideOAuth2
OAuth2 configuration.
| JSON representation |
|---|
{
"clientId": string,
"clientSecret": string,
"tokenUri": string,
"authorizationUri": string,
"scopes": [
string
],
"pkceVerificationEnabled": boolean,
"basicAuthenticationEnabled": boolean,
"privateNetworkConfig": {
object ( |
| Fields | |
|---|---|
clientId |
Required. The OAuth2 client ID. |
clientSecret |
Required. The OAuth2 client secret. Encrypted at rest. |
tokenUri |
Required. The HTTP endpoint that exchanges a client authorization for an access token. |
authorizationUri |
Required. The URI the user is directed to when they need to authorize. Should include everything required for a successful authorization: OAuth id, extra flags, etc. Example: The |
scopes[] |
Optional. The scopes to request. Example: |
pkceVerificationEnabled |
Optional. Whether to enable PKCE verification. https://datatracker.ietf.org/doc/html/rfc7636#section-3.1/ |
basicAuthenticationEnabled |
Optional. Whether the OAuth token exchange uses HTTP Basic authentication ( |
privateNetworkConfig |
Optional. Set only when the OAuth provider publishes no public endpoint, in which case a token exchange has to be routed over the private network the instance is on instead of over public egress. Leaving it unset keeps the exchange on public egress. |
PrivateNetworkConfig
Identifies the instance hosting an OAuth provider that is reachable only over a private network.
| JSON representation |
|---|
{ "instanceResource": string } |
| Fields | |
|---|---|
instanceResource |
Required. Resource name of the instance hosting the OAuth provider. For Looker, the Looker instance, in the form |
Methods |
|
|---|---|
|
Uses the stored refresh token for the user identified by their end-user credentials and the given resource, and returns the generated access token and its details. |
|
Creates an Authorization. |
|
Deletes an Authorization. |
|
Gets an Authorization. |
|
Lists all Authorizations under an Engine. |
|
Updates an Authorization |
|
Exchanges OAuth authorization credentials for a refresh token and stores the refresh token and the scopes. |