REST Resource: projects.locations.authorizations

Resource: Authorization

Discovery Engine Authorization resource.

JSON representation
{
  "name": string,
  "displayName": string,

  // The following is a list of mutually exclusive fields. At most one of the
  // fields will be set in a response:
  "serverSideOauth2": {
    object (ServerSideOAuth2)
  }
  // End of mutually exclusive fields.
}
Fields
name

string

Identifier. Resource name of the authorization. Format: projects/{project}/locations/{location}/authorizations/{authorization}

It must be a UTF-8 encoded string with a length limit of 1024 characters.

displayName

string

Required. The display name of the authorization.

It must be a UTF-8 encoded string with a length limit of 128 characters.

The authorization configuration. The following is a list of mutually exclusive fields. At most one of the fields will be set in a response:
serverSideOauth2

object (ServerSideOAuth2)

Server-side OAuth2 configuration.

End of mutually exclusive fields.

ServerSideOAuth2

OAuth2 configuration.

JSON representation
{
  "clientId": string,
  "clientSecret": string,
  "tokenUri": string,
  "authorizationUri": string,
  "scopes": [
    string
  ],
  "pkceVerificationEnabled": boolean,
  "basicAuthenticationEnabled": boolean,
  "privateNetworkConfig": {
    object (PrivateNetworkConfig)
  }
}
Fields
clientId

string

Required. The OAuth2 client ID.

clientSecret

string

Required. The OAuth2 client secret.

Encrypted at rest.

tokenUri

string

Required. The HTTP endpoint that exchanges a client authorization for an access token.

authorizationUri

string

Required. The URI the user is directed to when they need to authorize. Should include everything required for a successful authorization: OAuth id, extra flags, etc. Example: https://accounts.google.com/o/oauth2/v2/auth?clientId=OAUTH_ID&scope=https://www.googleapis.com/auth/calendar.events&responseType=code&access_type=offline&prompt=consent

The redirectUri parameter will be overwritten by the Vertex AI Search frontend.

scopes[]

string

Optional. The scopes to request. Example: https://www.googleapis.com/auth/calendar.events If omitted, no additional scopes are requested beyond those required by the authorization uri. If set, it will overwrite the scopes in the authorization uri when acquiring user authorization.

pkceVerificationEnabled

boolean

Optional. Whether to enable PKCE verification. https://datatracker.ietf.org/doc/html/rfc7636#section-3.1/

basicAuthenticationEnabled

boolean

Optional. Whether the OAuth token exchange uses HTTP Basic authentication (client_secret_basic) instead of sending the client credentials in the request body (client_secret_post). When true, the credentials (clientId:clientSecret) are Base64 encoded and sent in the Authorization header. Some OAuth providers (e.g. Splunk) require client_secret_basic. When false or unset, the default client_secret_post is used.

privateNetworkConfig

object (PrivateNetworkConfig)

Optional. Set only when the OAuth provider publishes no public endpoint, in which case a token exchange has to be routed over the private network the instance is on instead of over public egress. Leaving it unset keeps the exchange on public egress.

PrivateNetworkConfig

Identifies the instance hosting an OAuth provider that is reachable only over a private network.

JSON representation
{
  "instanceResource": string
}
Fields
instanceResource

string

Required. Resource name of the instance hosting the OAuth provider. For Looker, the Looker instance, in the form projects/{project}/locations/{location}/instances/{instance}.

Methods

create

Creates an Authorization.

delete

Deletes an Authorization.

get

Gets an Authorization.

list

Lists all Authorizations under an Engine.

patch

Updates an Authorization