I am able to call the cloud function with my login which is owner of account through cloud shell.
curl -X POST https://us-central1-<project name>.cloudfunctions.net/hello_work_authentication_required -H "Authorization:
bearer $(gcloud auth print-identity-token)" -H "Accept: application/json" -d '{}'
But when I activate service account and then fire above curl command from cloud shell. I get unauthorized access error.
<html><head>
<meta http-equiv="content-type" content="text/html;charset=utf-8">
<title>403 Forbidden</title>
</head>
<body text=#000000 bgcolor=#ffffff>
<h1>Error: Forbidden</h1>
<h2>Your client does not have permission to get URL <code>/hello_work_authentication_required</code> from this server.</h2>
<h2></h2>
</body></html>
Service account I am using have owner, cloud function invoker and cloud function developer role assigned to it. I am clueless how this authentication is working.