You can use IAM condition. The doc is interesting if you want to script the access. For a test, you can use the console
Start by adding or editing permission in the IAM page. Choose a role and then click on add permissions

Name your condition and choose the condition(s).

EDIT
You can use the API directly for this
You can also use the client library. There is no dedicated library for resource manager, you have to use the discovery API. Here the description of the resource manager v1
So, in Python, the code look like this
import googleapiclient.discovery
resourceManager = googleapiclient.discovery.build("cloudresourcemanager","v1")
result = resourceManager.projects().getIamPolicy(resource="<ProjectId>").execute()
print(result)
body={
'policy': {
'bindings': [
{
'role': 'roles/storage.objectViewer',
'members': [
'user:myUser@example.com'
],
'condition': {
'title': 'expirable access',
'expression': 'request.time < timestamp("2020-10-01T00:00:00.000Z")'
}
}
],
'version': 3
}
}
result = resourceManager.projects().setIamPolicy(resource="<ProjectId>", body=body).execute()
print(result)
Note: you have to repeat the binding bloc for each role that you want to grant
BE CAREFUL
In both case, you will set the IAM policy, it's an erase/replace of the existing policy on the project. By the way, one of the good practice is to perform a getIamPolicy (also in my example) before and to update the results before setting it.