Google cloud serverless storage private api

Viewed 49

I can download data "copy Authenticated data" from Serverless storage. But I don't want public access.

Could I access (or download) data serverless storage using a private API? Is it possible?

1 Answers

As @John Hanley suggested Cloud Storage uses OAuth 2.0 for API authentication and authorization.The details of authentication vary depending on how you are accessing Cloud Storage, but fall into two general types:

  1. A server-centric flow allows an application to directly hold the credentials of a service account to complete authentication. Use this flow if your application works with its own data rather than user data. Google Cloud projects have default service accounts you can use, or you can create new ones.

  2. A user-centric flow allows an application to obtain credentials from an end user. The user signs in to complete authentication. Use this flow if your application needs to access user data. See the User account credentials section later in this page for scenarios where a user-centric flow is appropriate. OAuth 2.0 uses scopes to determine if an authenticated identity is authorized.

For example, application A with an access token with read-only scope can only read, while application B with an access token with read-write scope can read and modify data. Neither application can read or modify access control lists on objects and buckets; only an application with full-control scope can do so.

Refer to the document on Cloud storage authorization and Authentication overview for more information.

Related