ServicesSolutionsIndustriesExpertiseResourcesCompanyMore…Updated: May 7, 2024Do you want a time-sensitive way to give access to a third party to your GCP account with a low administrative burden? Look no further! Set up a service account!It’s actually very simple:Create a new service account, and give it the permissions needed by the third partyAsk the third party for a Google IdentityAdd this identity to the service account with the TokenCreator permissionsProfit!Now the third party needs to execute the gcloud command with an additional parameter, –impersonate-service-account = . All API calls will be done with this service account identity.*PROTIP:* If you set the variable CLOUDSDK_AUTH_IMPERSONATE_SERVICE_ACCOUNT, you don't need to add the aforementioned parameter, as gcloud will honor it automatically.Carlos BarrosoHead of AIteracloud.io [email protected] & AnalyticsAI & Cloud ComputingSolutionsManaged ServicesIndustriesUtilitiesResourcesSucces StoriesStartupsFinancial ServicesBlogSmall & Medium BusinessFrom Idea to Gen AICloud FitEcommerce & RetailOil and GasCompanyAboutJoin usExpertiseAWS Well ArchitectedAWS LambdaAmazon CloudfrontAmazon AuroraAmazon EKSAWS WAFAmazon ECSAmazon Open SearchCopyright © 2026 Teracloud USA LLC.All Rights Reserved. All trademarks are property of their legal owners.AWS GlueAPI Gateway