- INFORMATION
-
gcloud alpha access-context-manager cloud-bindings updateis not available in universe domainuniverse. - NAME
-
- gcloud alpha access-context-manager cloud-bindings update - update an existing cloud access binding under an organization
- SYNOPSIS
-
-
gcloud alpha access-context-manager cloud-bindings update(--binding=BINDING:--organization=ORGANIZATION) [--append] [--binding-file=YAML_FILE] [--dry-run-level=[DRY_RUN_LEVEL,…]] [--level=[LEVEL,…]] [--session-length=SESSION_LENGTH] [--session-reauth-method=SESSION_REAUTH_METHOD; default="login"] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)Update an existing cloud access binding. You can update the level, dry run level, session settings, and scoped access settings. They cannot all be empty.For Google Group bindings (
--group-key), you can update the access level, dry run level, top-level session settings (1 hour to 24 hours, or 0 to disable), and/or scoped access settings for specific applications (restrictedClientApplication).For bindings tied to all workforce pools in an organization (
principalSet://cloudresourcemanager.googleapis.com/organizations/{organization_id}/type/WorkforcePool), you can update or append scoped access settings withrestrictedProjectand activesessionSettingsusing--binding-file. Top-level session settings, top-level access levels, dry run levels, and application scopes (restrictedClientApplication) are not supported for this principal type.Session settings are only supported for Google Groups and bindings tied to all workforce pools in an organization. No other bindings allow session settings, and requests containing session settings for other principal types will be rejected.
- EXAMPLES
-
To update an existing cloud access binding, run:
gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --level=accessPolicies/123/accessLevels/new-abcTo remove level and add dry run level, run:
gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --level= --dry-run-level=accessPolicies/123/accessLevels/new-defTo replace scoped access settings (e.g., for specific applications on a group binding or restricted projects on a workforce pool binding) with a new list, run:
gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --binding-file='binding.yaml'To append scoped access settings to the existing list, run:
gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --binding-file='binding.yaml' --appendNote this is only possible for scoped access settings that exclusively hold session settings (i.e. no access levels).
To update or append project-scoped session settings on a binding tied to all workforce pools in an organization:
Create a `binding.yaml` file containing the desired `scopedAccessSettings` with `restrictedProject`:
scopedAccessSettings: - scope: clientScope: restrictedProject: name: projects/1234567890 activeSettings: sessionSettings: sessionLength: 7776000s sessionLengthEnabled: true sessionReauthMethod: LOGIN
Then run:gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --binding-file='binding.yaml' --appendTo update top-level session settings on a Google Group binding, run:
gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --session-length=2hTo update the session reauth method on a Google Group binding, you must also specify
--session-length(this can be the existing value if you only want to modify the reauth method), run:gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --session-length=2h --session-reauth-method=loginTo disable session settings on a Google Group binding, set
--session-length=0, for example:gcloud alpha access-context-manager cloud-bindings update --binding=my-binding-id --session-length=0 - REQUIRED FLAGS
-
-
Cloud access binding resource - The cloud access binding you want to update. The
arguments in this group can be used to specify the attributes of this resource.
This must be specified.
--binding=BINDING-
ID of the cloud-access-binding or fully qualified identifier for the
cloud-access-binding.
To set the
bindingattribute:-
provide the argument
--bindingon the command line.
This flag argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--organization=ORGANIZATION-
The ID of the organization.
To set the
organizationattribute:-
provide the argument
--bindingon the command line with a fully specified name; -
provide the argument
--organizationon the command line; -
set the property
access_context_manager/organization.
-
provide the argument
-
Cloud access binding resource - The cloud access binding you want to update. The
arguments in this group can be used to specify the attributes of this resource.
- OPTIONAL FLAGS
-
--append-
When true, append the
ScopedAccessSettingsin--binding-fileto the existingScopedAccessSettingson the binding. When false, the existing binding'sScopedAccessSettingswill be overwritten. Defaults to false. You may only appendScopedAccessSettingsthat exclusively hold session settings (i.e no access levels). --binding-file=YAML_FILE-
Path to the file that contains a Google Cloud user access binding.
This file contains a YAML-compliant object representing a GcpUserAccessBinding containing
scopedAccessSettingsonly. No other binding fields are allowed.For Google Group bindings,
scopedAccessSettingscan specifyrestrictedClientApplication(usingclientIdorname) withaccessLevels,dryRunAccessLevels, and/orsessionSettings(session length up to 1 day / 24 hours). TherestrictedProjectscope is not supported for Google Group bindings.For bindings tied to all workforce pools in an organization (
principalSet://cloudresourcemanager.googleapis.com/organizations/{organization_id}/type/WorkforcePool),scopedAccessSettingsmust only containrestrictedProject(format:name: projects/{project_number}) withinscope.clientScopeandsessionSettingswithinactiveSettings. For this configuration:-
sessionLengthmust be set and must be between 1 hour and 90 days (e.g.7776000s). -
sessionReauthMethodmust beLOGINor omitted (defaults toLOGIN). -
sessionLengthEnabledmust be set totrue. -
maxInactivitymust be set to 0 or omitted. -
useOidcMaxAgemust be set tofalseor omitted. -
No application scopes (
restrictedClientApplication), access levels, or dry run settings are allowed.
The
restrictedProjectscope is only usable with bindings tied to the all workforce pools in an organization federated principal.The file content replaces the corresponding fields in the existing binding, unless
--appendis specified. See--appendhelp text for more details. -
--dry-run-level=[DRY_RUN_LEVEL,…]-
The dry run access level that replaces the existing dry run level for the given
binding. The input must be the full identifier of an access level, such as
accessPolicies/123/accessLevels/new-def. This parameter is not supported for bindings tied to all workforce pools in an organization. --level=[LEVEL,…]-
The access level that replaces the existing level for the given binding. The
input must be the full identifier of an access level, such as
accessPolicies/123/accessLevels/new-abc. This parameter is not supported for bindings tied to all workforce pools in an organization. --session-length=SESSION_LENGTH-
The maximum lifetime of a user session provided as an ISO 8601 duration string.
Must be at least one hour or zero seconds, and no more than twenty-four hours.
Granularity is limited to seconds.
When
--session-length=0users in the group attached to this binding will have infinite session length, effectively disabling the session settings.A session begins after a user signs in successfully. If a user signs out before the end of the session lifetime, a new login creates a new session with a fresh lifetime. When a session expires, the user is asked to re-authenticate in accordance with
--session-reauth-method.Setting
--session-reauth-methodwhen--session-lengthis empty raises an error.This parameter is only supported for Google Group bindings. It is not supported for bindings tied to all workforce pools in an organization (for which session settings can be updated or appended via
--binding-file) or any other principal type. --session-reauth-method=SESSION_REAUTH_METHOD; default="login"-
Specifies the security check a user must undergo when their session expires.
Defaults to
--session-reauth-method=LOGINif unspecified and--session-lengthis set. Cannot be used when--session-lengthis empty or 0. This parameter is only supported for Google Group bindings and is not supported for bindings tied to all workforce pools in an organization (for which session settings are configured via--binding-file).SESSION_REAUTH_METHODmust be one of:login- The user will be prompted to perform regular login. Users who are enrolled in two-step verification and haven't chosen to "Remember this computer" will be prompted for their second factor.
password- The user will only be required to enter their password.
security-key- The user will be prompted to authenticate using their security key. If no security key has been configured, the LOGIN method is used. For help configuring your security key, see https://support.google.com/a/answer/2537800?hl=en#zippy=%2Cview-add-or-remove-security-keys
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - API REFERENCE
-
This command uses the
accesscontextmanager/v1alphaAPI. The full documentation for this API can be found at: https://cloud.google.com/access-context-manager/docs/reference/rest/ - NOTES
-
This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation-only early access
allowlist. This variant is also available:
gcloud access-context-manager cloud-bindings update
gcloud alpha access-context-manager cloud-bindings update
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-08-26 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-08-26 UTC."],[],[]]