- INFORMATION
-
gcloud alpha agent-identity auth-providers updateis not available in universe domainuniverse. - NAME
-
- gcloud alpha agent-identity auth-providers update - update authProviders
- SYNOPSIS
-
-
gcloud alpha agent-identity auth-providers update(AUTH_PROVIDER:--location=LOCATION) [--description=DESCRIPTION] [--request-id=REQUEST_ID] [--allowed-scopes=[ALLOWED_SCOPES,…] |--add-allowed-scopes=[ADD_ALLOWED_SCOPES,…]--clear-allowed-scopes|--remove-allowed-scopes=[REMOVE_ALLOWED_SCOPES,…]] [--blocked-scopes=[BLOCKED_SCOPES,…] |--add-blocked-scopes=[ADD_BLOCKED_SCOPES,…]--clear-blocked-scopes|--remove-blocked-scopes=[REMOVE_BLOCKED_SCOPES,…]] [--clear-auth-provider-type-params--api-key=API_KEY|--three-legged-oauth-authorization-url=THREE_LEGGED_OAUTH_AUTHORIZATION_URL--three-legged-oauth-client-id=THREE_LEGGED_OAUTH_CLIENT_ID--three-legged-oauth-client-secret=THREE_LEGGED_OAUTH_CLIENT_SECRET--[no-]three-legged-oauth-enable-pkce--three-legged-oauth-token-url=THREE_LEGGED_OAUTH_TOKEN_URL|--two-legged-oauth-client-id=TWO_LEGGED_OAUTH_CLIENT_ID--two-legged-oauth-client-secret=TWO_LEGGED_OAUTH_CLIENT_SECRET--two-legged-oauth-token-url=TWO_LEGGED_OAUTH_TOKEN_URL] [--labels=[LABELS,…] |--update-labels=[UPDATE_LABELS,…]--clear-labels|--remove-labels=REMOVE_LABELS] [--workload-ids=[WORKLOAD_IDS,…] |--add-workload-ids=[ADD_WORKLOAD_IDS,…]--clear-workload-ids|--remove-workload-ids=[REMOVE_WORKLOAD_IDS,…]] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)Update an authProvider - EXAMPLES
-
To update an auth provider named 'my-auth-provider' in location 'global' and
project 'my-project', run:
gcloud alpha agent-identity auth-providers update my-auth-provider --location=global --project=my-project - POSITIONAL ARGUMENTS
-
-
AuthProvider resource - Identifier. The full resource name of the auth_provider.
Format: projects/{project}/locations/{location}/authProviders/{auth_provider}
The arguments in this group can be used to specify the attributes of this
resource. (NOTE) Some attributes are not given arguments in this group but can
be set in other ways.
To set the
projectattribute:-
provide the argument
auth_provideron the command line with a fully specified name; -
provide the argument
--projecton the command line; -
set the property
core/project.
This must be specified.
AUTH_PROVIDER-
ID of the authProvider or fully qualified identifier for the authProvider.
To set the
auth_providerattribute:-
provide the argument
auth_provideron the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--location=LOCATION-
The location id of the authProvider resource.
To set the
locationattribute:-
provide the argument
auth_provideron the command line with a fully specified name; -
provide the argument
--locationon the command line.
-
provide the argument
-
provide the argument
-
AuthProvider resource - Identifier. The full resource name of the auth_provider.
Format: projects/{project}/locations/{location}/authProviders/{auth_provider}
The arguments in this group can be used to specify the attributes of this
resource. (NOTE) Some attributes are not given arguments in this group but can
be set in other ways.
- FLAGS
-
--description=DESCRIPTION- Description of the resource. Must be less than 256 characters.
--request-id=REQUEST_ID-
An optional request ID to identify requests. Specify a unique request ID so that
if you must retry your request, the server will know to ignore the request if it
has already been completed. The server will guarantee that for at least 60
minutes since the first request.
For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments.
The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).
-
Update allowed_scopes.
At most one of these can be specified:
--allowed-scopes=[ALLOWED_SCOPES,…]- Set allowed_scopes to new value.
-
Or at least one of these can be specified:
--add-allowed-scopes=[ADD_ALLOWED_SCOPES,…]- Add new value to allowed_scopes list.
-
At most one of these can be specified:
--clear-allowed-scopes- Clear allowed_scopes value and set to empty list.
--remove-allowed-scopes=[REMOVE_ALLOWED_SCOPES,…]- Remove existing value from allowed_scopes list.
-
Update blocked_scopes.
At most one of these can be specified:
--blocked-scopes=[BLOCKED_SCOPES,…]- Set blocked_scopes to new value.
-
Or at least one of these can be specified:
--add-blocked-scopes=[ADD_BLOCKED_SCOPES,…]- Add new value to blocked_scopes list.
-
At most one of these can be specified:
--clear-blocked-scopes- Clear blocked_scopes value and set to empty list.
--remove-blocked-scopes=[REMOVE_BLOCKED_SCOPES,…]- Remove existing value from blocked_scopes list.
- AuthProvider type specific parameters. Required when creating an auth_provider.
--clear-auth-provider-type-params- Set authProvider.authProviderTypeParams back to default value.
-
Arguments for the type.
At most one of these can be specified:
- Message describing ApiKeyParams object.
--api-key=API_KEY- The API key for this auth_provider.
- Message describing ThreeLeggedOAuth object.
- The authorization endpoint to send users to for consenting to delegate to the agent. eg. "https://auth.atlassian.com/authorize"
--three-legged-oauth-client-id=THREE_LEGGED_OAUTH_CLIENT_ID- The client ID of the OAuth client.
--three-legged-oauth-client-secret=THREE_LEGGED_OAUTH_CLIENT_SECRET- The client secret of the OAuth client.
--[no-]three-legged-oauth-enable-pkce-
Enables Proof Key for Code Exchange (PKCE) for the OAuth flow to prevent
authorization code interception attacks. Use
--three-legged-oauth-enable-pkceto enable and--no-three-legged-oauth-enable-pkceto disable. --three-legged-oauth-token-url=THREE_LEGGED_OAUTH_TOKEN_URL- The token endpoint for requesting tokens on behalf of an end user. eg. "https://auth.atlassian.com/oauth/token"
- Message describing TwoLeggedOAuth object.
--two-legged-oauth-client-id=TWO_LEGGED_OAUTH_CLIENT_ID- The client ID of the OAuth client.
--two-legged-oauth-client-secret=TWO_LEGGED_OAUTH_CLIENT_SECRET- The client secret of the OAuth client.
--two-legged-oauth-token-url=TWO_LEGGED_OAUTH_TOKEN_URL- The token endpoint of the OAuth client.
-
Update labels.
At most one of these can be specified:
--labels=[LABELS,…]-
Set labels to new value. Labels as key value pairs.
KEY-
Keys must start with a lowercase character and contain only hyphens
(
-), underscores (_), lowercase characters, and numbers. VALUE-
Values must contain only hyphens (
-), underscores (_), lowercase characters, and numbers.
Shorthand Example:--labels=string=string
JSON Example:--labels='{"string": "string"}'
File Example:--labels=path_to_file.(yaml|json)
-
Or at least one of these can be specified:
--update-labels=[UPDATE_LABELS,…]-
Update labels value or add key value pair. Labels as key value pairs.
KEY-
Keys must start with a lowercase character and contain only hyphens
(
-), underscores (_), lowercase characters, and numbers. VALUE-
Values must contain only hyphens (
-), underscores (_), lowercase characters, and numbers.
Shorthand Example:--update-labels=string=string
JSON Example:--update-labels='{"string": "string"}'
File Example:--update-labels=path_to_file.(yaml|json)
-
At most one of these can be specified:
--clear-labels- Clear labels value and set to empty map.
--remove-labels=REMOVE_LABELS-
Remove existing value from map labels. Sets
remove_labelsvalue.Shorthand Example:--remove-labels=string,stringJSON Example:--remove-labels=["string"]
File Example:--remove-labels=path_to_file.(yaml|json)
-
Update workload_ids.
At most one of these can be specified:
--workload-ids=[WORKLOAD_IDS,…]- Set workload_ids to new value.
-
Or at least one of these can be specified:
--add-workload-ids=[ADD_WORKLOAD_IDS,…]- Add new value to workload_ids list.
-
At most one of these can be specified:
--clear-workload-ids- Clear workload_ids value and set to empty list.
--remove-workload-ids=[REMOVE_WORKLOAD_IDS,…]- Remove existing value from workload_ids list.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - API REFERENCE
-
This command uses the
agentidentity/v1alphaAPI. The full documentation for this API can be found at: https://cloud.google.com/iam/docs/ - NOTES
- This command is currently in alpha and might change without notice. If this command fails with API permission errors despite specifying the correct project, you might be trying to access an API with an invitation-only early access allowlist.
gcloud alpha agent-identity auth-providers update
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-06-09 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-06-09 UTC."],[],[]]