Agent skill

Google Cloud Auth

by davila7 in davila7/claude-code-templates

Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for…

MITAuto-check passedBackend & APIs

Install Google Cloud Auth

skills CLI
$ npx skills add davila7/claude-code-templates --skill google-cloud-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davila7/claude-code-templates google-cloud-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davila7/claude-code-templates.git skills-src && mkdir -p .claude/skills && cp -r skills-src/cli-tool/components/skills/security/google-cloud-auth .claude/skills/google-cloud-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-auth
GitHub stars
33k
Token cost
~3k tokens
SKILL.md length
1,271 words
Files
1
Skills in repo
479
Repo updated
First seen
Licence
MIT

At a glance

Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for…

  • Works in 4 steps: Who or what is authenticating? (A human… → Where is the code running? (Local… → What is the target? (A Google Cloud API… → …
  • Backend & APIs work in your project
  • SKILL.md covers Authentication, Human Authentication, Service-to-Service… and Authorization, plus 3 more sections
  • Calls gcloud; needs GOOGLE_APPLICATION_CREDENTIALS

What it does

Google Cloud Auth is an agent skill from davila7/claude-code-templates. Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for secure access.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. It works with Google Cloud. The repository describes itself as: CLI tool for configuring and monitoring Claude Code. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “Use the google-cloud-auth skill to provide expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human…”
  • “/google-cloud-auth”

Requirements

  • Python 3
  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Who or what is authenticating? (A human developer, a local script, or an
  2. Where is the code running? (Local laptop, [Compute
  3. What is the target? (A Google Cloud API like Storage/BigQuery, or a
  4. Are you using a high-level client library? (e.g., Python, Go, Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit c0ca7da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.cloud.google.com
    • console.cloud.google.com
    • workspace.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GOOGLE_APPLICATION_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Auth loads about 3k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 1,271 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davila7/claude-code-templates at commit c0ca7da, republished under its MIT licence (© davila7). 1,271 words, ~3,022 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-auth/SKILL.md (or your agent's skills folder).
name
google-cloud-auth
description
Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for secure access.
source
google/skills (Apache 2.0)

Authenticating to Google Cloud

Authentication is the process of proving who you are. In Google Cloud, you represent a Principal (an identity like a user or a service). This is the first step before Authorization (determining what you can do).

Authentication

Clarifying Questions for the Agent

Before providing a specific solution, clarify the following with the user:

  1. Who or what is authenticating? (A human developer, a local script, or an application running in production?)
  2. Where is the code running? (Local laptop, Compute Engine, GKE, Cloud Run, or another cloud like AWS/Azure?)
  3. What is the target? (A Google Cloud API like Storage/BigQuery, or a custom application you built?)
  4. Are you using a high-level client library? (e.g., Python, Go, Node.js libraries usually handle ADC automatically.)

Human Authentication

For users to access Google Cloud, they need an identity that Google Cloud can recognize.

Types of User Identities

Google Cloud supports several ways to configure identities for your internal workforce (developers, administrators, employees):

  • Google-Managed Accounts: You can use Cloud Identity or Google Workspace to create managed user accounts. These are called managed accounts because your organization controls their lifecycle and configuration.
  • Federation using Cloud Identity or Google Workspace: You can federate identities to allow users to use their existing identity and credentials to sign in to Google services. Users authenticate against an external identity provider (IdP), but you must keep accounts synchronized into Google Cloud using tools like Google Cloud Directory Sync (GCDS) or an external authoritative source like Active Directory or Microsoft Entra ID.
  • Workforce Identity Federation: This lets you use an external IdP to authenticate and authorize a workforce using IAM directly. Unlike standard federation, you do not need to synchronize user identities from your existing IdP to Google Cloud identities. It supports syncless, attribute-based single sign-on.
Methods of Access for Developers and Administrators

Used for interacting with Google Cloud resources and APIs during development and management.

  • Google Cloud Console: The primary web interface. You authenticate using your Google Account (Gmail or Google Workspace).
  • gcloud CLI (gcloud auth login): Used to authenticate the CLI itself so you can run management commands (e.g., gcloud compute instances list). It uses a Credential (like an OAuth 2.0 refresh token) stored locally.
  • Local Development with App Default Credentials (ADC) (gcloud auth application-default login): This is different from CLI auth. It creates a local JSON file that Google Cloud Client Libraries (Python, Java, etc.) use to act as "you" when you run code on your laptop.
  • Service Account Impersonation: For security reasons, developers should avoid downloading Service Account keys entirely. Instead, they should authenticate as humans (gcloud auth login) and use Service Account Impersonation to run CLI commands or generate short-lived credentials. This is a critical best practice for local development and troubleshooting.
For End-Users and Customers

Used when a human (who is not a developer) needs to access a web application you've deployed on Google Cloud. Note: These are distinct from workforce identities.

  • Identity-Aware Proxy (IAP): Acts as a central authorization layer for web applications. It intercepts web requests and verifies the user's identity (via Google Workspace, Cloud Identity, or external providers) before letting them reach the application. It's often used to protect internal apps without a VPN, or secure customer portals.
  • Identity Platform: A Customer Identity and Access Management (CIAM) solution for adding consumer sign-in (email/password, phone, social) directly into the code of your custom-built applications.

Service-to-Service Authentication

When code runs in production, it should use a Service Account rather than a human user account.

Service Accounts and Service Agents
  • Service Account: A special identity intended for non-human users. It's like a "robot identity" with its own email address.
  • Service Agent: A service account managed by Google that allows a service (like Pub/Sub) to access your resources on your behalf.
Best Practice: Attaching Service Accounts

Instead of using Service Account Keys (dangerous JSON files), you should attach a custom service account to the Google Cloud resource. The resource's environment then provides a Token (a short-lived digital object) via a local metadata server.

  • Compute Engine: Assign a service account during VM creation.
  • Cloud Run: Assign a service account in the service configuration.
Special Cases & Advanced Topics
Kubernetes Engine (GKE)

Use Workload Identity Federation for GKE to map Kubernetes identities to IAM principal identifiers. This grants specific Kubernetes workloads access to specific Google Cloud APIs. Learn more here.

External Workloads (Workload Identity Federation)

For code running outside Google Cloud (e.g., AWS, Azure, or on-prem), do not use keys. Instead, use Workload Identity Federation to exchange an external token (like an AWS IAM role) for a short-lived Google Cloud access token.

Show full SKILL.md (504 more words)Show less
API Keys

API keys are encrypted strings used for public data (e.g., Google Maps) or simplified access like Vertex AI Express Mode, which allows fast testing of Gemini models without complex setup. Both humans and services (e.g., Cloud Run-based AI agent) can use API keys, for the services that support it.

Note: API keys should be restricted to specific APIs and projects to minimize security risks. Store API keys in a secrets manager like Secret Manager to prevent accidental exposure.

OAuth 2.0 Access Scopes

While IAM is the modern way to handle authorization, legacy Compute Engine VMs and GKE node pools still rely on Access Scopes alongside IAM. If a VM's scope is restricted, the attached service account will fail to make API calls even if it has the correct IAM permissions. Check this first if attached service accounts are failing unexpectedly.

Short-Lived Credentials

The underlying mechanism for impersonation and secure service-to-service communication is the IAM Service Account Credentials API. This API generates short-lived access tokens, OpenID Connect (OIDC) ID tokens, or self-signed JSON Web Tokens (JWTs) dynamically, removing the need for static credentials.


Authorization

After Authentication, Google Cloud uses Identity and Access Management (IAM) to determine what the authenticated principal can do.

  • Allow Policy: A record that binds a Principal to a Role on a Resource.
  • Predefined Roles: Prebuilt roles like roles/storage.objectViewer or roles/bigquery.dataEditor. Always try to use these first.
  • Custom Roles: User-defined collections of specific permissions if predefined roles are too broad.

Examples

Human-to-Service (Local Python Development)
  1. Authn: Run gcloud auth application-default login to create local credentials (ADC).
  2. Authz: Grant your email the roles/storage.objectViewer role on a bucket.
  3. Code: Use the Python storage.Client(). It automatically finds your local credentials via ADC. Note: ADC searches in a specific order—first checking the GOOGLE_APPLICATION_CREDENTIALS environment variable, then the local gcloud JSON file, and finally the attached service account metadata server.
Service-to-Service (Cloud Run to Cloud SQL)
  1. Authn: Attach a custom Service Account to your Cloud Run service.
  2. Authz: Grant that Service Account the roles/cloudsql.client role on the project.
  3. Code: The Cloud Run environment provides the token automatically to the connection driver.
Calling a Custom Application (OIDC)

When calling a private Cloud Run service from another service, the caller generates a Google-signed OpenID Connect (OIDC) ID Token and passes it in the Authorization: Bearer <TOKEN> header.


Validation Checklist

  • Is the user running code locally? Suggest gcloud auth application-default login or Service Account Impersonation.
  • Is the user attempting to use Service Account keys locally? Strongly discourage this and recommend impersonation.
  • Is the user running in production? Recommend attaching a custom, least-privilege service account, NOT using keys.
  • Is the user relying on the Compute Engine Default Service Account? Recommend creating a custom service account instead.
  • Is the user running on another cloud? Recommend Workload Identity Federation.
  • Is the user calling a custom app? Recommend OIDC ID Tokens.
  • Has the user restricted their API Keys? Check for appropriate API Key Restrictions.

References

© davila7, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in cli-tool/components/skills/security/google-cloud-auth of davila7/claude-code-templates.

Open the folder on GitHubat commit c0ca7da

Compare with similar skills

Google Cloud Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Auth this skilldavila7/claude-code-templates33k—~3kAutomated safety check: PassMIT
Windmill Trigger Type Checklistwindmill-labs/windmill18k—~4.7kAutomated safety check: PassCustom licence
Polylith Base CreationDavidVujic/python-polylith554—~757Automated safety check: PassMIT
Liveapi ServiceGoogleCloudPlatform/vertex-ai-samples792—~1.2kAutomated safety check: PassApache-2.0
Ghealth SharedGoogle-Health-API/google-health-cli266—~1.7kAutomated safety check: PassApache-2.0
Serverless IntegrationsDataDog/dd-trace-js837—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Windmill Trigger Type Checklist

    windmill-labs/windmill

    Checklist of every backend, frontend, CLI and capture change needed to add a new TriggerCrud-based trigger type, such as Azure, GCP or Kafka, to Windmill.

    18k GitHub stars~4.7k tokensUpdated today
    Backend & APIsAuto-check passed
  • Polylith Base Creation

    DavidVujic/python-polylith

    Create a Polylith base with poly create base — the entry point of a deployable application (HTTP API, CLI, message-queue consumer, AWS Lambda handler, GCP Cloud Function, scheduled job).

    554 GitHub stars~757 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Liveapi Service

    GoogleCloudPlatform/vertex-ai-samples

    Generates a LiveAPI client service class in the user's chosen programming language.

    792 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ghealth Shared

    Google-Health-API/google-health-cli

    Shared prerequisites for all ghealth skills — auth, setup, global flags, command structure

    266 GitHub stars~1.7k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Serverless Integrations

    DataDog/dd-trace-js

    Official

    A skill your agent uses when adding, modifying, debugging, or reviewing dd-trace-js serverless platform integrations that create root invocation spans for AWS Lambda, Azure Functions, Google Cloud…

    837 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Interactive Login

    yc-software/qm

    Log a CLI in with a browser/device-code flow (aws sso, gh, glab, gcloud, …) and save the result to the keychain so later commands can request it through execute.credentials.

    15k GitHub stars~635 tokensUpdated today
    Backend & APIsAuto-check passed

More from davila7/claude-code-templates

All 479 skills in this repo
  • Perplexity Web Search

    davila7/claude-code-templates

    Runs web-grounded searches through Perplexity's Sonar models over OpenRouter for current events, recent literature and cited facts beyond the model's training cutoff.

    33k GitHub starsUsed in 11 repos~3.5k tokens
    Auto-check: notes
  • Neuropixels Data Analysis

    davila7/claude-code-templates

    Analyzes Neuropixels recordings from SpikeGLX or Open Ephys through preprocessing, drift correction, Kilosort4 spike sorting, quality metrics and curation.

    33k GitHub starsUsed in 9 repos~2.8k tokens
    Auto-check passed
  • Scientific Venue Templates

    davila7/claude-code-templates

    Supplies LaTeX templates and formatting rules for journals, conferences, posters, and grant proposals, then can check a draft against them.

    33k GitHub starsUsed in 9 repos~5.1k tokens
    Auto-check: notes
  • Brand Voice Content Creator

    davila7/claude-code-templates

    Analyzes a brand's existing writing to lock in a consistent voice, then builds SEO blog posts and platform-specific social content around it.

    33k GitHub starsUsed in 3 repos~1.9k tokens
    Auto-check passed
  • CAPA Officer

    davila7/claude-code-templates

    Guides corrective and preventive action (CAPA) work in a quality management system, from initiation and root cause analysis through effectiveness verification.

    33k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Fda Consultant Specialist

    davila7/claude-code-templates

    Senior FDA consultant and specialist for medical device companies including HIPAA compliance and requirement management.

    33k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed

Works with

Categories

Questions about Google Cloud Auth

What does Google Cloud Auth do?

Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for…. Google Cloud Auth is an agent skill from davila7/claude-code-templates. Provides expert guidance on authenticating and authorizing to Google Cloud services and APIs, covering human users, service identities, Application Default Credentials (ADC), and best practices for secure access.

When should I use Google Cloud Auth?

Google Cloud Auth fits situations like: backend & APIs work in your project.

How do I install Google Cloud Auth in Claude Code?

Run `npx skills add davila7/claude-code-templates --skill google-cloud-auth -a claude-code`. Or copy the skill folder (cli-tool/components/skills/security/google-cloud-auth in davila7/claude-code-templates) into .claude/skills/google-cloud-auth in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Auth in Codex?

Run `npx skills add davila7/claude-code-templates --skill google-cloud-auth -a codex`. Or copy the skill folder (cli-tool/components/skills/security/google-cloud-auth in davila7/claude-code-templates) into .agents/skills/google-cloud-auth in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davila7/claude-code-templates --skill google-cloud-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-auth, .gemini/skills/google-cloud-auth, .github/skills/google-cloud-auth and .opencode/skills/google-cloud-auth in your project.

What does Google Cloud Auth need to run?

Going by SKILL.md and its folder, Google Cloud Auth needs the command-line tools its instructions call (gcloud) and credentials named GOOGLE_APPLICATION_CREDENTIALS. Our summary lists: Python 3; Node.js.

Does Google Cloud Auth access the network?

SKILL.md names 3 domains. As links in the text: docs.cloud.google.com, console.cloud.google.com and workspace.google.com. This is read from the text; nothing was executed.

Is Google Cloud Auth safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Auth use?

Google Cloud Auth is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Auth use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Google Cloud Auth?

Skills that share tags, products or a category with Google Cloud Auth: Windmill Trigger Type Checklist (windmill-labs/windmill, 18k stars), Polylith Base Creation (DavidVujic/python-polylith, 554 stars), Liveapi Service (GoogleCloudPlatform/vertex-ai-samples, 792 stars) and Ghealth Shared (Google-Health-API/google-health-cli, 266 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Auth?

davila7 (a GitHub user) maintains it in davila7/claude-code-templates, which has 32,512 GitHub stars. The repository holds 479 skills in this directory. The repository was last updated on October 10, 2026.

Source: davila7/claude-code-templates on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.