One read of Claude Documentationclaude-docs-20260926T050705Z
2 pages moved out of 255 read.
Pages moved
2
significant first
Pages read
255
in this capture
Captured
05:07 UTC
Corpus hash
81b321640b46
corpus-hash
What this read moved
1-2 of 2claude-tag/admins/federated-access/limits Changed · +8 / -8 lines
from line 44
4444
4545## Google Cloud identities
4646
47| Limit | Value |
48| :------------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always. Effective permissions come from IAM. |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
47| Limit | Value |
48| :------------------------------------------- | :--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
49| **Workload identity provider** | The full resource name of a provider in a workload identity pool under a numeric project, `//iam.googleapis.com/projects/<number>/locations/global/workloadIdentityPools/<pool>/providers/<provider>`. Workforce identity pools aren't supported. |
50| **Service account to act as** | Optional. A service account, `<name>@<project>.iam.gserviceaccount.com`. Default compute and App Engine service accounts aren't accepted. Leave it empty to call Google Cloud as the federated identity itself. |
51| **Allowed Google hosts** | `googleapis.com`, a subdomain of it, or a subdomain of `clients6.google.com`. |
52| OAuth scope | `https://www.googleapis.com/auth/cloud-platform`, always, with no setting to change it. On Google Cloud APIs, IAM decides what the credential can do. An API that needs an OAuth scope of its own answers 403 whatever IAM allows; see [The cloud API answers 403 after a successful exchange](/docs/claude-tag/admins/federated-access/troubleshooting#the-cloud-api-answers-403-after-a-successful-exchange). |
53| **Block requests that mint new credentials** | On by default. When on, requests to Google's credential-minting and credential-delivering endpoints are refused, including over gRPC; see [What the credential-minting block refuses](#what-the-credential-minting-block-refuses). The block is best effort and doesn't replace least-privilege IAM. |
54| Google Cloud connections in one bundle | No two Google Cloud connections in the same Access bundle can cover the same host under **Allowed hosts**, whatever their providers or service accounts. A wildcard such as `*.googleapis.com` covers every subdomain but not `googleapis.com` itself. The same provider can be connected again with different hosts, or in another bundle. |
5555
5656### What the credential-minting block refuses
5757
claude-tag/admins/federated-access/troubleshooting Changed · +15 / -9 lines
from line 225
225225
226226**What you see**
227227
228Claude reports a 403 from an AWS or Google Cloud API, with the provider's own error body rather than a reason beginning "request blocked".
228Claude reports a 403 from an AWS or Google API, with the provider's own error body rather than a reason beginning "request blocked".
229229
230230**What it means**
231231
232The token exchange worked and Claude called the API with the exchanged credential, but the role or identity lacks permission for that action. For Google Cloud, the exchange always requests the `cloud-platform` scope, so IAM alone decides what the credential can do.
232The token exchange worked and Claude called the API with the exchanged credential, but the API refused the call for one of these reasons:
233233
234* **A missing permission.** The role or identity lacks permission for that action.
235* **A Google API that needs an OAuth scope of its own.** For Google Cloud, the exchange always requests the `https://www.googleapis.com/auth/cloud-platform` scope, and there's no setting to change it. Google Cloud APIs accept that scope, and IAM decides what the credential can do on those APIs. APIs that need an OAuth scope of their own, such as the Google Drive, Calendar, and Gmail APIs, answer 403 for insufficient scopes whatever IAM allows.
236
237If the 403 comes from a Google Cloud API, such as Cloud Storage, the OAuth scope isn't the cause, so check the permission. If the 403 comes from an API that needs an OAuth scope of its own, such as the Google Drive, Calendar, or Gmail API, the cause is the OAuth scope.
238
234239**How to resolve**
235240
236Grant the IAM permission to the AWS role, the Google Cloud service account, or the federated identity when no service account is named. For AWS, a 403 also makes Claude assume the role again on the next request, so a fix takes effect on the next try.
241* **A missing permission.** Grant the IAM permission to the AWS role, the Google Cloud service account, or the federated identity when no service account is named. For AWS, a 403 also makes Claude assume the role again on the next request, so a fix takes effect on the next try.
242* **A Google API that needs an OAuth scope of its own.** A federated connection can't reach that API. To connect Google Drive, Calendar, or Gmail another way, see [Choose OAuth or a service account](/docs/claude-tag/admins/connections/google#choose-oauth-or-a-service-account). If a channel gets both that connection and the federated connection, keep the two from covering the same host; see [Which credential wins](/docs/claude-tag/admins/attach-to-scope#which-credential-wins).
237243
238244## Rejections in your own logs
239245