Skip to content

GCP.CloudIdentity reference

Source: src/GCP/CloudIdentity/Device.ts

A Cloud Identity company-owned device.

Device create is limited to company-owned inventory (Enterprise / Cloud Identity Premium). There is no update API — serial number, type, and customer are identity. Alchemy stamps ownership into assetTag for list / nuke.

Generated serial

const device = yield* GCP.CloudIdentity.Device("Laptop", {
deviceType: "LINUX",
hostname: "eng-laptop",
});

Explicit serial and asset tag

const device = yield* GCP.CloudIdentity.Device("Laptop", {
serialNumber: "HT82V1A01076",
deviceType: "LINUX",
assetTag: "desk-14",
});

Source: src/GCP/CloudIdentity/Group.ts

A Cloud Identity / Google Group.

Groups have no user labels, so Alchemy identifies a group by its key (email): a group found under the generated key is adopted, one found under an explicit groupKeyId without state is reported as unowned. parent and groupKeyId are identity; display name, description, and labels update in place.

Generated email on a Workspace domain

const group = yield* GCP.CloudIdentity.Group("Eng", {
parent: "customers/my_customer",
domain: "example.com",
displayName: "Engineering",
});

Explicit group key

const group = yield* GCP.CloudIdentity.Group("Eng", {
parent: "customers/C046psxkn",
groupKeyId: "eng@example.com",
displayName: "Engineering",
description: "product engineering",
});
const group = yield* GCP.CloudIdentity.Group("Eng", {
groupKeyId: "eng@example.com",
displayName: "Engineering 2026",
});

Source: src/GCP/CloudIdentity/GroupsMembership.ts

A Cloud Identity group membership.

Memberships have no labels or description, so Alchemy lists memberships of alchemy-owned groups (ownership stamped on the parent group description) for list / nuke. Parent group and member key are identity; roles update in place via modifyMembershipRoles.

Add a member

const membership = yield* GCP.CloudIdentity.GroupsMembership("Ada", {
parent: group.name,
memberKeyId: "ada@example.com",
});

Manager role

const membership = yield* GCP.CloudIdentity.GroupsMembership("Ada", {
parent: group.name,
memberKeyId: "ada@example.com",
roles: [{ name: "MEMBER" }, { name: "MANAGER" }],
});

Source: src/GCP/CloudIdentity/InboundOidcSsoProfile.ts

An inbound OIDC SSO profile for a Google enterprise customer.

Profiles have no labels field, so Alchemy stamps ownership into displayName for list / nuke. customer is identity; display name and IdP / RP config update in place.

const profile = yield* GCP.CloudIdentity.InboundOidcSsoProfile("Okta", {
displayName: "Okta",
idpConfig: { issuerUri: "https://idp.example.com" },
rpConfig: { clientId: "google-rp", clientSecret: "secret" },
});

Source: src/GCP/CloudIdentity/InboundSamlSsoProfile.ts

An inbound SAML 2.0 SSO profile for a Google enterprise customer.

Profiles have no labels field, so Alchemy stamps ownership into displayName for list / nuke. customer is identity; display name and IdP config update in place.

const profile = yield* GCP.CloudIdentity.InboundSamlSsoProfile("Okta", {
displayName: "Okta",
idpConfig: {
entityId: "https://idp.example.com/metadata",
singleSignOnServiceUri: "https://idp.example.com/sso",
},
});

Source: src/GCP/CloudIdentity/InboundSsoAssignment.ts

An inbound SSO assignment for a Cloud Identity group or org unit.

Assignments have no labels or description, so Alchemy lists assignments whose targetGroup is an alchemy-owned group for list / nuke. Customer, target group, and target org unit are identity; mode, rank, and IdP details update in place.

InboundSsoAssignment: Creating an Assignment

Section titled “InboundSsoAssignment: Creating an Assignment”
const assignment = yield* GCP.CloudIdentity.InboundSsoAssignment(
"EngSso",
{
targetGroup: group.name,
ssoMode: "SAML_SSO",
rank: 1,
samlSsoInfo: { inboundSamlSsoProfile: profile.name },
},
);