- HTTP request
- Path parameters
- Request body
- Response body
- Authorization scopes
- IAM Permissions
- Try it!
Returns the Shielded VM Identity of an instance
HTTP request
GET https://compute.googleapis.com/compute/beta/projects/{project}/zones/{zone}/instances/{instance}/getShieldedVmIdentity
The URLs use gRPC Transcoding syntax.
Path parameters
| Parameters | |
|---|---|
project
|
Project ID for this request. |
zone
|
The name of the zone for this request. |
instance
|
Name of the instance scoping this request. |
Request body
The request body must be empty.
Response body
A Shielded VM Identity.
If successful, the response body contains data with the following structure:
| JSON representation |
|---|
{ "kind" : string , "signingKey" : { "ekCert" : string , "ekPub" : string } , "encryptionKey" : { "ekCert" : string , "ekPub" : string } } |
| Fields | |
|---|---|
kind
|
Output only. Type of the resource. Always |
signingKey
|
An Attestation Key (AK) issued to the Shielded VM's vTPM. |
signingKey.ekCert
|
A PEM-encoded X.509 certificate. This field can be empty. |
signingKey.ekPub
|
A PEM-encoded public key. |
encryptionKey
|
An Endorsement Key (EK) issued to the Shielded VM's vTPM. |
encryptionKey.ekCert
|
A PEM-encoded X.509 certificate. This field can be empty. |
encryptionKey.ekPub
|
A PEM-encoded public key. |
Authorization scopes
Requires one of the following OAuth scopes:
-
https://www.googleapis.com/auth/compute.readonly -
https://www.googleapis.com/auth/compute -
https://www.googleapis.com/auth/cloud-platform
For more information, see the Authentication Overview .
IAM Permissions
In addition to any permissions specified on the fields above, authorization requires one or more of the following IAM permissions:
-
compute.instances.getShieldedVmIdentity
To find predefined roles that contain those permissions, see Compute Engine IAM Roles .

