Service Account (GCP)
An identity used by applications, VMs, and automated processes to authenticate to Google Cloud APIs, rather than by a human user. A Service Account is itself also a resource with its own IAM permissions, and can be attached directly to a VM or impersonated temporarily, both safer alternatives to downloading its long-lived JSON key file.
Frequently Asked Questions
How is a GCP service account different from a regular user account?
A service account isn't tied to a person — it's an identity your code, VM, or pipeline authenticates as, and it exists as its own IAM-manageable resource (with an email like name@project.iam.gserviceaccount.com). You grant it roles just like a user, but nobody logs into it interactively. It's also the identity you attach to Compute Engine VMs or Cloud Run services so the workload can call other GCP APIs without embedding credentials in code.
What's the biggest security mistake teams make with GCP service accounts?
Downloading a long-lived JSON key file and hardcoding it into an app or committing it to a repo. Keys don't expire on their own and are a top cause of GCP credential leaks. The safer pattern is attaching the service account directly to the compute resource (Workload Identity for GKE, or the VM's attached identity) or using short-lived impersonation via `gcloud auth print-access-token --impersonate-service-account`, avoiding a static key entirely.