API Keys
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for apikeys.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| google. | Creates a new API key. | activity | Y | Y |
| google. | Deletes an API key. | activity | Y | N |
| google. | Get the key string for an API key. The API redacts the value by default; request unredacted_key on GetKeyRequest to see the plaintext value. | data_access | Y | Y |
| google. | Patches the modifiable fields of an API key. | activity | Y | N |
any: apikeys.googleapis.com (any method)
#Description
Catch-all entry for apikeys.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
google.api.apikeys.ApiKeys.CreateKey: Create API key
#Description
Creates a new API key.
Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
protoPayload.authorizationInfo | 1 detection rule | Panther |
protoPayload.authorizationInfo.permission | 1 detection rule | Panther |
protoPayload.methodName | 1 detection rule | Panther |
Example Audit Log Entry #
{
"insertId": "opbxpxd9bcy",
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operations/akmf.p7-000000000000-029e3f13-16b5-408f-a350-29d6f873d1de",
"last": true,
"producer": "apikeys.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "serviceusage.apiKeys.create",
"permissionType": "ADMIN_WRITE",
"resource": "projectnumbers/000000000000",
"resourceAttributes": {}
}
],
"methodName": "google.api.apikeys.v2.ApiKeys.CreateKey",
"request": {
"@type": "type.googleapis.com/google.api.apikeys.v2.CreateKeyRequest",
"key": {},
"parent": "projects/example-project-id/locations/global"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.services.api-keys.create invocation-id/18179842e0c443a4ae7ae5527a44b0fc environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {}
},
"resourceName": "projects/000000000000",
"response": {
"@type": "type.googleapis.com/google.api.apikeys.v2.Key",
"createTime": "1970-01-01T00:00:00Z",
"etag": "W/\"Kr6K7OinhBDoItUr6CmKqQ==\"",
"name": "projects/000000000000/locations/global/keys/bde4a9e3-70bb-4e9d-9d8f-a7e0fa9f48e3",
"updateTime": "1970-01-01T00:00:00Z"
},
"serviceName": "apikeys.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T13:22:19.628725316Z",
"resource": {
"labels": {
"method": "google.api.apikeys.v2.ApiKeys.CreateKey",
"project_id": "example-project-id",
"service": "apikeys.googleapis.com"
},
"type": "audited_resource"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T13:22:19.628725316Z"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1548
google.api.apikeys.ApiKeys.DeleteKey: Delete API key
#Description
Deletes an API key.
Example Audit Log Entry #
{
"insertId": "-ksd9nycago",
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operations/akmf.p12-000000000000-4572acfc-fd42-4769-b869-426b1080af33",
"last": true,
"producer": "apikeys.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "serviceusage.apiKeys.delete",
"permissionType": "ADMIN_WRITE",
"resource": "apikeys/000000000000/9ece34fd-6a5e-44cd-9248-85c55e792731",
"resourceAttributes": {}
}
],
"methodName": "google.api.apikeys.v2.ApiKeys.DeleteKey",
"request": {
"@type": "type.googleapis.com/google.api.apikeys.v2.DeleteKeyRequest",
"name": "projects/000000000000/locations/global/keys/9ece34fd-6a5e-44cd-9248-85c55e792731"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.services.api-keys.delete invocation-id/c49ea0b646784d859cdc82f48e905691 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/False python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {}
},
"resourceName": "projects/000000000000/locations/global/keys/9ece34fd-6a5e-44cd-9248-85c55e792731",
"response": {
"@type": "type.googleapis.com/google.api.apikeys.v2.Key",
"createTime": "1970-01-01T00:00:00Z",
"deleteTime": "1970-01-01T00:00:00Z",
"etag": "W/\"aS5xt8kfEzTigm5z3k9P0Q==\"",
"name": "projects/000000000000/locations/global/keys/9ece34fd-6a5e-44cd-9248-85c55e792731",
"updateTime": "1970-01-01T00:00:00Z"
},
"serviceName": "apikeys.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:38:11.101942234Z",
"resource": {
"labels": {
"method": "google.api.apikeys.v2.ApiKeys.DeleteKey",
"project_id": "example-project-id",
"service": "apikeys.googleapis.com"
},
"type": "audited_resource"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T16:38:11.101942234Z"
}
google.api.apikeys.ApiKeys.GetKeyString: Get key string
#Description
Get the key string for an API key. The API redacts the value by default; request unredacted_key on GetKeyRequest to see the plaintext value.
Data Access audit logs are disabled by default. Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Fields #
Name Rules Vendors metadata.log_type1 detection rule YARA-L security_result.action1 detection rule YARA-L target.application1 detection rule YARA-L Example Audit Log Entry #
{
"insertId": "83a44ncdcl",
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Fdata_access",
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "apikeys.keys.getKeyString",
"permissionType": "ADMIN_READ",
"resource": "apikeys/000000000000/9ece34fd-6a5e-44cd-9248-85c55e792731",
"resourceAttributes": {
"name": "apikeys/000000000000/9ece34fd-6a5e-44cd-9248-85c55e792731",
"service": "apikeys.googleapis.com"
}
},
{
"granted": true,
"permission": "apikeys.keys.getKeyString",
"permissionType": "ADMIN_READ",
"resource": "apikeys/000000000000/9ece34fd-6a5e-44cd-9248-85c55e792731",
"resourceAttributes": {}
}
],
"methodName": "google.api.apikeys.v2.ApiKeys.GetKeyString",
"request": {
"@type": "type.googleapis.com/google.api.apikeys.v2.GetKeyStringRequest",
"name": "projects/000000000000/locations/global/keys/9ece34fd-6a5e-44cd-9248-85c55e792731"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.services.api-keys.get-key-string invocation-id/d54c9a7337b44bc4ac6af31e40f8d365 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {}
},
"resourceName": "projects/000000000000/locations/global/keys/9ece34fd-6a5e-44cd-9248-85c55e792731",
"serviceName": "apikeys.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T16:27:33.435694396Z",
"resource": {
"labels": {
"method": "google.api.apikeys.v2.ApiKeys.GetKeyString",
"project_id": "example-project-id",
"service": "apikeys.googleapis.com"
},
"type": "audited_resource"
},
"severity": "INFO",
"timestamp": "2026-06-29T16:27:32.810854Z"
}
Detection Rules #
YARA-L #
T1555
google.api.apikeys.ApiKeys.UpdateKey: Update API key
#Description
Patches the modifiable fields of an API key.
Example Audit Log Entry #
{
"insertId": "rj15l4dacr8",
"logName": "projects/example-project-id/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operations/akmf.p10-000000000000-152942d1-1b05-4dcf-a873-3faa8064f1fd",
"last": true,
"producer": "apikeys.googleapis.com"
},
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"oauthInfo": {
"oauthClientId": "32555940559.apps.googleusercontent.com"
},
"principalEmail": "user@example.com",
"principalSubject": "user:user@example.com"
},
"authorizationInfo": [
{
"granted": true,
"permission": "serviceusage.apiKeys.update",
"permissionType": "ADMIN_WRITE",
"resource": "apikeys/000000000000/94e13b18-4900-42b3-903e-aed2007389f6",
"resourceAttributes": {}
}
],
"methodName": "google.api.apikeys.v2.ApiKeys.UpdateKey",
"request": {
"@type": "type.googleapis.com/google.api.apikeys.v2.UpdateKeyRequest",
"key": {
"name": "projects/example-project-id/locations/global/keys/94e13b18-4900-42b3-903e-aed2007389f6"
},
"updateMask": "displayName"
},
"requestMetadata": {
"callerIp": "203.0.113.10",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/574.0.0 agent-name/claude_code command/gcloud.services.api-keys.update invocation-id/31e6926c06ae49eeaabb0b50116762c9 environment/None environment-version/None client-os/LINUX client-os-ver/6.1.0 client-pltf-arch/x86_64 interactive/False from-script/True python/3.14.5 term/tmux-256color (Linux 6.1.0-41-amd64),gzip(gfe)",
"destinationAttributes": {},
"requestAttributes": {}
},
"resourceName": "projects/example-project-id/locations/global/keys/94e13b18-4900-42b3-903e-aed2007389f6",
"response": {
"@type": "type.googleapis.com/google.api.apikeys.v2.Key",
"createTime": "1970-01-01T00:00:00Z",
"etag": "W/\"LwNHUPemNwAPadDfOgVwVg==\"",
"name": "projects/000000000000/locations/global/keys/94e13b18-4900-42b3-903e-aed2007389f6",
"updateTime": "1970-01-01T00:00:00Z"
},
"serviceName": "apikeys.googleapis.com",
"status": {}
},
"receiveTimestamp": "2026-06-29T14:34:41.058859623Z",
"resource": {
"labels": {
"method": "google.api.apikeys.v2.ApiKeys.UpdateKey",
"project_id": "example-project-id",
"service": "apikeys.googleapis.com"
},
"type": "audited_resource"
},
"severity": "NOTICE",
"timestamp": "2026-06-29T14:34:41.058859623Z"
}