HEX
Server: Apache/2.4.65 (Ubuntu)
System: Linux ielts-store-v2 6.8.0-1036-gcp #38~22.04.1-Ubuntu SMP Thu Aug 14 01:19:18 UTC 2025 x86_64
User: root (0)
PHP: 7.2.34-54+ubuntu20.04.1+deb.sury.org+1
Disabled: pcntl_alarm,pcntl_fork,pcntl_waitpid,pcntl_wait,pcntl_wifexited,pcntl_wifstopped,pcntl_wifsignaled,pcntl_wifcontinued,pcntl_wexitstatus,pcntl_wtermsig,pcntl_wstopsig,pcntl_signal,pcntl_signal_get_handler,pcntl_signal_dispatch,pcntl_get_last_error,pcntl_strerror,pcntl_sigprocmask,pcntl_sigwaitinfo,pcntl_sigtimedwait,pcntl_exec,pcntl_getpriority,pcntl_setpriority,pcntl_async_signals,
Upload Files
File: //snap/google-cloud-cli/396/help/man/man1/gcloud_alpha_transfer_authorize.1
.TH "GCLOUD_ALPHA_TRANSFER_AUTHORIZE" 1



.SH "NAME"
.HP
gcloud alpha transfer authorize \- authorize an account for all Transfer Service features



.SH "SYNOPSIS"
.HP
\f5gcloud alpha transfer authorize\fR [\fB\-\-add\-missing\fR] [\fB\-\-creds\-file\fR=\fICREDS_FILE\fR] [\fIGCLOUD_WIDE_FLAG\ ...\fR]



.SH "DESCRIPTION"

\fB(ALPHA)\fR Authorize a Google account for all Transfer Service features.

This command provides admin and owner rights for simplicity. If that's too much
authority for your use case, see custom setups here:
https://cloud.google.com/storage\-transfer/docs/on\-prem\-set\-up



.SH "EXAMPLES"

To see what Transfer Service IAM roles the account logged into gcloud may be
missing, run:

.RS 2m
$ gcloud alpha transfer authorize
.RE

To add the missing IAM roles, run:

.RS 2m
$ gcloud alpha transfer authorize \-\-add\-missing
.RE

To check a custom service account for missing roles, run:

.RS 2m
$ gcloud alpha transfer authorize \e
    \-\-creds\-file=path/to/service\-account\-key.json
.RE



.SH "FLAGS"

.RS 2m
.TP 2m
\fB\-\-add\-missing\fR

Add IAM roles necessary to use all Transfer Service features to the specified
account. By default, this command just prints missing roles.

.TP 2m
\fB\-\-creds\-file\fR=\fICREDS_FILE\fR

The path to the creds file for an account to authorize. The file should be in
JSON format and contain a "type" and "client_email", which are automatically
generated for most creds files downloaded from Google (e.g. service account
tokens). If this flag is not present, the command authorizes the user currently
logged into gcloud.


.RE
.sp

.SH "GCLOUD WIDE FLAGS"

These flags are available to all commands: \-\-access\-token\-file, \-\-account,
\-\-billing\-project, \-\-configuration, \-\-flags\-file, \-\-flatten,
\-\-format, \-\-help, \-\-impersonate\-service\-account, \-\-log\-http,
\-\-project, \-\-quiet, \-\-trace\-token, \-\-user\-output\-enabled,
\-\-verbosity.

Run \fB$ gcloud help\fR for details.



.SH "NOTES"

This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation\-only early access
allowlist. This variant is also available:

.RS 2m
$ gcloud transfer authorize
.RE