This page lists the IAM roles and permissions for App Engine. To search through all roles and permissions, see the role and permission index.
App Engine roles
Role | Permissions |
---|---|
App Engine Admin( Read/Write/Modify access to all application configuration and settings. To deploy new versions, a principal must have the
Service Account User
( Lowest-level resources where you can grant this role:
|
|
App Engine Creator( Ability to create the App Engine resource for the project. Lowest-level resources where you can grant this role:
|
|
App Engine Viewer( Read-only access to all application configuration and settings. Lowest-level resources where you can grant this role:
|
|
App Engine Code Viewer( Read-only access to all application configuration, settings, and deployed source code. Lowest-level resources where you can grant this role:
|
|
App Engine Managed VM Debug Access( Ability to read or manage v2 instances. |
|
App Engine Deployer( Read-only access to all application configuration and settings. To deploy new versions, you must also have the
Service Account User
( Cannot modify existing versions other than deleting versions that are not receiving traffic. Lowest-level resources where you can grant this role:
|
|
App Engine Memcache Data Admin( Can get, set, delete, and flush App Engine Memcache items. |
|
App Engine Service Admin( Read-only access to all application configuration and settings. Write access to module-level and version-level settings. Cannot deploy a new version. Lowest-level resources where you can grant this role:
|
|
App Engine Standard Environment Service Agent( Give App Engine Standard Envirnoment service account access to managed resources. Includes access to service accounts. |
|
App Engine permissions
Permission | Included in roles |
---|---|
|
Owner (
App Engine Creator ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Memcache Data Admin (
App Engine Service Admin (
Cloud Scheduler Admin (
Cloud Scheduler Job Runner (
Cloud Scheduler Viewer (
Web Security Scanner Editor (
Cloud Datastore Import Export Admin (
Cloud Datastore Index Admin (
Cloud Datastore Owner (
Cloud Datastore User (
Cloud Datastore Viewer (
Firebase Admin (
Firebase Develop Admin (
Firebase Admin SDK Administrator Service Agent (
Firebase Extensions API Service Agent (
Security Center Admin (
Security Center Admin Editor ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Managed VM Debug Access (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Managed VM Debug Access ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin (
Security Admin (
Security Reviewer ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Memcache Data Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Memcache Data Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Memcache Data Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer ( |
|
Owner (
Editor (
App Engine Admin (
App Engine Memcache Data Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin (
Security Admin (
Security Reviewer ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin (
Security Admin (
Security Reviewer ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Deployer ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin ( Service agent roles
|
|
Owner (
App Engine Code Viewer ( |
|
Owner (
Editor (
Viewer (
App Engine Admin (
App Engine Viewer (
App Engine Code Viewer (
App Engine Managed VM Debug Access (
App Engine Deployer (
App Engine Service Admin (
Security Admin (
Security Reviewer ( Service agent roles
|
|
Owner (
Editor (
App Engine Admin (
App Engine Service Admin ( Service agent roles
|