Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

[Action Advised] Automatically disable publicly exposed Service Account keys

I just got an email saying Google will proactively disable any publicly exposed "Service Account Keys" that they become aware of after June 16, 2024, unless i opt-out. But i'm unable to do so since that can only be done at/on "Organization" level/resource, which my account lacks due to it being ancient, before such features/requirements, and solely registered to be used with OAuth and Google/Firebase Cloud Messaging for an Android app.

Do "Service Account Keys" also mean API keys as included in an APK by the google-services-plugin? For which i've previously received warnings about it being exposed, but apps are of course unable to hide.

If so, then i need to opt-out, how do i do so without an "Organization level" in "Organization Policies"?

If an "Organization" is needed, what is the easiest way to set one up?

Is setting up an "Organization" a free service?

Will setting up an "Organization" break existing projects, e.g. currently used API keys, etc.?

 

5 4 1,414
4 REPLIES 4
Top Labels in this Space