There are a few ways to authenticate this action. The caller must have permissions to access the secrets being requested. You will need to authenticate to Google Cloud as a service account with the following roles: Cloud Run Admin (roles/run.admin) … Can create, update, and delete services. Can get and set IAM policies. … This service account needs to be a member of the Compute Engine default service account, (PROJECT_NUMBER-compute@developer.gserviceaccount.com), with role Service Account User. To grant a user permissions for a service account, use one of the methods found in Configuring Ownership and access to a service account.