<!-- llms-explorer concept facts · https://llms-explorer.com/tree/atlas-admin-api-gcp-auth/ · pack 2026-09-18 · ~797 tokens -->

# Atlas Admin API GCP Auth

> MongoDB Atlas Admin API authentication on GCP uses OAuth 2.0 Service Accounts for API/administrative access, while cluster data access instead uses Workload Identity Federation (OIDC) for passwordless auth from GCP workloads.

Parent: [MongoDB Atlas on GCP](https://llms-explorer.com/tree/mongodb-atlas-on-gcp/) · 3 facets · 11 facts · page: https://llms-explorer.com/tree/atlas-admin-api-gcp-auth/

## Authentication flows

- Atlas Admin API uses OAuth 2.0 Service Accounts with the Client Credentials flow; tokens are obtained from POST https://cloud.mongodb.com/api/oauth/token and are valid for 1 hour (3600 seconds), reusable within that window. — [source](https://www.mongodb.com/docs/atlas/api/api-authentication/)
- Admin API authentication (managing projects, users, and networks) is a distinct concern from cluster data access (reading and writing documents) — the two use different auth mechanisms. — [source](https://www.mongodb.com/docs/atlas/api/api-authentication/)
- GCP does not provide a native Admin API integration; the recommended pattern is to store Atlas API credentials in GCP Secret Manager and retrieve them from the workload (Compute Engine, Cloud Run, GKE). — [source](https://www.mongodb.com/docs/atlas/api/service-accounts-overview/)
- For cluster data access (not Admin API), Workload Identity Federation gives OIDC-based passwordless auth from a GCP Service Account to Atlas clusters on MongoDB 7.0.11+ running on M10+ tiers. — [source](https://www.mongodb.com/docs/atlas/workload-oidc/)
- The MONGODB-OIDC connection string uses authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>; supported by PyMongo 4.7+, Node.js driver 6.7+, Go driver 1.17+, and Java driver 5.1+, among other current drivers. — [source](https://www.mongodb.com/docs/atlas/workload-oidc/)

## Best practices

- Assign minimal Atlas roles to service accounts — e.g. Project Data Access Admin — rather than Organization Owner. — [source](https://www.mongodb.com/docs/atlas/architecture/current/auth/authentication/)
- IP-allowlist token usage to known CIDR blocks (CI/CD runners, GCP NAT ranges) and rotate secrets on a fixed cadence, roughly every 90 days. — [source](https://www.mongodb.com/docs/atlas/architecture/current/auth/authentication/)
- Cache the 1-hour OAuth token and refresh it a few minutes before expiry rather than requesting a new token on every call. — [source](https://www.mongodb.com/docs/atlas/api/api-authentication/)
- Store credentials in GCP Secret Manager rather than plain environment variables. — [source](https://www.mongodb.com/docs/atlas/api/service-accounts-overview/)

## Open questions

- No GCP-published SDK exists for the Atlas Admin API; implementations rely on generic OAuth 2.0 client libraries such as google-auth-library-python. — [source](https://www.mongodb.com/docs/atlas/api/api-authentication/) *(knowledge gap noted in the source research)*
- Throughput characteristics for high-volume Admin API calls, and token-refresh/caching patterns at scale, are not documented publicly. — [source](https://www.mongodb.com/docs/atlas/api/api-authentication/) *(knowledge gap noted in the source research)*
