Atlas Admin API GCP Auth
Parent: MongoDB Atlas on GCP · Published reference · snapshot 2026-09-18
↓ Facts as markdownall context files
MongoDB Atlas Admin API authentication on GCP uses OAuth 2.0 Service Accounts for API/administrative access, while cluster data access instead uses Workload Identity Federation (OIDC) for passwordless auth from GCP workloads.
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Authentication flows
- Atlas Admin API uses OAuth 2.0 Service Accounts with the Client Credentials flow; tokens are obtained from POST https://cloud.mongodb.com/api/oauth/token and are valid for 1 hour (3600 seconds), reusable within that window. [source]
- Admin API authentication (managing projects, users, and networks) is a distinct concern from cluster data access (reading and writing documents) — the two use different auth mechanisms. [source]
- GCP does not provide a native Admin API integration; the recommended pattern is to store Atlas API credentials in GCP Secret Manager and retrieve them from the workload (Compute Engine, Cloud Run, GKE). [source]
- For cluster data access (not Admin API), Workload Identity Federation gives OIDC-based passwordless auth from a GCP Service Account to Atlas clusters on MongoDB 7.0.11+ running on M10+ tiers. [source]
- The MONGODB-OIDC connection string uses authMechanismProperties=ENVIRONMENT:gcp,TOKEN_RESOURCE:<audience>; supported by PyMongo 4.7+, Node.js driver 6.7+, Go driver 1.17+, and Java driver 5.1+, among other current drivers. [source]
Best practices
- Assign minimal Atlas roles to service accounts — e.g. Project Data Access Admin — rather than Organization Owner. [source]
- IP-allowlist token usage to known CIDR blocks (CI/CD runners, GCP NAT ranges) and rotate secrets on a fixed cadence, roughly every 90 days. [source]
- Cache the 1-hour OAuth token and refresh it a few minutes before expiry rather than requesting a new token on every call. [source]
- Store credentials in GCP Secret Manager rather than plain environment variables. [source]
Open questions
- No GCP-published SDK exists for the Atlas Admin API; implementations rely on generic OAuth 2.0 client libraries such as google-auth-library-python. [source] — knowledge gap noted in the source research
- Throughput characteristics for high-volume Admin API calls, and token-refresh/caching patterns at scale, are not documented publicly. [source] — knowledge gap noted in the source research
Children
- No children recorded.