Access control with IAM

reCAPTCHA offers Role-Based Access Control (RBAC) with Identity and Access Management (IAM) and access control for reCAPTCHA APIs using VPC Service Controls.

Role-based access control with IAM

IAM lets you give granular access to specific Google Cloud resources and prevents unwanted access to other resources, such as logs and analytics.

This section describes the IAM roles for reCAPTCHA.

To learn how to assign IAM roles to a user or service account, read Granting, changing, and revoking access to resources in the IAM documentation.

Roles and permissions

The following table lists the necessary IAM roles and their permissions for reCAPTCHA:

Role Permissions

(roles/recaptchaenterprise.admin)

Access to view and modify reCAPTCHA Enterprise keys

monitoring.timeSeries.list

recaptchaenterprise.firewallpolicies.*

  • recaptchaenterprise.firewallpolicies.