Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To find out who created a Google service-account key and whether it is still being used, combine IAM key metadata with Cloud Audit Logs and Cloud Monitoring. IAM can identify the key and its recorded metadata; the key-creation audit event can identify the creating principal; and authentication logs and metrics can help trace later activity. No single source establishes the key’s complete history or proves which application currently holds its private key.

What a service-account key can tell you about its origin

Google distinguishes Google-managed key pairs from user-managed keys. Google holds and manages its own keys for services such as App Engine and Compute Engine and for the Service Account Credentials API, which can create short-lived credentials. A user-managed key has a private key that can authenticate to Google APIs.

User-managed key pairs can be created through the Cloud Console, gcloud CLI, IAM API, or client libraries. Google can generate a pair and return the private key, or a customer can generate a pair and upload only the public key. These different paths mean that a key’s provenance includes more than its key ID: consider its type, creation method, creator identity, and storage history. Google Cloud’s 2026 guidance says each service account can have up to 10 keys.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The private key file is delivered only when the pair is created. IAM key metadata and list/get operations can help identify the key ID and recorded details, but the file itself does not reveal which person, application, or machine currently possesses or uses it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How to investigate a key’s creator and activity

  1. Inventory the key in IAM. Identify the service account and project, then use IAM key-list or key-get operations to record the key ID, key type, state, creation time, and expiry information. Keep the key ID available for the log and metric checks that follow.
  2. Find the key-creation event in Cloud Audit Logs. Search for google.iam.admin.v1.CreateServiceAccountKey. In the event, protoPayload.authenticationInfo.principalEmail identifies the principal that created the key. This answers who performed the creation recorded in the log; it does not establish who later copied, stored, or used the private key.
  3. Look for authenticated activity tied to the key. In relevant audit events, inspect protoPayload.authenticationInfo.serviceAccountKeyName. Google documents this field as identifying the key that requested the OAuth 2.0 access token. Correlate the key name with downstream service audit logs and timestamps. Caller IP or network fields, when present, may provide additional context, and the service account’s granted roles help show what access its credentials could exercise.
  4. Check Cloud Monitoring for recent key-authentication events. Use the iam.googleapis.com/service_account/key/authn_events_count metric and filter it by the key ID. Google says these metrics usually become available within a few minutes and include successful and failed API calls. Treat a metric event as a lead to investigate, not as proof of successful authentication.

How to interpret evidence of use

Separate the creator from the user

The principal in the key-creation event tells you who created the key. The key name in an authenticated request can connect that request to a specific key resource. Neither field, on its own, identifies the application or machine that stores the private key. To investigate a possible workload, compare event times and available network details with downstream service logs and what you know about the service account’s assigned roles.

Do not treat every metric event as successful use

Key-authentication metrics can be generated when a system lists keys while attempting authentication, including in signed-URL and third-party-application scenarios. They can also include failed calls. A metric count therefore indicates key-related activity, not necessarily that the private key successfully authenticated or that a workload completed an operation.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Account for retention and credential type

Google Cloud’s 2026 monitoring guidance says service-account key metrics are retained for six weeks. If an investigation needs a longer history, export metrics to BigQuery or another durable store. These metrics do not cover Cloud Storage HMAC authentication keys or requests authenticated by API keys bound to service accounts; distinguish those credential types when triaging activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to do when a key may be unused or exposed

  • Disable first when you need a reversible check. Google recommends disabling unused keys. If you are unsure whether a key is still required, disabling it can help you assess dependencies before deciding whether to delete it.
  • Delete after confirming it is no longer needed. Google recommends deleting unused keys once you have confirmed they are not required.
  • Rotate keys that remain necessary. If a workload still depends on a user-managed key, plan a replacement and update the workload before retiring the old key. Store private key material in a secure hardware-based or software-based key store; Google’s guidance is to keep service-account keys in a secure location.
  • Reduce future reliance on long-lived key files. Google recommends short-lived credentials and Workload Identity Federation for workloads outside Google Cloud. Organization policy can also prevent user-managed key creation with constraints/iam.disableServiceAccountKeyCreation or public-key upload with constraints/iam.disableServiceAccountKeyUpload.
  • Review the service account’s roles. The account’s granted roles determine the permissions available to credentials using it, so include them in the impact assessment for a suspected exposed key.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Choosing a safer credential approach

Approach Credential lifetime and private-key exposure Operational and audit considerations Best fit supported by Google’s guidance
User-managed service-account key Private key material is returned or uploaded as part of key-pair creation; it can authenticate to Google APIs. Requires secure storage and, if retained, rotation. Audit Logs can identify the principal recorded as creating a key, but the file does not establish its current holder. Use only when a workload still requires this credential approach; secure and rotate keys that remain necessary.
Short-lived credentials Short-lived rather than a long-lived key file. Reduces the risk associated with long-lived key files. Specific lifetime and setup details are not stated in the cited guidance. Google recommends short-lived credentials; Workload Identity Federation is recommended for workloads outside Google Cloud.
Google-managed keys Google holds and manages the key pairs rather than returning user-managed private keys. Used by Google services such as App Engine and Compute Engine and by the Service Account Credentials API to create short-lived credentials. Relevant to those Google-managed service and API flows, rather than a customer-held private key file.

The appropriate choice depends on whether the workload runs inside or outside Google Cloud, whether it truly needs private key material, the burden of rotation, how the initiating principal can be audited, and the permissions attached to the service account. Workload Identity Federation is Google’s recommended direction for workloads outside Google Cloud that would otherwise rely on long-lived keys.

Best Value
Yubico - YubiKey 5 Nano C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (Nano USB-C)
  • POWERFUL SECURITY KEY: The YubiKey 5C Nano is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C Nano secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: The YubiKey 5C Nano is designed to stay plugged into your device via USB-C. Simply tap it to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #4
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.