Secure Google Cloud Run API Access with JWT Auth - n8n Workflow

Use this robust n8n workflow to authenticate with Google Service Accounts and securely call private Cloud Run endpoints. Features JWT signing and Bearer token exchange.

Workflow Preview

Ready to automate?

Download this n8n workflow template and start using it instantly.

Who is this best for?

This secure n8n workflow is ideal for:

Developers needing to integrate internal, authenticated Google Cloud Run APIs into their business processes.
Automation engineers building reliable n8n templates for accessing secure cloud infrastructure.


  • Teams requiring robust service account authentication methods within their n8n environment.

Overview

Calling securely authenticated services, like private Google Cloud Run endpoints, requires a complex multi-step process involving Google Service Accounts and JWT signing. This specialized n8n workflow eliminates the manual effort and boilerplate code required for this task.

Instead of relying on simpler API key authentication (which often lacks proper security), this n8n automation uses the standard Google Service Account flow: signing a JWT, exchanging it for an ID token, and then using that ID token as a Bearer authorization header. This n8n workflow template is essential for anyone running critical DevOps or secure data pipelines where proper authentication is paramount. By leveraging a dedicated n8n node for JWT signing, the process is both secure and highly repeatable across different projects.

How it Works

This specific n8n workflow uses a manual n8n trigger for testing, but can be easily adapted to any time-based or incoming webhook n8n trigger.


  1. Configuration: The “Edit Fields” n8n node defines the necessary service variables: serviceurl (the target Cloud Run API) and clientemail (from the Google Service Account key file).

  2. JWT Creation: The “JWT” n8n node generates a signed token using the private key stored in a specialized n8n JWT Credential. The payload includes critical claims like iss, aud (the token URI), and the targetaudience (the service URL) required by Google for validation.

  3. Token Exchange: The “Bearer Token Request” n8n node sends this signed JWT assertion in a POST request to the Google OAuth token URI. Google validates the assertion using the service account and returns a response containing the secure idtoken.

  4. API Call: Finally, the “Cloud Run Request” n8n node executes the actual HTTP call to the secured Cloud Run URL, utilizing the newly acquired id_token within the Bearer Authentication header. This robust n8n workflow ensures secure, automated access to private cloud APIs.

Installation Guide

To import and run this n8n workflow, follow these steps:


  1. Import the Workflow: Copy the provided JSON and paste it into your n8n instance using the 'New' -> 'Import from JSON' option.

  2. Google Cloud Setup: Ensure you have a Google Service Account created with the 'Cloud Run Invoker' role for your targeted service.

  3. Configure Variables: Update the 'Edit Fields' n8n node with your specific serviceurl and clientemail.

  4. Setup JWT Credential: Create a new n8n JWT Credential. Set the Key Type to 'PEM Key' and paste the full privatekey block (including BEGIN/END headers) from your Google Service Account JSON file. Link this credential to the 'JWT' n8n node.

  5. Setup Bearer Credential: Create a new n8n HTTP Bearer Auth Credential. Configure it to use a dynamic value: {{$json.idtoken}}. This references the token retrieved in the previous step. Link this credential to the 'Cloud Run Request' n8n node.

  6. Execution: Run the n8n trigger manually to test the full authentication flow.

Node Details

Execute (n8n trigger): Manual starting point for initiating this secure authentication n8n workflow.
Edit Fields (Set n8n node): Function: Stores critical configuration variables (serviceurl, clientemail). Key Configuration: Raw JSON output used to structure data for subsequent nodes.
JWT (n8n node): Function: Cryptographically signs the required JWT using the Service Account private key credential. This is a crucial step in the n8n template logic. Key Configuration: Uses expressions ({{ $json.clientemail }}) to dynamically populate claims (issuer, subject, audience, expiry) necessary for Google's validation.
Bearer Token Request (HTTP Request n8n node): Function: Exchanges the signed JWT assertion for an official Google ID token (Bearer token). Key Configuration: POST request to token
uri with the content type set to form-urlencoded and the JWT dynamically inserted as the assertion body parameter.


  • Cloud Run Request (HTTP Request n8n node): Function: Makes the final authenticated request to the private Cloud Run API. Key Configuration: Uses Generic Bearer Authentication linked to the credential containing the retrieved id_token.

Related n8n Workflows

Free

Nodes: 5 Nodes
Updated: December 26 2025
View all
Created by
Marco Cassar
Marco Cassar

Featured*