Tool: list_deny_policies
Lists deny policies attached to a Google Cloud project. Organizations and folders are not supported.
Use this tool to discover deny policies enforced at an attachment point.
This tool requires the following parameters:
parent(string): The URL-encoded full resource name of the attachment point where the policies are listed. Only projects are supported. The format ispolicies/URL_ENCODED_ATTACHMENT_POINT/denypolicies(for example,policies/cloudresourcemanager.googleapis.com%2Fprojects%2Fmy-project/denypolicies).
The following parameters are optional:
page_size(int32): The maximum number of policies to return.page_token(string): Pagination token from a previous list request.
The tool returns a list of deny policies attached to the specified resource along with an optional next page token.
The following code sample shows how to use curl to call the list_deny_policies MCP tool.
| Curl Request |
|---|
curl --location 'https://iam.googleapis.com/mcp' \ --header 'content-type: application/json' \ --header 'accept: application/json, text/event-stream' \ --data '{ "method": "tools/call", "params": { "name": "list_deny_policies", "arguments": { // Provide these details according to the MCP tool specification. } }, "jsonrpc": "2.0", "id": 1 }' |
Input Schema
Request message for ListPolicies.
ListPoliciesRequest
| JSON representation |
|---|
{ "parent": string, "pageSize": integer, "pageToken": string } |
| Fields | |
|---|---|
parent |
Required. The resource that the policy is attached to, along with the kind of policy to list. Format: The attachment point is identified by its URL-encoded full resource name, which means that the forward-slash character, For organizations and folders, use the numeric ID in the full resource name. For projects, you can use the alphanumeric or the numeric ID. |
pageSize |
The maximum number of policies to return. IAM ignores this value and uses the value 1000. |
pageToken |
A page token received in a |
Output Schema
Response message for ListPolicies.
ListPoliciesResponse
| JSON representation |
|---|
{
"policies": [
{
object ( |
| Fields | |
|---|---|
policies[] |
Metadata for the policies that are attached to the resource. |
nextPageToken |
A page token that you can use in a |
Policy
| JSON representation |
|---|
{
"name": string,
"uid": string,
"kind": string,
"displayName": string,
"annotations": {
string: string,
...
},
"etag": string,
"createTime": string,
"updateTime": string,
"deleteTime": string,
"rules": [
{
object ( |
| Fields | |
|---|---|
name |
Immutable. The resource name of the The attachment point is identified by its URL-encoded full resource name, which means that the forward-slash character, For organizations and folders, use the numeric ID in the full resource name. For projects, requests can use the alphanumeric or the numeric ID. Responses always contain the numeric ID. |
uid |
Immutable. The globally unique ID of the |
kind |
Output only. The kind of the |
displayName |
A user-specified description of the |
annotations |
A key-value map to store arbitrary metadata for the An object containing a list of |
etag |
An opaque tag that identifies the current version of the If this field is present in a |
createTime |
Output only. The time when the Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
updateTime |
Output only. The time when the Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
deleteTime |
Output only. The time when the Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
rules[] |
A list of rules that specify the behavior of the |
AnnotationsEntry
| JSON representation |
|---|
{ "key": string, "value": string } |
| Fields | |
|---|---|
key |
|
value |
|
Timestamp
| JSON representation |
|---|
{ "seconds": string, "nanos": integer } |
| Fields | |
|---|---|
seconds |
Represents seconds of UTC time since Unix epoch 1970-01-01T00:00:00Z. Must be between -62135596800 and 253402300799 inclusive (which corresponds to 0001-01-01T00:00:00Z to 9999-12-31T23:59:59Z). |
nanos |
Non-negative fractions of a second at nanosecond resolution. This field is the nanosecond portion of the duration, not an alternative to seconds. Negative second values with fractions must still have non-negative nanos values that count forward in time. Must be between 0 and 999,999,999 inclusive. |
PolicyRule
| JSON representation |
|---|
{ "description": string, // Union field |
| Fields | |
|---|---|
description |
A user-specified description of the rule. This value can be up to 256 characters. |
Union field
|
|
denyRule |
A rule for a deny policy. |
DenyRule
| JSON representation |
|---|
{
"deniedPrincipals": [
string
],
"exceptionPrincipals": [
string
],
"deniedPermissions": [
string
],
"exceptionPermissions": [
string
],
"denialCondition": {
object ( |
| Fields | |
|---|---|
deniedPrincipals[] |
The identities that are prevented from using one or more permissions on Google Cloud resources. This field can contain the following values:
|
exceptionPrincipals[] |
The identities that are excluded from the deny rule, even if they are listed in the This field can contain the same values as the |
deniedPermissions[] |
The permissions that are explicitly denied by this rule. Each permission uses the format |
exceptionPermissions[] |
Specifies the permissions that this rule excludes from the set of denied permissions given by The excluded permissions can be specified using the same syntax as |
denialCondition |
The condition that determines whether this deny rule applies to a request. If the condition expression evaluates to Each deny rule is evaluated independently. If this deny rule does not apply to a request, other deny rules might still apply. The condition can use CEL functions that evaluate resource tags. Other functions and operators are not supported. |
Expr
| JSON representation |
|---|
{ "expression": string, "title": string, "description": string, "location": string } |
| Fields | |
|---|---|
expression |
Textual representation of an expression in Common Expression Language syntax. |
title |
Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression. |
description |
Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI. |
location |
Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file. |
Tool Annotations
Tool annotations are sent to MCP clients to describe the basic risk of a given tool. Most clients treat these hints as untrusted, but they can be used to decide when a confirmation prompt might be sent to a user.
Along with the title string, the following boolean hints are defined as follows:
readOnlyHint: If true, the tool doesn't modify its environment. Default: false.destructiveHint: If true, then the tool can perform destructive actions. If false, then the tool can only perform additive actions. Default: true.idempotentHint: If true, then calling the tool repeatedly with the same arguments will have no additional effect on its environment. Default: false.openWorldHint: If true, then the tool can interact with an 'open world' of external entities. If false, then the tool can only interact with internal entities. For example, a web search tool would be open world, while a memory tool would not be open world.
Destructive Hint: ❌ | Idempotent Hint: ✅ | Read Only Hint: ✅ | Open World Hint: ❌