gcloud storage buckets add-iam-policy-binding URL --member=PRINCIPAL --role=ROLE [--condition=[KEY=VALUE,…] | --condition-from-file=PATH_TO_FILE] [GCLOUD_WIDE_FLAG …]
gcloud storage buckets add-iam-policy-binding gs://BUCKET --member=user:john.doe@example.com --role=roles/storage.objectCreatorTo make objects in BUCKET publicly readable:
gcloud storage buckets add-iam-policy-binding gs://BUCKET --member=allUsers --role=roles/storage.objectViewerTo specify a custom role for a principal on BUCKET:
gcloud storage buckets add-iam-policy-binding gs://BUCKET --member=user:john.doe@example.com --role=roles/customRoleNameURL--member=PRINCIPALuser|group|serviceAccount:email or domain:domain.
Examples: user:test-user@gmail.com,
group:admins@example.com,
serviceAccount:test123@example.domain.com, or
domain:example.domain.com.
allUsers - Special identifier that represents anyone who is on the
internet, with or without a Google account.
allAuthenticatedUsers - Special identifier that represents anyone
who is authenticated with a Google account or a service account.
--role=ROLEroles/logging.viewer, or the role ID for a
custom role, such as
organizations/{ORGANIZATION_ID}/roles/logging.viewer.
--condition=[KEY=VALUE,…]None (--condition=None), a binding
without a condition is added. When the condition is specified and is not
None, --role cannot be a basic role. Basic roles are
roles/editor, roles/owner, and
roles/viewer. For more on conditions, refer to the conditions
overview guide: https://cloud.google.com/iam/docs/conditions-overview
When using the --condition flag, include the following key-value
pairs:
expression:) as the delimiter, do the
following: --condition=^:^title=TITLE:expression=EXPRESSION. For
more information, see https://cloud.google.com/sdk/gcloud/reference/topic/escaping.
titledescription--condition-from-file=PATH_TO_FILE--condition. Use a full or relative path
to a local file containing the value of condition.
--access-token-file,
--account, --billing-project,
--configuration,
--flags-file,
--flatten, --format, --help, --impersonate-service-account,
--log-http,
--project, --quiet, --trace-token, --user-output-enabled,
--verbosity.
Run $ gcloud help for details.
gcloud alpha storage buckets add-iam-policy-binding
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.