---
title: "POST /v1/{+name}:signJwt"
method: POST
path: "/v1/{+name}:signJwt"
tags: ["projects"]
---

# POST /v1/{+name}:signJwt

`POST /v1/{+name}:signJwt`

Signs a JWT using a service account's system-managed private key.

## Path parameters

- `name` string, required

## Request body

- SignJwtRequest
  - `delegates` string[] — The sequence of service accounts in a delegation chain. Each service account must be granted the `roles/iam.serviceAccountTokenCreator` role on its next service account in the chain. The last service account in the chain must be granted the `roles/iam.serviceAccountTokenCreator` role on the service account that is specified in the `name` field of the request. The delegates must have the following format: `projects/-/serviceAccounts/{ACCOUNT_EMAIL_OR_UNIQUEID}`. The `-` wildcard character is required; replacing it with a project ID is invalid.
  - `payload` string — Required. The JWT payload to sign. Must be a serialized JSON object that contains a JWT Claims Set. For example: `{"sub": "user@example.com", "iat": 313435}` If the JWT Claims Set contains an expiration time (`exp`) claim, it must be an integer timestamp that is not in the past and no more than 12 hours in the future.

## Response `200`

Successful response

---

[API](https://skmtc.dev/google/apis/iamcredentials.md) · [All operations](https://skmtc.dev/google/apis/iamcredentials/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/google/iamcredentials/revisions/470ff76e345d/schema)
