Build Cloud Endpoints OpenAPI service configurations with authentication providers and quota limits.
Build Cloud Endpoints OpenAPI service configurations with authentication providers, quota limits, and backend routing rules.
Required Fields
nametitleapisbackend.rulesOutput will appear here...Build a Cloud Endpoints OpenAPI service configuration (the google.api.Service descriptor deployed via `gcloud endpoints services deploy`), covering authentication providers, per-selector auth rules, usage rules, quota limits, and backend routing. The ESPv2 proxy sitting in front of your backend enforces everything declared here: JWT validation against each provider's jwks_uri, the allowUnregisteredCalls gate on anonymous traffic, and quota limits keyed by the {project} substitution so limits apply per API-key-holding consumer rather than globally.
A mobile team adds a new Firebase-authenticated feature and starts seeing intermittent 401s only from Android clients, not iOS, three days after a security team rotated the Firebase signing key as part of a routine credential rotation. Investigating the ESPv2 logs shows JWT signature validation failures that trace back to the jwks_uri cache not having refreshed on some proxy replicas yet. They use the builder to review the authentication.providers block, confirm the jwks_uri is correct, and coordinate a rolling restart of the ESPv2 deployment to force an immediate key refresh instead of waiting out the cache TTL.
config_version 3 is the current schema; older Endpoints deployments pinned to version 1 or 2 are missing fields like usage.rules and won't accept some of the newer quota syntax, check the version before copying an example from older documentation.
jwks_uri is fetched and cached by ESPv2 at startup and on a refresh interval, rotating a provider's signing keys without waiting for that cache to refresh causes a window of spurious 401s for legitimately valid new tokens.
backend.rules address must be reachable from wherever ESPv2 is actually running (a GKE sidecar, a Cloud Run container, or a Compute Engine instance), a common deploy mistake is leaving the address pointed at a dev backend URL after promoting the config to production.
The builder checks that name, title, apis, and backend.rules all resolve before accepting the JSON as a valid Endpoints service config, mirroring the minimum fields `gcloud endpoints services deploy` needs to register a service, an API surface, and somewhere to actually route the traffic it authenticates.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.