The Advisory Notifications API exposes the notifications that Google Cloud and Google Workspace surface to organisation administrators about security incidents, regulatory changes, and product issues affecting their tenant. It lets platforms list and read notifications scoped to an organisation or location and acknowledge that they have been seen. It is intended for SecOps, GRC, and platform teams that want these advisories pulled into their own ticketing or alerting systems instead of read by hand in the console.
3 endpointsThe Google Cloud API Gateway API lets developers create and manage gateways, API configs, and APIs that front backend services running on Cloud Run, Cloud Functions, or App Engine. It exposes resources for the API, ApiConfig (the OpenAPI spec plus auth and rate-limit policy), and Gateway (the deployable endpoint), along with IAM helpers for resource-level permissions and operation tracking for asynchronous deploys.
15 endpointsThe App Engine Admin API provisions and manages developers' App Engine applications. It exposes the application itself, services, versions, and instances, plus authorized domains, authorized certificates, domain mappings, firewall ingress rules, and operations. Through it, teams create apps, deploy and migrate traffic across versions, attach SSL certificates, lock down ingress, and inspect running instances.
43 endpointsBackup for GKE is a managed service that backs up and restores Kubernetes workloads running on Google Kubernetes Engine. The API manages backup plans, individual backups, restore plans, and restore operations, including selective restores of namespaces and resources. It captures both Kubernetes object state and persistent volume data so clusters can recover from accidental deletion, region outages, or operator errors.
20 endpointsThe Bare Metal Solution API manages physical bare-metal servers, networks, volumes, and SAN LUNs hosted in regional extensions adjacent to Google Cloud data centres. It exposes operations to detach LUNs from instances, list network usage, disable hyperthreading or interactive serial console, and patch instance, network, and volume settings. The API is the control plane for legacy or licence-bound workloads such as Oracle databases that must run on dedicated hardware while integrating with Google Cloud networking. It does not run a hypervisor or manage VMs.
33 endpointsThe Google Cloud Batch API runs batch compute jobs on managed Compute Engine and GKE infrastructure without requiring users to operate their own scheduler. It exposes operations to submit jobs that bundle one or more tasks, list and cancel running jobs, and report task state from inside the job. Batch handles VM provisioning, retries, and result collection so HPC, genomics, simulation, and rendering workloads can be expressed as a single API call. The API is the orchestration surface only and does not store result artifacts.
9 endpointsGoogle Cloud Asset Inventory exposes a unified history and metadata index for resources, IAM policies, and org policies across a Google Cloud organization, folder, or project. Agents can search assets across asset types, export point-in-time snapshots, analyze IAM grants, and subscribe to feeds that emit changes as assets are created, updated, or deleted. The API supports SQL-like asset queries, move analysis between resource containers, and saved queries that can be re-run by agents on a schedule.
20 endpointsGoogle Cloud Deployment Manager lets you declaratively configure, deploy, and update Google Cloud resources using YAML or Jinja/Python templates. Manage deployments, manifests, and resources programmatically across projects, with support for previewing changes before applying them. Templates can compose multiple Cloud services (Compute Engine, Cloud Storage, Cloud SQL) into a single repeatable deployment. Built for teams running infrastructure-as-code workflows on Google Cloud.
18 endpointsGoogle Cloud DNS is a high-availability, low-latency authoritative DNS service. The API exposes managed zones, resource record sets, atomic change transactions, DNSSEC keys, response policies, and per-project DNS policies so platform teams can automate authoritative DNS at scale across public and private (split-horizon) zones. It supports BIND zone files, DNSSEC, and integration with Google Cloud VPC for private DNS resolution.
40 endpointsGoogle Cloud Domains lets you register, transfer, and manage domain name registrations directly from your Google Cloud project. The API exposes the full registration lifecycle: search for available domains, retrieve register and transfer parameters, configure DNS settings (Cloud DNS or custom name servers), manage WHOIS contact privacy, configure auto-renew, and export or transfer registrations out. Operations are scoped under projects and locations and return long-running operations for asynchronous registration steps.
26 endpointsGoogle Cloud Functions runs short-lived, event-driven code without server management. The v2 API exposes function lifecycle operations — create, update, delete, list — plus signed download and upload URLs for source archives, and traffic-management endpoints used during version upgrades. Agents can deploy a new function from a source archive, generate a signed upload URL for a build artefact, list every function in a region, and orchestrate the v2 upgrade flow that detaches, redirects traffic, and commits or aborts the upgrade.
19 endpointsThe Cloud Life Sciences API runs container-based pipelines on Google Cloud, primarily for genomics, biology, and other life sciences batch workloads. It exposes a pipelines:run operation that schedules a Pipeline definition onto a Compute Engine VM and a set of operations endpoints to list, get, and cancel the resulting long-running operations. Locations can be discovered via the locations:list endpoint to choose a regional endpoint for compliance.
5 endpointsGoogle Cloud Pub/Sub is a globally distributed, fully managed messaging service for asynchronous service-to-service communication, event ingestion, and streaming analytics pipelines. The REST API exposes topics, subscriptions, snapshots, schemas, and IAM controls so producers can publish messages, subscribers can pull or acknowledge them, and operators can manage retention, ordering, and dead-letter behavior. Pub/Sub backs many Google Cloud event flows, including Cloud Storage notifications, Dataflow pipelines, and Cloud Run event triggers.
33 endpointsThe Cloud Resource Manager API creates, reads, and updates metadata for Google Cloud Platform resource containers including projects, folders, organizations, tag keys, and tag values. It exposes hierarchical IAM controls for managing access to those containers and supports lien protection to prevent accidental project deletion. Resource Manager is the foundation for organizing GCP resources at scale and underpins billing, policy enforcement, and asset inventory across the platform.
28 endpointsThe Cloud Run Admin API v2 deploys and manages user-supplied container images that scale automatically based on incoming requests, aligned with Google Cloud AIP-based API standards. It exposes operations to deploy services, run jobs, manage revisions, list operations, export metadata and images, and cancel or wait on long-running operations. Cloud Run is the serverless container platform on Google Cloud and is the v2 successor to the Knative Serving API surface used by v1.
25 endpointsCloud Tasks is a fully managed service for the asynchronous execution of distributed work items. The API exposes queue and task primitives so you can enqueue HTTP or App Engine targets, control delivery rate, set retry policy, and pause queues during incidents. It is the backbone for offloading long work from request handlers, smoothing traffic spikes, and decoupling producers from consumers without standing up a Kafka or Redis cluster.
16 endpointsCloud TPU API provisions and manages Tensor Processing Unit nodes used for training and serving large machine-learning models. Through it teams allocate single nodes or queued resources, list available accelerator types and TensorFlow runtime versions per zone, manage device guest attributes, and stop or reset nodes when jobs finish. The API is the control plane behind every TPU VM that PyTorch, JAX, and TensorFlow workloads run on in Google Cloud.
17 endpointsThe Google Cloud Workstations API provisions and manages fully managed developer environments in Google Cloud. Administrators define workstation clusters and configurations, while individual developers create, start, stop, and connect to workstations that run preconfigured container images with their tools and source. The API exposes the cluster, config, and workstation lifecycle as well as start, stop, and connection-token endpoints, removing the need to manage VMs or local laptops as the source of truth for developer environments.
20 endpointsThe Compute Engine API creates and runs virtual machines on Google Cloud Platform and is one of the largest control surfaces in GCP, covering instances, instance groups, disks, images, networks, subnetworks, firewalls, load balancers, routers, VPNs, and global networking primitives. It is the foundation for IaaS workloads on Google Cloud and is the same API the gcloud CLI and Terraform provider use under the hood. Most platform teams interact with a focused subset around instances, disks, and networking rather than the full surface.
802 endpointsGoogle Cloud Connectors API lets developers create and manage connections between Google Cloud services and third-party business applications such as Salesforce, ServiceNow, Jira, and SAP. It exposes connection lifecycle operations, custom connector definitions, managed zones, runtime endpoint attachments, and IAM policy management for connection resources. Connections are then consumable from Application Integration, Workflows, and Apigee for low-code orchestration. The API is region-scoped and uses long-running operations for resource provisioning.
41 endpointsThe Essential Contacts API lets Google Cloud customers register the right people to receive critical Google notifications about billing, technical, security, suspension, and legal events for their organisation, folder, or project. Contacts are scoped to a resource and subscribe to specific notification categories so notices reach the team that owns each domain. The API supports creating, updating, listing, computing effective contacts (by inheriting from parents), and sending test messages to verify routing. It is the canonical interface for ensuring outage and policy notifications never go to a stale single inbox.
7 endpointsEventarc routes events from Google Cloud sources, third-party SaaS providers, and custom publishers to event-driven workloads such as Cloud Run, Cloud Functions, GKE, and Workflows. The API manages triggers (which events to listen for and where to send them), channels and channel connections (third-party event delivery), Google API and provider catalogues, and the long-running operations that back these resources. Triggers can filter on event type, attributes, and source so each consumer receives only the events it cares about. It is the canonical event bus for Google Cloud serverless and container workloads.
25 endpointsThe Firebase Hosting REST API enables programmatic management of long-running operations behind Firebase Hosting sites and channels, including custom domain provisioning workflows. The v1 surface exposes operations to list, cancel, and delete the long-running operation resources spawned by deploys, channel creation, and custom domain setup. Use it to monitor and tidy up asynchronous Hosting jobs from automation pipelines.
3 endpointsGKE Hub is the control plane for managing fleets of Kubernetes clusters across GKE, Anthos, and attached on-prem or multi-cloud clusters. The API manages fleets, memberships, features such as Config Management and Service Mesh, and the bindings that scope namespaces and roles across the fleet. Use it to centralise policy, observability, and configuration for many clusters under one Google Cloud project.
27 endpointsThe GKE On-Prem API manages Anthos clusters that run on customer hardware, including bare metal admin and user clusters and VMware-based clusters. It supports cluster creation, upgrades, enrollment of existing clusters, and version queries, integrating on-prem clusters with the rest of Google Cloud's control plane. The API works alongside GKE Hub so on-prem clusters appear in fleets and can receive fleet-level features.
31 endpointsGoogle Kubernetes Engine (GKE) API lets developers provision and manage GKE clusters, node pools, and operations on Google Cloud. It exposes the full lifecycle of a managed Kubernetes control plane: create clusters in zonal or regional mode, scale node pools, upgrade master and node versions, configure addons such as HTTP load balancing or network policy, and rotate cluster credentials. The API also surfaces server configuration metadata describing the available Kubernetes versions and machine types per location. It is the canonical way to script GKE infrastructure outside of Terraform or the Cloud Console.
63 endpointsMigration Center is Google Cloud's unified workload-discovery and migration-planning service that catalogs on-premises and cloud assets, groups them, and produces reports for migrations to Google Cloud. The API exposes assets, groups, import jobs, preference sets, sources, and reports, plus heartbeat endpoints used by data collectors. Many state changes are long-running operations and the API is scoped to project locations.
34 endpointsThe Network Connectivity API manages Google Cloud's Network Connectivity Center — a hub-and-spoke service that interconnects on-premises networks, VPCs, and hybrid environments. It exposes hubs, spokes, route tables, internal ranges, and policy-based routes so platform teams can build, inspect, and govern transitive connectivity across global Google Cloud infrastructure. Pair it with Compute Engine networking and Cloud DNS for a full hybrid networking control plane.
35 endpointsThe Network Management API provides Google Cloud's network performance monitoring and diagnostics surface. It exposes connectivityTests as a primary resource — a saved test definition with source and destination endpoints — together with operations for create, list, rerun, and delete. Use it to verify reachability across VPCs, hybrid networks, and Network Connectivity Center hubs as part of change management or incident response.
14 endpointsThe Network Services API manages Google Cloud's application-aware networking resources — gateways, meshes, endpoint policies, HTTP/gRPC/TCP/TLS routes, service bindings, and authorization extensions. It is the control plane for Cloud Service Mesh and managed networking resources that route traffic to backend services with L7 logic. Use it to configure traffic routing, attach service extensions for custom request/response processing, and bind services to meshes. The spec exposes 38 endpoints across regional locations.
38 endpointsThe OS Config API manages patch deployments, OS policy assignments, and inventory across Compute Engine VM fleets. It schedules patch jobs (with maintenance windows, reboot behaviour, and rollout strategies), declares desired OS state via OS Policies, and surfaces inventory and patch compliance per instance. Use it to keep Linux and Windows VM fleets compliant with security baselines and to drive scheduled patch rollouts. The spec exposes 17 endpoints.
17 endpointsGoogle Cloud Pub/Sub Lite is a zonal, partition-based messaging service that offers lower per-message cost than Pub/Sub at the expense of zonal availability and explicit partition and capacity management. The admin API exposes topics, subscriptions, reservations, and partition statistics, while the cursor and topicStats APIs let consumers manage commit positions and inspect lag and throughput. Pub/Sub Lite is well suited for log ingestion, event archival, and telemetry pipelines that can tolerate zonal scope in exchange for predictable economics.
20 endpointsThe Google Cloud Rapid Migration Assessment API drives the Migration Center collector workflow used to inventory on-premises and other-cloud workloads ahead of a Google Cloud migration. It exposes operations to register collectors, pause and resume their data collection, attach annotations, and manage the long-running operations that back collector lifecycle changes. Output from this API feeds Migration Center cost and fit analyses and the recommended landing-zone shape for Google Cloud.
12 endpointsThe Google Cloud Recommender API surfaces machine-learning-driven recommendations and insights about Google Cloud resources, helping teams optimize cost, security, performance, and reliability across projects, folders, and organizations. It exposes recommenders for areas such as idle VM detection, IAM role rightsizing, and commitment utilization, and lets clients mark recommendations as claimed, accepted, succeeded, failed, or dismissed to track lifecycle. Insights and recommendations are scoped per location and recommender type, with full IAM-controlled access and audit visibility.
12 endpointsThe Serverless VPC Access API manages connectors that let serverless services (Cloud Run, Cloud Functions, App Engine standard) reach internal IP addresses inside a VPC network. It exposes connector create, list, get, and delete operations along with locations and long-running operation tracking. Connectors are the canonical bridge for serverless workloads that need private connectivity to databases, internal load balancers, or other VPC-only resources.
7 endpointsService Consumer Management is the Google Cloud API service producers use to manage tenant projects and tenancy units for services built on Service Infrastructure. It lets producers create per-consumer tenant projects, attach existing projects, apply project-level configuration like IAM bindings and billing accounts, and clean up by detaching, removing, or undeleting projects. This is the control plane behind multi-tenant SaaS-on-GCP offerings such as Cloud SQL or AlloyDB private services.
12 endpointsService Control is the runtime admission-control and telemetry-reporting endpoint for services integrated with Google's Service Infrastructure. Service producers call check before serving a request to enforce per-consumer policy, allocateQuota to debit metered quota buckets, and report to push usage and audit telemetry into the GCP control plane. It is what powers the per-consumer enforcement and billing for Google's own and partner-managed APIs.
3 endpointsService Directory is Google Cloud's managed service registry for discovering, publishing, and connecting services across GCP, on-prem, and other clouds. The API organises services into namespaces, registers individual services with metadata, and tracks endpoints with addresses, ports, and annotations. A resolve operation returns all healthy endpoints for a service so clients can do client-side load balancing or DNS lookup.
14 endpointsGoogle Service Management is the producer-side API for publishing and managing services on Google Cloud Platform's Service Infrastructure. Service producers create a service, submit configuration documents (.proto, OpenAPI, gRPC) describing endpoints and policies, manage rollouts that promote configs into production, and control which consumer projects have the service enabled. It powers the lifecycle of every Google API and customer-managed service that integrates with the Service Infrastructure.
19 endpointsService Networking automates the network plumbing required for managed Google Cloud services that need private connectivity into a customer's VPC, like Cloud SQL, Memorystore, and AlloyDB. The API lets you create and manage VPC peerings between a producer service and a consumer VPC, allocate private IP ranges from the consumer side, manage DNS zones for the producer service, and configure VPC Service Controls. It is the control plane behind 'Private services access' in the GCP UI.
25 endpointsService Usage is the consumer-side API for managing which Google Cloud services are enabled on a project, folder, or organization. Agents can list every available service in the catalogue, see which are currently enabled, enable or disable a service, and batch enable up to 20 services in one call. It is the API behind 'Enable APIs and services' in the GCP console and the foundation for any tooling that bootstraps GCP projects.
9 endpointsTraffic Director is Google Cloud's managed control plane for service mesh and proxyless gRPC architectures. Its single discovery endpoint reports the runtime status of connected Envoy proxies and gRPC clients — which clusters, listeners, routes, and endpoints each xDS client has accepted, and which versions are in use. Operators query this surface to debug mesh propagation, verify configuration roll-outs across thousands of sidecars, and confirm that a new route or endpoint update has reached every workload.
1 endpointsThe VM Migration API (Migrate to Virtual Machines) programmatically migrates VMware, AWS, and Azure virtual machine workloads to Google Compute Engine. It exposes sources, datacenter connectors, migrating VMs, clone and cutover jobs, replication cycles, groups, and target projects so platform teams can script migration waves, observe replication health, and finalize cutovers. It replaces a console-driven workflow with end-to-end automation suitable for large fleet migrations.
34 endpointsThe Google VMware Engine API programmatically manages dedicated VMware private clouds running natively on Google Cloud. It exposes private clouds, clusters, ESXi node types, networks, network peerings, HCX activation keys, DNS bindings, management DNS zones, NSX and vCenter credentials, and subnets so platform teams can script cluster provisioning, capacity changes, and network integration. It targets organizations running VMware workloads who need cloud control without changing the underlying hypervisor.
45 endpointsThe Google Workflow Executions API runs workflows defined in Google Cloud Workflows and exposes the lifecycle of each execution. Clients trigger a workflow with a JSON argument payload, observe step-by-step progress through stepEntries, cancel in-flight runs, and pull a structured execution result when complete. It also supports triggering workflows from Pub/Sub messages and exporting historical execution data for analysis. This is the runtime companion to the Workflows API, which manages workflow definitions.
9 endpointsThe Google Workflows API manages the definitions of Cloud Workflows — a serverless service that orchestrates calls to Google Cloud, third-party APIs, and HTTP endpoints in declarative YAML. Through this API you create, update, list, and delete workflow definitions and inspect available revisions for rollback and audit. To actually execute a workflow you call the companion Workflow Executions API; this API is purely the control plane for the definition lifecycle.
8 endpointsThe Google Workload Manager API automates the validation of enterprise workloads — SAP, Microsoft SQL Server, and other regulated deployments — against best-practice rules and recommendations on Google Cloud. Through evaluations and rules, teams discover deployed workload profiles, run on-demand or scheduled checks, and ingest insights for centralised reporting. The API exposes evaluations, executions, results, discovered profiles, and rules so engineering and SRE teams can shift workload compliance left into automation.
14 endpointsStep 1: Jentic One Host machine
# On the machine that will host your Jentic One instance:
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | shStep 2: Agent machine
# On the machine where your agent runs (keep this separate from the instance):
curl -fsSL https://raw.githubusercontent.com/jentic/jentic-one/main/tools/install.sh | sh
jentic register # connects your agent to your Jentic One instanceJentic One is in public beta. The setup above keeps your agent separate from the instance, which is what you want before using real credentials: an agent running as the same OS user as Jentic One can read its stored keys directly. Just evaluating? A single local install is fine to start. See the secure deployment guide for the tiers.