-
Notifications
You must be signed in to change notification settings - Fork 177
Privacy
IAP Desktop accesses Google Cloud Platform to:
- establish Cloud IAP TCP tunnels to VM instances
- list VMs and obtain metadata and logs for VM instances
- generate Windows logon credentials if requested
The application uses the following Google APIs for this purpose:
The application does not disclose or transmit any user data to APIs other than the ones listed above.
When you use the application for the first time, you have to authorize it to access your Google Cloud Platform on your behalf. As a result of this authorization, the application receives an OAuth refresh token which allows it to re-authenticate automatically the next time you use it. This refresh token is encrypted by using the Windows Data Protection API (DPAPI) and stored in the current user part of the Windows registry.
You can revoke your authorization at any time by selecting File > Sign out in the menu.
IAP Desktop also allows you to save the username and password used to connect to the Remote Desktop of a VM instance. These credentials are also stored in the current user part of the Windows registry. Like the OAuth refresh token, all passwords are encrypted by using the DPAPI before storage.
IAP Desktop is an open-source project and not an officially supported Google product.