{
  "auth": {
    "oauth2": {
      "scopes": {
        "https://www.googleapis.com/auth/cloud-platform": {
          "description": "See, edit, configure, and delete your Google Cloud data and see the email address for your Google Account."
        }
      }
    }
  },
  "resources": {
    "projects": {
      "resources": {
        "locations": {
          "methods": {
            "list": {
              "response": {
                "$ref": "GoogleCloudLocationListLocationsResponse"
              },
              "path": "v1alpha/{+name}/locations",
              "description": "Lists information about the supported locations for this service. This method lists locations based on the resource scope provided in the ListLocationsRequest.name field: * **Global locations**: If `name` is empty, the method lists the public locations available to all projects. * **Project-specific locations**: If `name` follows the format `projects/{project}`, the method lists locations visible to that specific project. This includes public, private, or other project-specific locations enabled for the project. For gRPC and client library implementations, the resource name is passed as the `name` field. For direct service calls, the resource name is incorporated into the request path based on the specific service implementation and version.",
              "flatPath": "v1alpha/projects/{projectsId}/locations",
              "id": "beyondcorp.projects.locations.list",
              "parameterOrder": [
                "name"
              ],
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "parameters": {
                "pageSize": {
                  "description": "The maximum number of results to return. If not set, the service selects a default.",
                  "format": "int32",
                  "type": "integer",
                  "location": "query"
                },
                "filter": {
                  "type": "string",
                  "location": "query",
                  "description": "A filter to narrow down results to a preferred subset. The filtering language accepts strings like `\"displayName=tokyo\"`, and is documented in more detail in [AIP-160](https://google.aip.dev/160)."
                },
                "extraLocationTypes": {
                  "type": "string",
                  "description": "Optional. Do not use this field unless explicitly documented otherwise. This is primarily for internal usage.",
                  "location": "query",
                  "repeated": true
                },
                "name": {
                  "description": "The resource that owns the locations collection, if applicable.",
                  "type": "string",
                  "location": "path",
                  "required": true,
                  "pattern": "^projects/[^/]+$"
                },
                "pageToken": {
                  "description": "A page token received from the `next_page_token` field in the response. Send that page token to receive the subsequent page.",
                  "type": "string",
                  "location": "query"
                }
              },
              "httpMethod": "GET"
            },
            "get": {
              "scopes": [
                "https://www.googleapis.com/auth/cloud-platform"
              ],
              "parameterOrder": [
                "name"
              ],
              "description": "Gets information about a location.",
              "response": {
                "$ref": "GoogleCloudLocationLocation"
              },
              "path": "v1alpha/{+name}",
              "id": "beyondcorp.projects.locations.get",
              "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}",
              "parameters": {
                "name": {
                  "location": "path",
                  "pattern": "^projects/[^/]+/locations/[^/]+$",
                  "required": true,
                  "description": "Resource name for the location.",
                  "type": "string"
                }
              },
              "httpMethod": "GET"
            }
          },
          "resources": {
            "connections": {
              "methods": {
                "list": {
                  "response": {
                    "$ref": "ListConnectionsResponse"
                  },
                  "id": "beyondcorp.projects.locations.connections.list",
                  "description": "Lists Connections in a given project and location.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections",
                  "parameterOrder": [
                    "parent"
                  ],
                  "parameters": {
                    "pageToken": {
                      "location": "query",
                      "description": "Optional. The next_page_token value returned from a previous ListConnectionsRequest, if any.",
                      "type": "string"
                    },
                    "pageSize": {
                      "location": "query",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "format": "int32",
                      "type": "integer"
                    },
                    "parent": {
                      "type": "string",
                      "description": "Required. The resource name of the connection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "required": true,
                      "location": "path"
                    },
                    "filter": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. A filter specifying constraints of a list operation."
                    },
                    "orderBy": {
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information.",
                      "location": "query",
                      "type": "string"
                    }
                  },
                  "path": "v1alpha/{+parent}/connections",
                  "httpMethod": "GET"
                },
                "getIamPolicy": {
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections/{connectionsId}:getIamPolicy",
                  "id": "beyondcorp.projects.locations.connections.getIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connections/[^/]+$"
                    },
                    "options.requestedPolicyVersion": {
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "type": "integer",
                      "location": "query",
                      "format": "int32"
                    }
                  },
                  "httpMethod": "GET",
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set."
                },
                "get": {
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connections/[^/]+$",
                      "description": "Required. BeyondCorp Connection name using the form: `projects/{project_id}/locations/{location_id}/connections/{connection_id}`"
                    }
                  },
                  "httpMethod": "GET",
                  "description": "Gets details of a single Connection.",
                  "response": {
                    "$ref": "Connection"
                  },
                  "path": "v1alpha/{+name}",
                  "parameterOrder": [
                    "name"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections/{connectionsId}",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "id": "beyondcorp.projects.locations.connections.get"
                },
                "setIamPolicy": {
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "id": "beyondcorp.projects.locations.connections.setIamPolicy",
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connections/[^/]+$"
                    }
                  },
                  "httpMethod": "POST",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections/{connectionsId}:setIamPolicy",
                  "parameterOrder": [
                    "resource"
                  ]
                },
                "resolve": {
                  "response": {
                    "$ref": "ResolveConnectionsResponse"
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections:resolve",
                  "parameters": {
                    "parent": {
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "description": "Required. The resource name of the connection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "location": "path",
                      "required": true
                    },
                    "pageToken": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ResolveConnectionsResponse, if any."
                    },
                    "pageSize": {
                      "type": "integer",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "format": "int32",
                      "location": "query"
                    },
                    "connectorId": {
                      "description": "Required. BeyondCorp Connector name of the connector associated with those connections using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector_id}`",
                      "type": "string",
                      "location": "query"
                    }
                  },
                  "httpMethod": "GET",
                  "description": "Resolves connections details for a given connector. An internal method called by a connector to find connections to connect to.",
                  "path": "v1alpha/{+parent}/connections:resolve",
                  "id": "beyondcorp.projects.locations.connections.resolve",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "create": {
                  "description": "Creates a new Connection in a given project and location.",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "request": {
                    "$ref": "Connection"
                  },
                  "path": "v1alpha/{+parent}/connections",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections",
                  "parameterOrder": [
                    "parent"
                  ],
                  "parameters": {
                    "requestId": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    },
                    "validateOnly": {
                      "location": "query",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "type": "boolean"
                    },
                    "parent": {
                      "description": "Required. The resource project name of the connection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$"
                    },
                    "connectionId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. User-settable connection resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or a letter."
                    }
                  },
                  "id": "beyondcorp.projects.locations.connections.create",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "POST"
                },
                "patch": {
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "id": "beyondcorp.projects.locations.connections.patch",
                  "path": "v1alpha/{+name}",
                  "parameters": {
                    "validateOnly": {
                      "location": "query",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "type": "boolean"
                    },
                    "allowMissing": {
                      "type": "boolean",
                      "description": "Optional. If set as true, will create the resource if it is not found.",
                      "location": "query"
                    },
                    "name": {
                      "location": "path",
                      "description": "Required. Unique resource name of the connection. The name is ignored when creating a connection.",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connections/[^/]+$"
                    },
                    "updateMask": {
                      "type": "string",
                      "description": "Required. Mask of fields to update. At least one path must be supplied in this field. The elements of the repeated paths field may only include these fields from [BeyondCorp.Connection]: * `labels` * `display_name` * `application_endpoint` * `connectors`",
                      "location": "query",
                      "format": "google-fieldmask"
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string",
                      "location": "query"
                    }
                  },
                  "httpMethod": "PATCH",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections/{connectionsId}",
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Updates the parameters of a single Connection.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "request": {
                    "$ref": "Connection"
                  }
                },
                "delete": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connections/{connectionsId}",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "httpMethod": "DELETE",
                  "parameters": {
                    "requestId": {
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string"
                    },
                    "name": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/connections/[^/]+$",
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connections/{connection_id}`",
                      "type": "string",
                      "required": true,
                      "location": "path"
                    },
                    "validateOnly": {
                      "location": "query",
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
                    }
                  },
                  "description": "Deletes a single Connection.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+name}",
                  "parameterOrder": [
                    "name"
                  ],
                  "id": "beyondcorp.projects.locations.connections.delete"
                }
              }
            },
            "insights": {
              "methods": {
                "list": {
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaListInsightsResponse"
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/insights",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "view": {
                      "description": "Required. List only metadata or full data.",
                      "type": "string",
                      "enumDescriptions": [
                        "The default / unset value. The API will default to the BASIC view.",
                        "Include basic metadata about the insight, but not the insight data. This is the default value (for both ListInsights and GetInsight).",
                        "Include everything."
                      ],
                      "enum": [
                        "INSIGHT_VIEW_UNSPECIFIED",
                        "BASIC",
                        "FULL"
                      ],
                      "location": "query"
                    },
                    "pageToken": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. A token identifying a page of results the server should return."
                    },
                    "parent": {
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "location": "path",
                      "description": "Required. The resource name of InsightMetadata using the form: `organizations/{organization_id}/locations/{location}` `projects/{project_id}/locations/{location_id}`",
                      "type": "string",
                      "required": true
                    },
                    "pageSize": {
                      "type": "integer",
                      "description": "Optional. Requested page size. Server may return fewer items than requested. If unspecified, server will pick an appropriate default. NOTE: Default page size is 50.",
                      "location": "query",
                      "format": "int32"
                    },
                    "endTime": {
                      "format": "google-datetime",
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Ending time for the duration for which insights are to be pulled. The default is the current time."
                    },
                    "filter": {
                      "description": "Optional. Filter expression to restrict the insights returned. Supported filter fields: * `type` * `category` * `subCategory` Examples: * \"category = application AND type = count\" * \"category = application AND subCategory = iap\" * \"type = status\" Allowed values: * type: [count, latency, status, list] * category: [application, device, request, security] * subCategory: [iap, caa, webprotect] NOTE: Only equality based comparison is allowed. Only `AND` conjunction is allowed. NOTE: The 'AND' in the filter field needs to be in capital letters only. NOTE: Just filtering on `subCategory` is not allowed. It should be passed in with the parent `category` too. (These expressions are based on the filter language described at https://google.aip.dev/160).",
                      "location": "query",
                      "type": "string"
                    },
                    "startTime": {
                      "location": "query",
                      "description": "Optional. Starting time for the duration for which insights are to be pulled. The default is 7 days before the current time.",
                      "format": "google-datetime",
                      "type": "string"
                    },
                    "orderBy": {
                      "type": "string",
                      "description": "Optional. Hint for how to order the results. This is currently ignored.",
                      "location": "query"
                    },
                    "aggregation": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Aggregation type. The default is 'DAILY'.",
                      "enumDescriptions": [
                        "Unspecified.",
                        "Insight should be aggregated at hourly level.",
                        "Insight should be aggregated at daily level.",
                        "Insight should be aggregated at weekly level.",
                        "Insight should be aggregated at monthly level.",
                        "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
                      ],
                      "enum": [
                        "AGGREGATION_UNSPECIFIED",
                        "HOURLY",
                        "DAILY",
                        "WEEKLY",
                        "MONTHLY",
                        "CUSTOM_DATE_RANGE"
                      ]
                    }
                  },
                  "httpMethod": "GET",
                  "id": "beyondcorp.projects.locations.insights.list",
                  "description": "Lists for all the available insights that could be fetched from the system. Allows to filter using category. Setting the `view` to `BASIC` will let you iterate over the list of insight metadatas.",
                  "path": "v1alpha/{+parent}/insights"
                },
                "configuredInsight": {
                  "id": "beyondcorp.projects.locations.insights.configuredInsight",
                  "parameterOrder": [
                    "insight"
                  ],
                  "description": "Gets the value for a selected particular insight based on the provided filters. Use the organization level path for fetching at org level and project level path for fetching the insight value specific to a particular project.",
                  "path": "v1alpha/{+insight}:configuredInsight",
                  "parameters": {
                    "pageSize": {
                      "description": "Optional. Requested page size. Server may return fewer items than requested. If unspecified, server will pick an appropriate default.",
                      "format": "int32",
                      "type": "integer",
                      "location": "query"
                    },
                    "fieldFilter": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. Other filterable/configurable parameters as applicable to the selected insight. Available fields could be fetched by calling insight list and get APIs in `BASIC` view. `=` is the only comparison operator supported. `AND` is the only logical operator supported. Usage: field_filter=\"fieldName1=fieldVal1 AND fieldName2=fieldVal2\". NOTE: Only `AND` conditions are allowed. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for the filtering the corresponding fields in this filter field. (These expressions are based on the filter language described at https://google.aip.dev/160)."
                    },
                    "endTime": {
                      "format": "google-datetime",
                      "type": "string",
                      "description": "Required. Ending time for the duration for which insight is to be pulled.",
                      "location": "query"
                    },
                    "customGrouping.groupFields": {
                      "type": "string",
                      "location": "query",
                      "repeated": true,
                      "description": "Required. Fields to be used for grouping. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for declaring the fields to be grouped-by here."
                    },
                    "customGrouping.fieldFilter": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Filterable parameters to be added to the grouping clause. Available fields could be fetched by calling insight list and get APIs in `BASIC` view. `=` is the only comparison operator supported. `AND` is the only logical operator supported. Usage: field_filter=\"fieldName1=fieldVal1 AND fieldName2=fieldVal2\". NOTE: Only `AND` conditions are allowed. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for the filtering the corresponding fields in this filter field. (These expressions are based on the filter language described at https://google.aip.dev/160)."
                    },
                    "startTime": {
                      "description": "Required. Starting time for the duration for which insight is to be pulled.",
                      "format": "google-datetime",
                      "location": "query",
                      "type": "string"
                    },
                    "aggregation": {
                      "description": "Required. Aggregation type. Available aggregation could be fetched by calling insight list and get APIs in `BASIC` view.",
                      "enum": [
                        "AGGREGATION_UNSPECIFIED",
                        "HOURLY",
                        "DAILY",
                        "WEEKLY",
                        "MONTHLY",
                        "CUSTOM_DATE_RANGE"
                      ],
                      "enumDescriptions": [
                        "Unspecified.",
                        "Insight should be aggregated at hourly level.",
                        "Insight should be aggregated at daily level.",
                        "Insight should be aggregated at weekly level.",
                        "Insight should be aggregated at monthly level.",
                        "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
                      ],
                      "type": "string",
                      "location": "query"
                    },
                    "pageToken": {
                      "location": "query",
                      "description": "Optional. Used to fetch the page represented by the token. Fetches the first page when not set.",
                      "type": "string"
                    },
                    "group": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Group id of the available groupings for the insight. Available groupings could be fetched by calling insight list and get APIs in `BASIC` view."
                    },
                    "insight": {
                      "type": "string",
                      "description": "Required. The resource name of the insight using the form: `organizations/{organization_id}/locations/{location_id}/insights/{insight_id}` `projects/{project_id}/locations/{location_id}/insights/{insight_id}`.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/insights/[^/]+$",
                      "required": true,
                      "location": "path"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/insights/{insightsId}:configuredInsight",
                  "httpMethod": "GET",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaConfiguredInsightResponse"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "get": {
                  "path": "v1alpha/{+name}",
                  "parameterOrder": [
                    "name"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/insights/[^/]+$",
                      "type": "string",
                      "description": "Required. The resource name of the insight using the form: `organizations/{organization_id}/locations/{location_id}/insights/{insight_id}` `projects/{project_id}/locations/{location_id}/insights/{insight_id}`"
                    },
                    "view": {
                      "type": "string",
                      "enum": [
                        "INSIGHT_VIEW_UNSPECIFIED",
                        "BASIC",
                        "FULL"
                      ],
                      "description": "Required. Metadata only or full data view.",
                      "location": "query",
                      "enumDescriptions": [
                        "The default / unset value. The API will default to the BASIC view.",
                        "Include basic metadata about the insight, but not the insight data. This is the default value (for both ListInsights and GetInsight).",
                        "Include everything."
                      ]
                    }
                  },
                  "id": "beyondcorp.projects.locations.insights.get",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/insights/{insightsId}",
                  "description": "Gets the value for a selected particular insight with default configuration. The default aggregation level is 'DAILY' and no grouping will be applied or default grouping if applicable. The data will be returned for recent 7 days starting the day before. The insight data size will be limited to 50 rows. Use the organization level path for fetching at org level and project level path for fetching the insight value specific to a particular project. Setting the `view` to `BASIC` will only return the metadata for the insight.",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsight"
                  }
                }
              }
            },
            "operations": {
              "methods": {
                "delete": {
                  "path": "v1alpha/{+name}",
                  "id": "beyondcorp.projects.locations.operations.delete",
                  "response": {
                    "$ref": "Empty"
                  },
                  "httpMethod": "DELETE",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/operations/[^/]+$",
                      "description": "The name of the operation resource to be deleted."
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/operations/{operationsId}",
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Deletes a long-running operation. This method indicates that the client is no longer interested in the operation result. It does not cancel the operation. If the server doesn't support this method, it returns `google.rpc.Code.UNIMPLEMENTED`."
                },
                "list": {
                  "id": "beyondcorp.projects.locations.operations.list",
                  "description": "Lists operations that match the specified filter in the request. If the server doesn't support this method, it returns `UNIMPLEMENTED`.",
                  "response": {
                    "$ref": "GoogleLongrunningListOperationsResponse"
                  },
                  "parameters": {
                    "pageToken": {
                      "type": "string",
                      "location": "query",
                      "description": "The standard list page token."
                    },
                    "returnPartialSuccess": {
                      "type": "boolean",
                      "description": "When set to `true`, operations that are reachable are returned as normal, and those that are unreachable are returned in the ListOperationsResponse.unreachable field. This can only be `true` when reading across collections. For example, when `parent` is set to `\"projects/example/locations/-\"`. This field is not supported by default and will result in an `UNIMPLEMENTED` error if set unless explicitly documented otherwise in service or product specific documentation.",
                      "location": "query"
                    },
                    "pageSize": {
                      "format": "int32",
                      "location": "query",
                      "type": "integer",
                      "description": "The standard list page size."
                    },
                    "name": {
                      "type": "string",
                      "required": true,
                      "location": "path",
                      "description": "The name of the operation's parent resource.",
                      "pattern": "^projects/[^/]+/locations/[^/]+$"
                    },
                    "filter": {
                      "location": "query",
                      "description": "The standard list filter.",
                      "type": "string"
                    }
                  },
                  "httpMethod": "GET",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameterOrder": [
                    "name"
                  ],
                  "path": "v1alpha/{+name}/operations",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/operations"
                },
                "cancel": {
                  "request": {
                    "$ref": "GoogleLongrunningCancelOperationRequest"
                  },
                  "description": "Starts asynchronous cancellation on a long-running operation. The server makes a best effort to cancel the operation, but success is not guaranteed. If the server doesn't support this method, it returns `google.rpc.Code.UNIMPLEMENTED`. Clients can use Operations.GetOperation or other methods to check whether the cancellation succeeded or whether the operation completed despite cancellation. On successful cancellation, the operation is not deleted; instead, it becomes an operation with an Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`.",
                  "parameterOrder": [
                    "name"
                  ],
                  "httpMethod": "POST",
                  "path": "v1alpha/{+name}:cancel",
                  "parameters": {
                    "name": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/operations/[^/]+$",
                      "description": "The name of the operation resource to be cancelled.",
                      "type": "string",
                      "required": true,
                      "location": "path"
                    }
                  },
                  "id": "beyondcorp.projects.locations.operations.cancel",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/operations/{operationsId}:cancel",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "Empty"
                  }
                },
                "get": {
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/operations/{operationsId}",
                  "path": "v1alpha/{+name}",
                  "id": "beyondcorp.projects.locations.operations.get",
                  "description": "Gets the latest state of a long-running operation. Clients can use this method to poll the operation result at intervals as recommended by the API service.",
                  "parameters": {
                    "name": {
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/operations/[^/]+$",
                      "required": true,
                      "type": "string",
                      "description": "The name of the operation resource."
                    }
                  },
                  "httpMethod": "GET",
                  "parameterOrder": [
                    "name"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                }
              }
            },
            "applicationDomains": {
              "methods": {
                "testIamPermissions": {
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "path": "v1alpha/{+resource}:testIamPermissions",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameterOrder": [
                    "resource"
                  ],
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applicationDomains/{applicationDomainsId}:testIamPermissions",
                  "httpMethod": "POST",
                  "parameters": {
                    "resource": {
                      "location": "path",
                      "required": true,
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/applicationDomains/[^/]+$"
                    }
                  },
                  "id": "beyondcorp.projects.locations.applicationDomains.testIamPermissions",
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  }
                },
                "setIamPolicy": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applicationDomains/{applicationDomainsId}:setIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "id": "beyondcorp.projects.locations.applicationDomains.setIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "httpMethod": "POST",
                  "parameters": {
                    "resource": {
                      "location": "path",
                      "required": true,
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/applicationDomains/[^/]+$"
                    }
                  }
                },
                "getIamPolicy": {
                  "id": "beyondcorp.projects.locations.applicationDomains.getIamPolicy",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applicationDomains/{applicationDomainsId}:getIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "httpMethod": "GET",
                  "parameters": {
                    "resource": {
                      "location": "path",
                      "required": true,
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/applicationDomains/[^/]+$",
                      "type": "string"
                    },
                    "options.requestedPolicyVersion": {
                      "type": "integer",
                      "format": "int32",
                      "location": "query",
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies)."
                    }
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set."
                }
              }
            },
            "connectors": {
              "methods": {
                "delete": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "validateOnly": {
                      "type": "boolean",
                      "location": "query",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
                    },
                    "name": {
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector_id}`",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$",
                      "type": "string",
                      "location": "path",
                      "required": true
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "location": "query",
                      "type": "string"
                    }
                  },
                  "httpMethod": "DELETE",
                  "path": "v1alpha/{+name}",
                  "description": "Deletes a single Connector.",
                  "id": "beyondcorp.projects.locations.connectors.delete",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}"
                },
                "setIamPolicy": {
                  "id": "beyondcorp.projects.locations.connectors.setIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}:setIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$"
                    }
                  },
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "parameterOrder": [
                    "resource"
                  ],
                  "httpMethod": "POST"
                },
                "create": {
                  "request": {
                    "$ref": "Connector"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "parameters": {
                    "connectorId": {
                      "description": "Optional. User-settable connector resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or a letter.",
                      "type": "string",
                      "location": "query"
                    },
                    "parent": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "type": "string",
                      "description": "Required. The resource project name of the connector location using the form: `projects/{project_id}/locations/{location_id}`"
                    },
                    "requestId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    },
                    "validateOnly": {
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query",
                      "type": "boolean"
                    }
                  },
                  "id": "beyondcorp.projects.locations.connectors.create",
                  "description": "Creates a new Connector in a given project and location.",
                  "path": "v1alpha/{+parent}/connectors",
                  "httpMethod": "POST"
                },
                "reportStatus": {
                  "httpMethod": "POST",
                  "parameterOrder": [
                    "connector"
                  ],
                  "parameters": {
                    "connector": {
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector}`",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}:reportStatus",
                  "request": {
                    "$ref": "ReportStatusRequest"
                  },
                  "id": "beyondcorp.projects.locations.connectors.reportStatus",
                  "path": "v1alpha/{+connector}:reportStatus",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Report status for a given connector.",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  }
                },
                "list": {
                  "parameterOrder": [
                    "parent"
                  ],
                  "response": {
                    "$ref": "ListConnectorsResponse"
                  },
                  "path": "v1alpha/{+parent}/connectors",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors",
                  "parameters": {
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ListConnectorsRequest, if any.",
                      "location": "query"
                    },
                    "pageSize": {
                      "format": "int32",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "location": "query",
                      "type": "integer"
                    },
                    "orderBy": {
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information.",
                      "location": "query",
                      "type": "string"
                    },
                    "filter": {
                      "location": "query",
                      "description": "Optional. A filter specifying constraints of a list operation.",
                      "type": "string"
                    },
                    "parent": {
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "description": "Required. The resource name of the connector location using the form: `projects/{project_id}/locations/{location_id}`",
                      "required": true,
                      "location": "path"
                    }
                  },
                  "httpMethod": "GET",
                  "id": "beyondcorp.projects.locations.connectors.list",
                  "description": "Lists Connectors in a given project and location."
                },
                "get": {
                  "parameters": {
                    "name": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$",
                      "type": "string",
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector_id}`",
                      "required": true,
                      "location": "path"
                    }
                  },
                  "httpMethod": "GET",
                  "path": "v1alpha/{+name}",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "Connector"
                  },
                  "description": "Gets details of a single Connector.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}",
                  "parameterOrder": [
                    "name"
                  ],
                  "id": "beyondcorp.projects.locations.connectors.get"
                },
                "getIamPolicy": {
                  "parameters": {
                    "options.requestedPolicyVersion": {
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "format": "int32",
                      "type": "integer",
                      "location": "query"
                    },
                    "resource": {
                      "required": true,
                      "type": "string",
                      "location": "path",
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$"
                    }
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "GET",
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}:getIamPolicy",
                  "parameterOrder": [
                    "resource"
                  ],
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.",
                  "id": "beyondcorp.projects.locations.connectors.getIamPolicy"
                },
                "patch": {
                  "path": "v1alpha/{+name}",
                  "request": {
                    "$ref": "Connector"
                  },
                  "description": "Updates the parameters of a single Connector.",
                  "id": "beyondcorp.projects.locations.connectors.patch",
                  "parameters": {
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "location": "query",
                      "type": "string"
                    },
                    "name": {
                      "description": "Required. Unique resource name of the connector. The name is ignored when creating a connector.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$",
                      "location": "path",
                      "required": true
                    },
                    "validateOnly": {
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "type": "boolean",
                      "location": "query"
                    },
                    "updateMask": {
                      "description": "Required. Mask of fields to update. At least one path must be supplied in this field. The elements of the repeated paths field may only include these fields from [BeyondCorp.Connector]: * `labels` * `display_name`",
                      "type": "string",
                      "location": "query",
                      "format": "google-fieldmask"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}",
                  "httpMethod": "PATCH",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "name"
                  ]
                },
                "resolveInstanceConfig": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "ResolveInstanceConfigResponse"
                  },
                  "parameters": {
                    "connector": {
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/connectors/[^/]+$",
                      "location": "path",
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector}`",
                      "type": "string"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/connectors/{connectorsId}:resolveInstanceConfig",
                  "httpMethod": "GET",
                  "id": "beyondcorp.projects.locations.connectors.resolveInstanceConfig",
                  "path": "v1alpha/{+connector}:resolveInstanceConfig",
                  "parameterOrder": [
                    "connector"
                  ],
                  "description": "Gets instance configuration for a given connector. An internal method called by a connector to get its container config."
                }
              }
            },
            "applications": {
              "methods": {
                "getIamPolicy": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applications/{applicationsId}:getIamPolicy",
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.",
                  "id": "beyondcorp.projects.locations.applications.getIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "httpMethod": "GET",
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "parameters": {
                    "options.requestedPolicyVersion": {
                      "location": "query",
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "format": "int32",
                      "type": "integer"
                    },
                    "resource": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/applications/[^/]+$",
                      "location": "path",
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "required": true,
                      "type": "string"
                    }
                  }
                },
                "setIamPolicy": {
                  "parameterOrder": [
                    "resource"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/applications/[^/]+$"
                    }
                  },
                  "httpMethod": "POST",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "id": "beyondcorp.projects.locations.applications.setIamPolicy",
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applications/{applicationsId}:setIamPolicy"
                },
                "testIamPermissions": {
                  "path": "v1alpha/{+resource}:testIamPermissions",
                  "parameters": {
                    "resource": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/applications/[^/]+$",
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field."
                    }
                  },
                  "httpMethod": "POST",
                  "parameterOrder": [
                    "resource"
                  ],
                  "id": "beyondcorp.projects.locations.applications.testIamPermissions",
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/applications/{applicationsId}:testIamPermissions",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning."
                }
              }
            },
            "securityGateways": {
              "methods": {
                "delete": {
                  "id": "beyondcorp.projects.locations.securityGateways.delete",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "path": "v1alpha/{+name}",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "name": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                      "description": "Required. BeyondCorp SecurityGateway name using the form: `projects/{project_id}/locations/{location_id}/securityGateways/{security_gateway_id}`",
                      "location": "path",
                      "required": true,
                      "type": "string"
                    },
                    "validateOnly": {
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query"
                    },
                    "requestId": {
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}",
                  "httpMethod": "DELETE",
                  "description": "Deletes a single SecurityGateway."
                },
                "list": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways",
                  "parameterOrder": [
                    "parent"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListSecurityGatewaysResponse"
                  },
                  "description": "Lists SecurityGateways in a given project and location.",
                  "id": "beyondcorp.projects.locations.securityGateways.list",
                  "path": "v1alpha/{+parent}/securityGateways",
                  "httpMethod": "GET",
                  "parameters": {
                    "filter": {
                      "type": "string",
                      "description": "Optional. A filter specifying constraints of a list operation. All fields in the SecurityGateway message are supported. For example, the following query will return the SecurityGateway with displayName \"test-security-gateway\" For more information, please refer to https://google.aip.dev/160.",
                      "location": "query"
                    },
                    "parent": {
                      "description": "Required. The parent location to which the resources belong. `projects/{project_id}/locations/{location_id}/`",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "location": "path",
                      "required": true,
                      "type": "string"
                    },
                    "pageSize": {
                      "format": "int32",
                      "location": "query",
                      "type": "integer",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried."
                    },
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ListSecurityGatewayRequest, if any.",
                      "location": "query"
                    },
                    "orderBy": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information."
                    }
                  }
                },
                "create": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameters": {
                    "securityGatewayId": {
                      "type": "string",
                      "description": "Optional. User-settable SecurityGateway resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or letter.",
                      "location": "query"
                    },
                    "parent": {
                      "description": "Required. The resource project name of the SecurityGateway location using the form: `projects/{project_id}/locations/{location_id}`",
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "type": "string",
                      "required": true
                    },
                    "requestId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request."
                    }
                  },
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway"
                  },
                  "httpMethod": "POST",
                  "parameterOrder": [
                    "parent"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways",
                  "id": "beyondcorp.projects.locations.securityGateways.create",
                  "description": "Creates a new Security Gateway in a given project and location.",
                  "path": "v1alpha/{+parent}/securityGateways"
                },
                "setIamPolicy": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}:setIamPolicy",
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "id": "beyondcorp.projects.locations.securityGateways.setIamPolicy",
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameterOrder": [
                    "resource"
                  ],
                  "httpMethod": "POST",
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "parameters": {
                    "resource": {
                      "type": "string",
                      "location": "path",
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$"
                    }
                  }
                },
                "patch": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway"
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "parameters": {
                    "updateMask": {
                      "description": "Optional. Mutable fields include: display_name, hubs.",
                      "type": "string",
                      "location": "query",
                      "format": "google-fieldmask"
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request timed out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string",
                      "location": "query"
                    },
                    "name": {
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                      "location": "path",
                      "type": "string",
                      "description": "Identifier. Name of the resource."
                    }
                  },
                  "httpMethod": "PATCH",
                  "description": "Updates the parameters of a single SecurityGateway.",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "path": "v1alpha/{+name}",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}",
                  "id": "beyondcorp.projects.locations.securityGateways.patch"
                },
                "get": {
                  "description": "Gets details of a single SecurityGateway.",
                  "parameters": {
                    "name": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                      "type": "string",
                      "description": "Required. The resource name of the PartnerTenant using the form: `projects/{project_id}/locations/{location_id}/securityGateway/{security_gateway_id}`"
                    }
                  },
                  "httpMethod": "GET",
                  "id": "beyondcorp.projects.locations.securityGateways.get",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}",
                  "path": "v1alpha/{+name}",
                  "parameterOrder": [
                    "name"
                  ]
                },
                "getIamPolicy": {
                  "parameterOrder": [
                    "resource"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "options.requestedPolicyVersion": {
                      "format": "int32",
                      "location": "query",
                      "type": "integer",
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies)."
                    },
                    "resource": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field."
                    }
                  },
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}:getIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "id": "beyondcorp.projects.locations.securityGateways.getIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  }
                },
                "testIamPermissions": {
                  "id": "beyondcorp.projects.locations.securityGateways.testIamPermissions",
                  "path": "v1alpha/{+resource}:testIamPermissions",
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameters": {
                    "resource": {
                      "type": "string",
                      "required": true,
                      "location": "path",
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$"
                    }
                  },
                  "httpMethod": "POST",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}:testIamPermissions",
                  "parameterOrder": [
                    "resource"
                  ],
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  }
                }
              },
              "resources": {
                "applications": {
                  "methods": {
                    "testIamPermissions": {
                      "id": "beyondcorp.projects.locations.securityGateways.applications.testIamPermissions",
                      "response": {
                        "$ref": "GoogleIamV1TestIamPermissionsResponse"
                      },
                      "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}:testIamPermissions",
                      "parameterOrder": [
                        "resource"
                      ],
                      "parameters": {
                        "resource": {
                          "location": "path",
                          "type": "string",
                          "required": true,
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$",
                          "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field."
                        }
                      },
                      "httpMethod": "POST",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "path": "v1alpha/{+resource}:testIamPermissions",
                      "request": {
                        "$ref": "GoogleIamV1TestIamPermissionsRequest"
                      }
                    },
                    "list": {
                      "description": "Lists Applications in a given project and location.",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "parameterOrder": [
                        "parent"
                      ],
                      "response": {
                        "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListApplicationsResponse"
                      },
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications",
                      "parameters": {
                        "orderBy": {
                          "type": "string",
                          "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information.",
                          "location": "query"
                        },
                        "pageToken": {
                          "description": "Optional. The next_page_token value returned from a previous ListApplicationsRequest, if any.",
                          "location": "query",
                          "type": "string"
                        },
                        "filter": {
                          "description": "Optional. A filter specifying constraints of a list operation. All fields in the Application message are supported. For example, the following query will return the Application with displayName \"test-application\" For more information, please refer to https://google.aip.dev/160.",
                          "location": "query",
                          "type": "string"
                        },
                        "pageSize": {
                          "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                          "format": "int32",
                          "location": "query",
                          "type": "integer"
                        },
                        "parent": {
                          "type": "string",
                          "description": "Required. The parent location to which the resources belong. `projects/{project_id}/locations/global/securityGateways/{security_gateway_id}`",
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                          "required": true,
                          "location": "path"
                        }
                      },
                      "path": "v1alpha/{+parent}/applications",
                      "httpMethod": "GET",
                      "id": "beyondcorp.projects.locations.securityGateways.applications.list"
                    },
                    "create": {
                      "request": {
                        "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication"
                      },
                      "httpMethod": "POST",
                      "parameters": {
                        "requestId": {
                          "location": "query",
                          "type": "string",
                          "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request."
                        },
                        "parent": {
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+$",
                          "description": "Required. The resource name of the parent SecurityGateway using the form: `projects/{project_id}/locations/global/securityGateways/{security_gateway_id}`",
                          "required": true,
                          "type": "string",
                          "location": "path"
                        },
                        "applicationId": {
                          "location": "query",
                          "type": "string",
                          "description": "Optional. User-settable Application resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or letter."
                        }
                      },
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications",
                      "path": "v1alpha/{+parent}/applications",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "response": {
                        "$ref": "GoogleLongrunningOperation"
                      },
                      "id": "beyondcorp.projects.locations.securityGateways.applications.create",
                      "description": "Creates a new Application in a given project and location.",
                      "parameterOrder": [
                        "parent"
                      ]
                    },
                    "get": {
                      "response": {
                        "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication"
                      },
                      "path": "v1alpha/{+name}",
                      "parameters": {
                        "name": {
                          "description": "Required. The resource name of the Application using the form: `projects/{project_id}/locations/global/securityGateway/{security_gateway_id}/applications/{application_id}`",
                          "type": "string",
                          "required": true,
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$",
                          "location": "path"
                        }
                      },
                      "description": "Gets details of a single Application.",
                      "httpMethod": "GET",
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}",
                      "parameterOrder": [
                        "name"
                      ],
                      "id": "beyondcorp.projects.locations.securityGateways.applications.get",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ]
                    },
                    "setIamPolicy": {
                      "id": "beyondcorp.projects.locations.securityGateways.applications.setIamPolicy",
                      "path": "v1alpha/{+resource}:setIamPolicy",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "parameters": {
                        "resource": {
                          "type": "string",
                          "required": true,
                          "location": "path",
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$",
                          "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field."
                        }
                      },
                      "parameterOrder": [
                        "resource"
                      ],
                      "httpMethod": "POST",
                      "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                      "response": {
                        "$ref": "GoogleIamV1Policy"
                      },
                      "request": {
                        "$ref": "GoogleIamV1SetIamPolicyRequest"
                      },
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}:setIamPolicy"
                    },
                    "getIamPolicy": {
                      "response": {
                        "$ref": "GoogleIamV1Policy"
                      },
                      "path": "v1alpha/{+resource}:getIamPolicy",
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}:getIamPolicy",
                      "parameterOrder": [
                        "resource"
                      ],
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "id": "beyondcorp.projects.locations.securityGateways.applications.getIamPolicy",
                      "parameters": {
                        "options.requestedPolicyVersion": {
                          "type": "integer",
                          "location": "query",
                          "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                          "format": "int32"
                        },
                        "resource": {
                          "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                          "required": true,
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$",
                          "location": "path",
                          "type": "string"
                        }
                      },
                      "httpMethod": "GET",
                      "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set."
                    },
                    "delete": {
                      "response": {
                        "$ref": "GoogleLongrunningOperation"
                      },
                      "description": "Deletes a single application.",
                      "path": "v1alpha/{+name}",
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}",
                      "parameters": {
                        "validateOnly": {
                          "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                          "location": "query",
                          "type": "boolean"
                        },
                        "name": {
                          "type": "string",
                          "location": "path",
                          "required": true,
                          "description": "Required. Name of the resource.",
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$"
                        },
                        "requestId": {
                          "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                          "location": "query",
                          "type": "string"
                        }
                      },
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "httpMethod": "DELETE",
                      "parameterOrder": [
                        "name"
                      ],
                      "id": "beyondcorp.projects.locations.securityGateways.applications.delete"
                    },
                    "patch": {
                      "description": "Updates the parameters of a single Application.",
                      "scopes": [
                        "https://www.googleapis.com/auth/cloud-platform"
                      ],
                      "request": {
                        "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication"
                      },
                      "parameters": {
                        "requestId": {
                          "location": "query",
                          "type": "string",
                          "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request timed out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                        },
                        "name": {
                          "pattern": "^projects/[^/]+/locations/[^/]+/securityGateways/[^/]+/applications/[^/]+$",
                          "location": "path",
                          "description": "Identifier. Name of the resource.",
                          "required": true,
                          "type": "string"
                        },
                        "updateMask": {
                          "type": "string",
                          "description": "Optional. Mutable fields include: display_name.",
                          "location": "query",
                          "format": "google-fieldmask"
                        }
                      },
                      "parameterOrder": [
                        "name"
                      ],
                      "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/securityGateways/{securityGatewaysId}/applications/{applicationsId}",
                      "httpMethod": "PATCH",
                      "response": {
                        "$ref": "GoogleLongrunningOperation"
                      },
                      "id": "beyondcorp.projects.locations.securityGateways.applications.patch",
                      "path": "v1alpha/{+name}"
                    }
                  }
                }
              }
            },
            "appConnections": {
              "methods": {
                "getIamPolicy": {
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "id": "beyondcorp.projects.locations.appConnections.getIamPolicy",
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}:getIamPolicy",
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "resource": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "type": "string",
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "required": true,
                      "location": "path"
                    },
                    "options.requestedPolicyVersion": {
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "type": "integer",
                      "format": "int32",
                      "location": "query"
                    }
                  }
                },
                "testIamPermissions": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}:testIamPermissions",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "POST",
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  },
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "location": "path",
                      "required": true
                    }
                  },
                  "id": "beyondcorp.projects.locations.appConnections.testIamPermissions",
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                  "parameterOrder": [
                    "resource"
                  ],
                  "path": "v1alpha/{+resource}:testIamPermissions"
                },
                "resolve": {
                  "id": "beyondcorp.projects.locations.appConnections.resolve",
                  "path": "v1alpha/{+parent}/appConnections:resolve",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections:resolve",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponse"
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "parent": {
                      "type": "string",
                      "location": "path",
                      "description": "Required. The resource name of the AppConnection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "required": true
                    },
                    "appConnectorId": {
                      "description": "Required. BeyondCorp Connector name of the connector associated with those AppConnections using the form: `projects/{project_id}/locations/{location_id}/appConnectors/{app_connector_id}`",
                      "location": "query",
                      "type": "string"
                    },
                    "pageToken": {
                      "description": "Optional. The next_page_token value returned from a previous ResolveAppConnectionsResponse, if any.",
                      "location": "query",
                      "type": "string"
                    },
                    "pageSize": {
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "location": "query",
                      "format": "int32",
                      "type": "integer"
                    }
                  },
                  "description": "Resolves AppConnections details for a given AppConnector. An internal method called by a connector to find AppConnections to connect to."
                },
                "list": {
                  "description": "Lists AppConnections in a given project and location.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections",
                  "id": "beyondcorp.projects.locations.appConnections.list",
                  "parameterOrder": [
                    "parent"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaListAppConnectionsResponse"
                  },
                  "httpMethod": "GET",
                  "parameters": {
                    "pageSize": {
                      "location": "query",
                      "type": "integer",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "format": "int32"
                    },
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ListAppConnectionsRequest, if any.",
                      "location": "query"
                    },
                    "filter": {
                      "description": "Optional. A filter specifying constraints of a list operation.",
                      "type": "string",
                      "location": "query"
                    },
                    "orderBy": {
                      "location": "query",
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information.",
                      "type": "string"
                    },
                    "parent": {
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "required": true,
                      "description": "Required. The resource name of the AppConnection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "location": "path"
                    }
                  },
                  "path": "v1alpha/{+parent}/appConnections",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "get": {
                  "httpMethod": "GET",
                  "parameters": {
                    "name": {
                      "type": "string",
                      "description": "Required. BeyondCorp AppConnection name using the form: `projects/{project_id}/locations/{location_id}/appConnections/{app_connection_id}`",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "location": "path",
                      "required": true
                    }
                  },
                  "id": "beyondcorp.projects.locations.appConnections.get",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+name}",
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Gets details of a single AppConnection.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection"
                  }
                },
                "delete": {
                  "parameterOrder": [
                    "name"
                  ],
                  "id": "beyondcorp.projects.locations.appConnections.delete",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+name}",
                  "httpMethod": "DELETE",
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/appConnections/{app_connection_id}`",
                      "type": "string"
                    },
                    "requestId": {
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if the original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string"
                    },
                    "validateOnly": {
                      "location": "query",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "type": "boolean"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}",
                  "description": "Deletes a single AppConnection.",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  }
                },
                "setIamPolicy": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "id": "beyondcorp.projects.locations.appConnections.setIamPolicy",
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}:setIamPolicy",
                  "httpMethod": "POST",
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "location": "path",
                      "required": true
                    }
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  }
                },
                "create": {
                  "description": "Creates a new AppConnection in a given project and location.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections",
                  "id": "beyondcorp.projects.locations.appConnections.create",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection"
                  },
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "httpMethod": "POST",
                  "parameters": {
                    "requestId": {
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if the original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string"
                    },
                    "validateOnly": {
                      "location": "query",
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
                    },
                    "parent": {
                      "description": "Required. The resource project name of the AppConnection location using the form: `projects/{project_id}/locations/{location_id}`",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$"
                    },
                    "appConnectionId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. User-settable AppConnection resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or a letter."
                    }
                  },
                  "path": "v1alpha/{+parent}/appConnections",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameterOrder": [
                    "parent"
                  ]
                },
                "patch": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnections/{appConnectionsId}",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection"
                  },
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "httpMethod": "PATCH",
                  "id": "beyondcorp.projects.locations.appConnections.patch",
                  "parameters": {
                    "requestId": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if the original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    },
                    "allowMissing": {
                      "location": "query",
                      "type": "boolean",
                      "description": "Optional. If set as true, will create the resource if it is not found."
                    },
                    "validateOnly": {
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query"
                    },
                    "name": {
                      "description": "Required. Unique resource name of the AppConnection. The name is ignored when creating a AppConnection.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnections/[^/]+$",
                      "type": "string",
                      "required": true,
                      "location": "path"
                    },
                    "updateMask": {
                      "location": "query",
                      "description": "Required. Mask of fields to update. At least one path must be supplied in this field. The elements of the repeated paths field may only include these fields from [BeyondCorp.AppConnection]: * `labels` * `display_name` * `application_endpoint` * `connectors`",
                      "type": "string",
                      "format": "google-fieldmask"
                    }
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Updates the parameters of a single AppConnection.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+name}"
                }
              }
            },
            "appConnectors": {
              "methods": {
                "delete": {
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "path": "v1alpha/{+name}",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}",
                  "parameters": {
                    "validateOnly": {
                      "type": "boolean",
                      "location": "query",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string",
                      "location": "query"
                    },
                    "name": {
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "description": "Required. BeyondCorp AppConnector name using the form: `projects/{project_id}/locations/{location_id}/appConnectors/{app_connector_id}`",
                      "type": "string"
                    }
                  },
                  "id": "beyondcorp.projects.locations.appConnectors.delete",
                  "parameterOrder": [
                    "name"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "DELETE",
                  "description": "Deletes a single AppConnector."
                },
                "getIamPolicy": {
                  "path": "v1alpha/{+resource}:getIamPolicy",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}:getIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "id": "beyondcorp.projects.locations.appConnectors.getIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "parameterOrder": [
                    "resource"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "location": "path",
                      "required": true
                    },
                    "options.requestedPolicyVersion": {
                      "format": "int32",
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "type": "integer",
                      "location": "query"
                    }
                  },
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set."
                },
                "patch": {
                  "parameterOrder": [
                    "name"
                  ],
                  "id": "beyondcorp.projects.locations.appConnectors.patch",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+name}",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector"
                  },
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "description": "Updates the parameters of a single AppConnector.",
                  "parameters": {
                    "name": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "description": "Required. Unique resource name of the AppConnector. The name is ignored when creating a AppConnector.",
                      "type": "string"
                    },
                    "validateOnly": {
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query",
                      "type": "boolean"
                    },
                    "updateMask": {
                      "description": "Required. Mask of fields to update. At least one path must be supplied in this field. The elements of the repeated paths field may only include these fields from [BeyondCorp.AppConnector]: * `labels` * `display_name`",
                      "format": "google-fieldmask",
                      "location": "query",
                      "type": "string"
                    },
                    "requestId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}",
                  "httpMethod": "PATCH"
                },
                "testIamPermissions": {
                  "parameterOrder": [
                    "resource"
                  ],
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}:testIamPermissions",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+resource}:testIamPermissions",
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  },
                  "id": "beyondcorp.projects.locations.appConnectors.testIamPermissions",
                  "parameters": {
                    "resource": {
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "required": true,
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "location": "path"
                    }
                  },
                  "httpMethod": "POST"
                },
                "resolveInstanceConfig": {
                  "id": "beyondcorp.projects.locations.appConnectors.resolveInstanceConfig",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}:resolveInstanceConfig",
                  "description": "Gets instance configuration for a given AppConnector. An internal method called by a AppConnector to get its container config.",
                  "httpMethod": "GET",
                  "parameters": {
                    "appConnector": {
                      "type": "string",
                      "description": "Required. BeyondCorp AppConnector name using the form: `projects/{project_id}/locations/{location_id}/appConnectors/{app_connector}`",
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "required": true
                    }
                  },
                  "parameterOrder": [
                    "appConnector"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaResolveInstanceConfigResponse"
                  },
                  "path": "v1alpha/{+appConnector}:resolveInstanceConfig",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "reportStatus": {
                  "httpMethod": "POST",
                  "parameters": {
                    "appConnector": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "location": "path",
                      "description": "Required. BeyondCorp Connector name using the form: `projects/{project_id}/locations/{location_id}/connectors/{connector}`",
                      "required": true,
                      "type": "string"
                    }
                  },
                  "id": "beyondcorp.projects.locations.appConnectors.reportStatus",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "appConnector"
                  ],
                  "path": "v1alpha/{+appConnector}:reportStatus",
                  "description": "Report status for a given connector.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}:reportStatus",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaReportStatusRequest"
                  }
                },
                "setIamPolicy": {
                  "parameters": {
                    "resource": {
                      "type": "string",
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "required": true,
                      "location": "path"
                    }
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "id": "beyondcorp.projects.locations.appConnectors.setIamPolicy",
                  "httpMethod": "POST",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}:setIamPolicy",
                  "parameterOrder": [
                    "resource"
                  ],
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  }
                },
                "get": {
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector"
                  },
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors/{appConnectorsId}",
                  "parameterOrder": [
                    "name"
                  ],
                  "id": "beyondcorp.projects.locations.appConnectors.get",
                  "path": "v1alpha/{+name}",
                  "parameters": {
                    "name": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appConnectors/[^/]+$",
                      "description": "Required. BeyondCorp AppConnector name using the form: `projects/{project_id}/locations/{location_id}/appConnectors/{app_connector_id}`",
                      "type": "string"
                    }
                  },
                  "httpMethod": "GET",
                  "description": "Gets details of a single AppConnector."
                },
                "create": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors",
                  "path": "v1alpha/{+parent}/appConnectors",
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "id": "beyondcorp.projects.locations.appConnectors.create",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector"
                  },
                  "httpMethod": "POST",
                  "parameters": {
                    "appConnectorId": {
                      "location": "query",
                      "description": "Optional. User-settable AppConnector resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or a letter.",
                      "type": "string"
                    },
                    "validateOnly": {
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query",
                      "type": "boolean"
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "location": "query",
                      "type": "string"
                    },
                    "parent": {
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "location": "path",
                      "type": "string",
                      "description": "Required. The resource project name of the AppConnector location using the form: `projects/{project_id}/locations/{location_id}`"
                    }
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "description": "Creates a new AppConnector in a given project and location.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "list": {
                  "id": "beyondcorp.projects.locations.appConnectors.list",
                  "httpMethod": "GET",
                  "parameters": {
                    "pageSize": {
                      "format": "int32",
                      "location": "query",
                      "type": "integer",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried."
                    },
                    "parent": {
                      "description": "Required. The resource name of the AppConnector location using the form: `projects/{project_id}/locations/{location_id}`",
                      "type": "string",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "location": "path",
                      "required": true
                    },
                    "filter": {
                      "description": "Optional. A filter specifying constraints of a list operation.",
                      "type": "string",
                      "location": "query"
                    },
                    "pageToken": {
                      "location": "query",
                      "description": "Optional. The next_page_token value returned from a previous ListAppConnectorsRequest, if any.",
                      "type": "string"
                    },
                    "orderBy": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information."
                    }
                  },
                  "description": "Lists AppConnectors in a given project and location.",
                  "path": "v1alpha/{+parent}/appConnectors",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appConnectors",
                  "parameterOrder": [
                    "parent"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaListAppConnectorsResponse"
                  }
                }
              }
            },
            "appGateways": {
              "methods": {
                "get": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways/{appGatewaysId}",
                  "response": {
                    "$ref": "AppGateway"
                  },
                  "path": "v1alpha/{+name}",
                  "httpMethod": "GET",
                  "parameterOrder": [
                    "name"
                  ],
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/appGateways/[^/]+$",
                      "type": "string",
                      "description": "Required. BeyondCorp AppGateway name using the form: `projects/{project_id}/locations/{location_id}/appGateways/{app_gateway_id}`"
                    }
                  },
                  "id": "beyondcorp.projects.locations.appGateways.get",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Gets details of a single AppGateway."
                },
                "testIamPermissions": {
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Returns permissions that a caller has on the specified resource. If the resource does not exist, this will return an empty set of permissions, not a `NOT_FOUND` error. Note: This operation is designed to be used for building permission-aware UIs and command-line tools, not for authorization checking. This operation may \"fail open\" without warning.",
                  "response": {
                    "$ref": "GoogleIamV1TestIamPermissionsResponse"
                  },
                  "parameters": {
                    "resource": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/appGateways/[^/]+$",
                      "description": "REQUIRED: The resource for which the policy detail is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "location": "path",
                      "required": true
                    }
                  },
                  "httpMethod": "POST",
                  "path": "v1alpha/{+resource}:testIamPermissions",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways/{appGatewaysId}:testIamPermissions",
                  "parameterOrder": [
                    "resource"
                  ],
                  "id": "beyondcorp.projects.locations.appGateways.testIamPermissions",
                  "request": {
                    "$ref": "GoogleIamV1TestIamPermissionsRequest"
                  }
                },
                "delete": {
                  "description": "Deletes a single AppGateway.",
                  "path": "v1alpha/{+name}",
                  "httpMethod": "DELETE",
                  "parameters": {
                    "name": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+/appGateways/[^/]+$",
                      "type": "string",
                      "description": "Required. BeyondCorp AppGateway name using the form: `projects/{project_id}/locations/{location_id}/appGateways/{app_gateway_id}`"
                    },
                    "validateOnly": {
                      "location": "query",
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
                    },
                    "requestId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    }
                  },
                  "id": "beyondcorp.projects.locations.appGateways.delete",
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways/{appGatewaysId}",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "name"
                  ]
                },
                "list": {
                  "response": {
                    "$ref": "ListAppGatewaysResponse"
                  },
                  "path": "v1alpha/{+parent}/appGateways",
                  "parameters": {
                    "pageSize": {
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "type": "integer",
                      "location": "query",
                      "format": "int32"
                    },
                    "orderBy": {
                      "type": "string",
                      "description": "Optional. Specifies the ordering of results. See [Sorting order](https://cloud.google.com/apis/design/design_patterns#sorting_order) for more information.",
                      "location": "query"
                    },
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ListAppGatewaysRequest, if any.",
                      "location": "query"
                    },
                    "parent": {
                      "type": "string",
                      "location": "path",
                      "description": "Required. The resource name of the AppGateway location using the form: `projects/{project_id}/locations/{location_id}`",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+$"
                    },
                    "filter": {
                      "description": "Optional. A filter specifying constraints of a list operation.",
                      "type": "string",
                      "location": "query"
                    }
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways",
                  "httpMethod": "GET",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "id": "beyondcorp.projects.locations.appGateways.list",
                  "description": "Lists AppGateways in a given project and location.",
                  "parameterOrder": [
                    "parent"
                  ]
                },
                "create": {
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "parameterOrder": [
                    "parent"
                  ],
                  "request": {
                    "$ref": "AppGateway"
                  },
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways",
                  "id": "beyondcorp.projects.locations.appGateways.create",
                  "parameters": {
                    "appGatewayId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. User-settable AppGateway resource ID. * Must start with a letter. * Must contain between 4-63 characters from `/a-z-/`. * Must end with a number or a letter."
                    },
                    "validateOnly": {
                      "type": "boolean",
                      "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
                      "location": "query"
                    },
                    "requestId": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
                    },
                    "parent": {
                      "required": true,
                      "location": "path",
                      "pattern": "^projects/[^/]+/locations/[^/]+$",
                      "type": "string",
                      "description": "Required. The resource project name of the AppGateway location using the form: `projects/{project_id}/locations/{location_id}`"
                    }
                  },
                  "path": "v1alpha/{+parent}/appGateways",
                  "httpMethod": "POST",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Creates a new AppGateway in a given project and location."
                },
                "setIamPolicy": {
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways/{appGatewaysId}:setIamPolicy",
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "path": "v1alpha/{+resource}:setIamPolicy",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "POST",
                  "request": {
                    "$ref": "GoogleIamV1SetIamPolicyRequest"
                  },
                  "parameters": {
                    "resource": {
                      "pattern": "^projects/[^/]+/locations/[^/]+/appGateways/[^/]+$",
                      "description": "REQUIRED: The resource for which the policy is being specified. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "type": "string",
                      "location": "path",
                      "required": true
                    }
                  },
                  "description": "Sets the access control policy on the specified resource. Replaces any existing policy. Can return `NOT_FOUND`, `INVALID_ARGUMENT`, and `PERMISSION_DENIED` errors.",
                  "id": "beyondcorp.projects.locations.appGateways.setIamPolicy",
                  "parameterOrder": [
                    "resource"
                  ]
                },
                "getIamPolicy": {
                  "description": "Gets the access control policy for a resource. Returns an empty policy if the resource exists and does not have a policy set.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "parameterOrder": [
                    "resource"
                  ],
                  "flatPath": "v1alpha/projects/{projectsId}/locations/{locationsId}/appGateways/{appGatewaysId}:getIamPolicy",
                  "parameters": {
                    "options.requestedPolicyVersion": {
                      "format": "int32",
                      "type": "integer",
                      "description": "Optional. The maximum policy version that will be used to format the policy. Valid values are 0, 1, and 3. Requests specifying an invalid value will be rejected. Requests for policies with any conditional role bindings must specify version 3. Policies with no conditional role bindings may specify any valid value or leave the field unset. The policy in the response might use the policy version that you specified, or it might use a lower policy version. For example, if you specify version 3, but the policy has no conditional role bindings, the response uses version 1. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
                      "location": "query"
                    },
                    "resource": {
                      "description": "REQUIRED: The resource for which the policy is being requested. See [Resource names](https://cloud.google.com/apis/design/resource_names) for the appropriate value for this field.",
                      "location": "path",
                      "required": true,
                      "pattern": "^projects/[^/]+/locations/[^/]+/appGateways/[^/]+$",
                      "type": "string"
                    }
                  },
                  "response": {
                    "$ref": "GoogleIamV1Policy"
                  },
                  "id": "beyondcorp.projects.locations.appGateways.getIamPolicy",
                  "httpMethod": "GET",
                  "path": "v1alpha/{+resource}:getIamPolicy"
                }
              }
            }
          }
        }
      }
    },
    "organizations": {
      "resources": {
        "locations": {
          "resources": {
            "operations": {
              "methods": {
                "delete": {
                  "id": "beyondcorp.organizations.locations.operations.delete",
                  "path": "v1alpha/{+name}",
                  "description": "Deletes a long-running operation. This method indicates that the client is no longer interested in the operation result. It does not cancel the operation. If the server doesn't support this method, it returns `google.rpc.Code.UNIMPLEMENTED`.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/operations/{operationsId}",
                  "parameterOrder": [
                    "name"
                  ],
                  "httpMethod": "DELETE",
                  "parameters": {
                    "name": {
                      "type": "string",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/operations/[^/]+$",
                      "required": true,
                      "location": "path",
                      "description": "The name of the operation resource to be deleted."
                    }
                  },
                  "response": {
                    "$ref": "Empty"
                  }
                },
                "get": {
                  "response": {
                    "$ref": "GoogleLongrunningOperation"
                  },
                  "description": "Gets the latest state of a long-running operation. Clients can use this method to poll the operation result at intervals as recommended by the API service.",
                  "path": "v1alpha/{+name}",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/operations/{operationsId}",
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "description": "The name of the operation resource.",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/operations/[^/]+$"
                    }
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "id": "beyondcorp.organizations.locations.operations.get",
                  "httpMethod": "GET"
                },
                "list": {
                  "parameters": {
                    "pageToken": {
                      "type": "string",
                      "location": "query",
                      "description": "The standard list page token."
                    },
                    "pageSize": {
                      "format": "int32",
                      "type": "integer",
                      "location": "query",
                      "description": "The standard list page size."
                    },
                    "filter": {
                      "description": "The standard list filter.",
                      "location": "query",
                      "type": "string"
                    },
                    "name": {
                      "type": "string",
                      "required": true,
                      "pattern": "^organizations/[^/]+/locations/[^/]+$",
                      "location": "path",
                      "description": "The name of the operation's parent resource."
                    },
                    "returnPartialSuccess": {
                      "description": "When set to `true`, operations that are reachable are returned as normal, and those that are unreachable are returned in the ListOperationsResponse.unreachable field. This can only be `true` when reading across collections. For example, when `parent` is set to `\"projects/example/locations/-\"`. This field is not supported by default and will result in an `UNIMPLEMENTED` error if set unless explicitly documented otherwise in service or product specific documentation.",
                      "type": "boolean",
                      "location": "query"
                    }
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "httpMethod": "GET",
                  "response": {
                    "$ref": "GoogleLongrunningListOperationsResponse"
                  },
                  "id": "beyondcorp.organizations.locations.operations.list",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/operations",
                  "description": "Lists operations that match the specified filter in the request. If the server doesn't support this method, it returns `UNIMPLEMENTED`.",
                  "path": "v1alpha/{+name}/operations",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                },
                "cancel": {
                  "path": "v1alpha/{+name}:cancel",
                  "id": "beyondcorp.organizations.locations.operations.cancel",
                  "parameters": {
                    "name": {
                      "type": "string",
                      "description": "The name of the operation resource to be cancelled.",
                      "required": true,
                      "location": "path",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/operations/[^/]+$"
                    }
                  },
                  "httpMethod": "POST",
                  "request": {
                    "$ref": "GoogleLongrunningCancelOperationRequest"
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "response": {
                    "$ref": "Empty"
                  },
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/operations/{operationsId}:cancel",
                  "description": "Starts asynchronous cancellation on a long-running operation. The server makes a best effort to cancel the operation, but success is not guaranteed. If the server doesn't support this method, it returns `google.rpc.Code.UNIMPLEMENTED`. Clients can use Operations.GetOperation or other methods to check whether the cancellation succeeded or whether the operation completed despite cancellation. On successful cancellation, the operation is not deleted; instead, it becomes an operation with an Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ]
                }
              }
            },
            "subscriptions": {
              "methods": {
                "create": {
                  "parameters": {
                    "parent": {
                      "description": "Required. The resource name of the subscription location using the form: `organizations/{organization_id}/locations/{location}`",
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "pattern": "^organizations/[^/]+/locations/[^/]+$"
                    }
                  },
                  "httpMethod": "POST",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
                  },
                  "id": "beyondcorp.organizations.locations.subscriptions.create",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions",
                  "path": "v1alpha/{+parent}/subscriptions",
                  "parameterOrder": [
                    "parent"
                  ],
                  "description": "Creates a new BeyondCorp Enterprise Subscription in a given organization. Location will always be global as BeyondCorp subscriptions are per organization.",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
                  }
                },
                "cancel": {
                  "parameters": {
                    "name": {
                      "description": "Required. Name of the resource.",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/subscriptions/[^/]+$",
                      "required": true,
                      "location": "path",
                      "type": "string"
                    },
                    "requestId": {
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string",
                      "location": "query"
                    }
                  },
                  "path": "v1alpha/{+name}:cancel",
                  "httpMethod": "GET",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaCancelSubscriptionResponse"
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Cancels an existing BeyondCorp Enterprise Subscription in a given organization. Location will always be global as BeyondCorp subscriptions are per organization. Returns the timestamp for when the cancellation will become effective",
                  "id": "beyondcorp.organizations.locations.subscriptions.cancel",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions/{subscriptionsId}:cancel"
                },
                "list": {
                  "description": "Lists Subscriptions in a given organization and location.",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaListSubscriptionsResponse"
                  },
                  "path": "v1alpha/{+parent}/subscriptions",
                  "parameters": {
                    "parent": {
                      "description": "Required. The resource name of Subscription using the form: `organizations/{organization_id}/locations/{location}`",
                      "type": "string",
                      "location": "path",
                      "required": true,
                      "pattern": "^organizations/[^/]+/locations/[^/]+$"
                    },
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. The next_page_token value returned from a previous ListSubscriptionsRequest, if any.",
                      "location": "query"
                    },
                    "pageSize": {
                      "format": "int32",
                      "type": "integer",
                      "description": "Optional. The maximum number of items to return. If not specified, a default value of 50 will be used by the service. Regardless of the page_size value, the response may include a partial list and a caller should only rely on response's next_page_token to determine if there are more instances left to be queried.",
                      "location": "query"
                    }
                  },
                  "id": "beyondcorp.organizations.locations.subscriptions.list",
                  "httpMethod": "GET",
                  "parameterOrder": [
                    "parent"
                  ],
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions"
                },
                "patch": {
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions/{subscriptionsId}",
                  "request": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
                  },
                  "description": "Updates an existing BeyondCorp Enterprise Subscription in a given organization. Location will always be global as BeyondCorp subscriptions are per organization.",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
                  },
                  "id": "beyondcorp.organizations.locations.subscriptions.patch",
                  "path": "v1alpha/{+name}",
                  "parameters": {
                    "name": {
                      "description": "Identifier. Unique resource name of the Subscription. The name is ignored when creating a subscription.",
                      "type": "string",
                      "location": "path",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/subscriptions/[^/]+$",
                      "required": true
                    },
                    "requestId": {
                      "type": "string",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "location": "query"
                    },
                    "updateMask": {
                      "location": "query",
                      "format": "google-fieldmask",
                      "type": "string",
                      "description": "Required. Field mask is used to specify the fields to be overwritten in the Subscription resource by the update. The fields specified in the update_mask are relative to the resource, not the full request. A field will be overwritten if it is in the mask. Mutable fields: seat_count."
                    }
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "httpMethod": "PATCH"
                },
                "get": {
                  "description": "Gets details of a single Subscription.",
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
                  },
                  "path": "v1alpha/{+name}",
                  "id": "beyondcorp.organizations.locations.subscriptions.get",
                  "parameters": {
                    "name": {
                      "type": "string",
                      "description": "Required. The resource name of Subscription using the form: `organizations/{organization_id}/locations/{location}/subscriptions/{subscription_id}`",
                      "required": true,
                      "location": "path",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/subscriptions/[^/]+$"
                    }
                  },
                  "parameterOrder": [
                    "name"
                  ],
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions/{subscriptionsId}",
                  "httpMethod": "GET"
                },
                "restart": {
                  "description": "Restarts an existing BeyondCorp Enterprise Subscription in a given organization, that is scheduled for cancellation. Location will always be global as BeyondCorp subscriptions are per organization. Returns the timestamp for when the cancellation will become effective",
                  "parameterOrder": [
                    "name"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaRestartSubscriptionResponse"
                  },
                  "parameters": {
                    "name": {
                      "location": "path",
                      "required": true,
                      "type": "string",
                      "description": "Required. Name of the resource.",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/subscriptions/[^/]+$"
                    },
                    "requestId": {
                      "location": "query",
                      "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
                      "type": "string"
                    }
                  },
                  "httpMethod": "GET",
                  "id": "beyondcorp.organizations.locations.subscriptions.restart",
                  "path": "v1alpha/{+name}:restart",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/subscriptions/{subscriptionsId}:restart"
                }
              }
            },
            "insights": {
              "methods": {
                "configuredInsight": {
                  "parameterOrder": [
                    "insight"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaConfiguredInsightResponse"
                  },
                  "path": "v1alpha/{+insight}:configuredInsight",
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/insights/{insightsId}:configuredInsight",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "httpMethod": "GET",
                  "parameters": {
                    "aggregation": {
                      "enumDescriptions": [
                        "Unspecified.",
                        "Insight should be aggregated at hourly level.",
                        "Insight should be aggregated at daily level.",
                        "Insight should be aggregated at weekly level.",
                        "Insight should be aggregated at monthly level.",
                        "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
                      ],
                      "enum": [
                        "AGGREGATION_UNSPECIFIED",
                        "HOURLY",
                        "DAILY",
                        "WEEKLY",
                        "MONTHLY",
                        "CUSTOM_DATE_RANGE"
                      ],
                      "description": "Required. Aggregation type. Available aggregation could be fetched by calling insight list and get APIs in `BASIC` view.",
                      "location": "query",
                      "type": "string"
                    },
                    "pageToken": {
                      "description": "Optional. Used to fetch the page represented by the token. Fetches the first page when not set.",
                      "type": "string",
                      "location": "query"
                    },
                    "fieldFilter": {
                      "type": "string",
                      "location": "query",
                      "description": "Optional. Other filterable/configurable parameters as applicable to the selected insight. Available fields could be fetched by calling insight list and get APIs in `BASIC` view. `=` is the only comparison operator supported. `AND` is the only logical operator supported. Usage: field_filter=\"fieldName1=fieldVal1 AND fieldName2=fieldVal2\". NOTE: Only `AND` conditions are allowed. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for the filtering the corresponding fields in this filter field. (These expressions are based on the filter language described at https://google.aip.dev/160)."
                    },
                    "endTime": {
                      "type": "string",
                      "location": "query",
                      "format": "google-datetime",
                      "description": "Required. Ending time for the duration for which insight is to be pulled."
                    },
                    "customGrouping.groupFields": {
                      "description": "Required. Fields to be used for grouping. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for declaring the fields to be grouped-by here.",
                      "type": "string",
                      "location": "query",
                      "repeated": true
                    },
                    "customGrouping.fieldFilter": {
                      "description": "Optional. Filterable parameters to be added to the grouping clause. Available fields could be fetched by calling insight list and get APIs in `BASIC` view. `=` is the only comparison operator supported. `AND` is the only logical operator supported. Usage: field_filter=\"fieldName1=fieldVal1 AND fieldName2=fieldVal2\". NOTE: Only `AND` conditions are allowed. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for the filtering the corresponding fields in this filter field. (These expressions are based on the filter language described at https://google.aip.dev/160).",
                      "location": "query",
                      "type": "string"
                    },
                    "group": {
                      "type": "string",
                      "description": "Optional. Group id of the available groupings for the insight. Available groupings could be fetched by calling insight list and get APIs in `BASIC` view.",
                      "location": "query"
                    },
                    "pageSize": {
                      "description": "Optional. Requested page size. Server may return fewer items than requested. If unspecified, server will pick an appropriate default.",
                      "location": "query",
                      "format": "int32",
                      "type": "integer"
                    },
                    "insight": {
                      "required": true,
                      "location": "path",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/insights/[^/]+$",
                      "type": "string",
                      "description": "Required. The resource name of the insight using the form: `organizations/{organization_id}/locations/{location_id}/insights/{insight_id}` `projects/{project_id}/locations/{location_id}/insights/{insight_id}`."
                    },
                    "startTime": {
                      "type": "string",
                      "description": "Required. Starting time for the duration for which insight is to be pulled.",
                      "location": "query",
                      "format": "google-datetime"
                    }
                  },
                  "description": "Gets the value for a selected particular insight based on the provided filters. Use the organization level path for fetching at org level and project level path for fetching the insight value specific to a particular project.",
                  "id": "beyondcorp.organizations.locations.insights.configuredInsight"
                },
                "get": {
                  "parameters": {
                    "name": {
                      "description": "Required. The resource name of the insight using the form: `organizations/{organization_id}/locations/{location_id}/insights/{insight_id}` `projects/{project_id}/locations/{location_id}/insights/{insight_id}`",
                      "pattern": "^organizations/[^/]+/locations/[^/]+/insights/[^/]+$",
                      "required": true,
                      "type": "string",
                      "location": "path"
                    },
                    "view": {
                      "enum": [
                        "INSIGHT_VIEW_UNSPECIFIED",
                        "BASIC",
                        "FULL"
                      ],
                      "description": "Required. Metadata only or full data view.",
                      "location": "query",
                      "type": "string",
                      "enumDescriptions": [
                        "The default / unset value. The API will default to the BASIC view.",
                        "Include basic metadata about the insight, but not the insight data. This is the default value (for both ListInsights and GetInsight).",
                        "Include everything."
                      ]
                    }
                  },
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsight"
                  },
                  "httpMethod": "GET",
                  "parameterOrder": [
                    "name"
                  ],
                  "description": "Gets the value for a selected particular insight with default configuration. The default aggregation level is 'DAILY' and no grouping will be applied or default grouping if applicable. The data will be returned for recent 7 days starting the day before. The insight data size will be limited to 50 rows. Use the organization level path for fetching at org level and project level path for fetching the insight value specific to a particular project. Setting the `view` to `BASIC` will only return the metadata for the insight.",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/insights/{insightsId}",
                  "id": "beyondcorp.organizations.locations.insights.get",
                  "path": "v1alpha/{+name}"
                },
                "list": {
                  "flatPath": "v1alpha/organizations/{organizationsId}/locations/{locationsId}/insights",
                  "parameters": {
                    "parent": {
                      "pattern": "^organizations/[^/]+/locations/[^/]+$",
                      "description": "Required. The resource name of InsightMetadata using the form: `organizations/{organization_id}/locations/{location}` `projects/{project_id}/locations/{location_id}`",
                      "required": true,
                      "type": "string",
                      "location": "path"
                    },
                    "view": {
                      "enum": [
                        "INSIGHT_VIEW_UNSPECIFIED",
                        "BASIC",
                        "FULL"
                      ],
                      "type": "string",
                      "enumDescriptions": [
                        "The default / unset value. The API will default to the BASIC view.",
                        "Include basic metadata about the insight, but not the insight data. This is the default value (for both ListInsights and GetInsight).",
                        "Include everything."
                      ],
                      "description": "Required. List only metadata or full data.",
                      "location": "query"
                    },
                    "startTime": {
                      "type": "string",
                      "format": "google-datetime",
                      "location": "query",
                      "description": "Optional. Starting time for the duration for which insights are to be pulled. The default is 7 days before the current time."
                    },
                    "pageToken": {
                      "type": "string",
                      "description": "Optional. A token identifying a page of results the server should return.",
                      "location": "query"
                    },
                    "filter": {
                      "description": "Optional. Filter expression to restrict the insights returned. Supported filter fields: * `type` * `category` * `subCategory` Examples: * \"category = application AND type = count\" * \"category = application AND subCategory = iap\" * \"type = status\" Allowed values: * type: [count, latency, status, list] * category: [application, device, request, security] * subCategory: [iap, caa, webprotect] NOTE: Only equality based comparison is allowed. Only `AND` conjunction is allowed. NOTE: The 'AND' in the filter field needs to be in capital letters only. NOTE: Just filtering on `subCategory` is not allowed. It should be passed in with the parent `category` too. (These expressions are based on the filter language described at https://google.aip.dev/160).",
                      "type": "string",
                      "location": "query"
                    },
                    "pageSize": {
                      "format": "int32",
                      "description": "Optional. Requested page size. Server may return fewer items than requested. If unspecified, server will pick an appropriate default. NOTE: Default page size is 50.",
                      "location": "query",
                      "type": "integer"
                    },
                    "endTime": {
                      "location": "query",
                      "format": "google-datetime",
                      "description": "Optional. Ending time for the duration for which insights are to be pulled. The default is the current time.",
                      "type": "string"
                    },
                    "aggregation": {
                      "type": "string",
                      "enumDescriptions": [
                        "Unspecified.",
                        "Insight should be aggregated at hourly level.",
                        "Insight should be aggregated at daily level.",
                        "Insight should be aggregated at weekly level.",
                        "Insight should be aggregated at monthly level.",
                        "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
                      ],
                      "description": "Optional. Aggregation type. The default is 'DAILY'.",
                      "enum": [
                        "AGGREGATION_UNSPECIFIED",
                        "HOURLY",
                        "DAILY",
                        "WEEKLY",
                        "MONTHLY",
                        "CUSTOM_DATE_RANGE"
                      ],
                      "location": "query"
                    },
                    "orderBy": {
                      "location": "query",
                      "type": "string",
                      "description": "Optional. Hint for how to order the results. This is currently ignored."
                    }
                  },
                  "httpMethod": "GET",
                  "path": "v1alpha/{+parent}/insights",
                  "parameterOrder": [
                    "parent"
                  ],
                  "response": {
                    "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaListInsightsResponse"
                  },
                  "id": "beyondcorp.organizations.locations.insights.list",
                  "scopes": [
                    "https://www.googleapis.com/auth/cloud-platform"
                  ],
                  "description": "Lists for all the available insights that could be fetched from the system. Allows to filter using category. Setting the `view` to `BASIC` will let you iterate over the list of insight metadatas."
                }
              }
            }
          }
        }
      }
    }
  },
  "id": "beyondcorp:v1alpha",
  "description": "Chrome Enterprise Premium is a secure enterprise browsing solution that provides secure access to applications and resources, and offers integrated threat and data protection. It adds an extra layer of security to safeguard your Chrome browser environment, including Data Loss Prevention (DLP), real-time URL and file scanning, and Context-Aware Access for SaaS and web apps.",
  "mtlsRootUrl": "https://beyondcorp.mtls.googleapis.com/",
  "canonicalName": "BeyondCorp",
  "kind": "discovery#restDescription",
  "basePath": "",
  "protocol": "rest",
  "fullyEncodeReservedExpansion": true,
  "batchPath": "batch",
  "schemas": {
    "GoogleCloudBeyondcorpPartnerservicesV1mainPartnerServiceOperationMetadata": {
      "type": "object",
      "description": "Represents the metadata of the long-running operation.",
      "deprecated": true,
      "properties": {
        "createTime": {
          "format": "google-datetime",
          "type": "string",
          "readOnly": true,
          "description": "Output only. The time the operation was created."
        },
        "apiVersion": {
          "description": "Output only. API version used to start the operation.",
          "readOnly": true,
          "type": "string"
        },
        "verb": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation."
        },
        "statusMessage": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Human-readable status of the operation, if any."
        },
        "endTime": {
          "format": "google-datetime",
          "readOnly": true,
          "type": "string",
          "description": "Output only. The time the operation finished running."
        },
        "requestedCancellation": {
          "readOnly": true,
          "type": "boolean",
          "description": "Output only. Identifies whether the caller has requested cancellation of the operation. Operations that have successfully been cancelled have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`."
        },
        "target": {
          "readOnly": true,
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string"
        }
      },
      "id": "GoogleCloudBeyondcorpPartnerservicesV1mainPartnerServiceOperationMetadata"
    },
    "CloudPubSubNotificationConfig": {
      "type": "object",
      "id": "CloudPubSubNotificationConfig",
      "properties": {
        "pubsubSubscription": {
          "type": "string",
          "description": "The Pub/Sub subscription the connector uses to receive notifications."
        }
      },
      "description": "The configuration for Pub/Sub messaging for the connector."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamExternal": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamExternal",
      "type": "object",
      "description": "Endpoints to forward traffic to.",
      "properties": {
        "endpoints": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpoint"
          },
          "type": "array",
          "description": "Required. List of the endpoints to forward traffic to."
        }
      }
    },
    "ListAppGatewaysResponse": {
      "properties": {
        "unreachable": {
          "items": {
            "type": "string"
          },
          "description": "A list of locations that could not be reached.",
          "type": "array"
        },
        "appGateways": {
          "items": {
            "$ref": "AppGateway"
          },
          "type": "array",
          "description": "A list of BeyondCorp AppGateways in the project."
        },
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        }
      },
      "description": "Response message for BeyondCorp.ListAppGateways.",
      "type": "object",
      "id": "ListAppGatewaysResponse"
    },
    "ServiceAccount": {
      "type": "object",
      "description": "ServiceAccount represents a GCP service account.",
      "properties": {
        "email": {
          "description": "Email address of the service account.",
          "type": "string"
        }
      },
      "id": "ServiceAccount"
    },
    "CloudSecurityZerotrustApplinkAppConnectorProtoGateway": {
      "properties": {
        "port": {
          "format": "uint32",
          "type": "integer",
          "description": "port specifies the port of the gateway for tunnel connections from the connectors."
        },
        "project": {
          "description": "project is the tenant project the gateway belongs to. Different from the project in the connection, it is a BeyondCorpAPI internally created project to manage all the gateways. It is sharing the same network with the consumer project user owned. It is derived from the gateway URL. For example, project=${project} assuming a gateway URL. https://www.googleapis.com/compute/${version}/projects/${project}/zones/${zone}/instances/${instance}",
          "type": "string"
        },
        "name": {
          "type": "string",
          "description": "name is the name of an instance running a gateway. It is the unique ID for a gateway. All gateways under the same connection have the same prefix. It is derived from the gateway URL. For example, name=${instance} assuming a gateway URL. https://www.googleapis.com/compute/${version}/projects/${project}/zones/${zone}/instances/${instance}"
        },
        "selfLink": {
          "type": "string",
          "description": "self_link is the gateway URL in the form https://www.googleapis.com/compute/${version}/projects/${project}/zones/${zone}/instances/${instance}"
        },
        "zone": {
          "description": "zone represents the zone the instance belongs. It is derived from the gateway URL. For example, zone=${zone} assuming a gateway URL. https://www.googleapis.com/compute/${version}/projects/${project}/zones/${zone}/instances/${instance}",
          "type": "string"
        },
        "interface": {
          "description": "interface specifies the network interface of the gateway to connect to.",
          "type": "string"
        }
      },
      "id": "CloudSecurityZerotrustApplinkAppConnectorProtoGateway",
      "description": "Gateway represents a GCE VM Instance endpoint for use by IAP TCP.",
      "type": "object"
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRowFieldVal": {
      "properties": {
        "value": {
          "description": "Output only. Value of the field in string format. Acceptable values are strings or numbers.",
          "readOnly": true,
          "type": "string"
        },
        "id": {
          "type": "string",
          "description": "Output only. Field id.",
          "readOnly": true
        },
        "filterAlias": {
          "description": "Output only. Field name to be used in filter while requesting configured insight filtered on this field.",
          "readOnly": true,
          "type": "string"
        },
        "displayName": {
          "type": "string",
          "description": "Output only. Name of the field.",
          "readOnly": true
        }
      },
      "type": "object",
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRowFieldVal",
      "description": "Column or key value pair from the request as part of key to use in query or a single pair of the fetch response."
    },
    "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaCancelSubscriptionResponse": {
      "description": "Response message for BeyondCorp.CancelSubscription",
      "type": "object",
      "properties": {
        "effectiveCancellationTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Time when the cancellation will become effective"
        }
      },
      "id": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaCancelSubscriptionResponse"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaImageConfig": {
      "type": "object",
      "description": "ImageConfig defines the control plane images to run.",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaImageConfig",
      "properties": {
        "stableImage": {
          "type": "string",
          "description": "The stable image that the remote agent will fallback to if the target image fails. Format would be a gcr image path, e.g.: gcr.io/PROJECT-ID/my-image:tag1"
        },
        "targetImage": {
          "type": "string",
          "description": "The initial image the remote agent will attempt to run for the control plane. Format would be a gcr image path, e.g.: gcr.io/PROJECT-ID/my-image:tag1"
        }
      }
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedGroupInfo": {
      "type": "object",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedGroupInfo",
      "description": "The delegated group configuration details.",
      "properties": {
        "outputType": {
          "description": "Optional. The output type of the delegated group information.",
          "enum": [
            "OUTPUT_TYPE_UNSPECIFIED",
            "PROTOBUF",
            "JSON",
            "NONE"
          ],
          "type": "string",
          "enumDescriptions": [
            "The unspecified output type.",
            "Protobuf output type.",
            "JSON output type.",
            "Explicitly disable header output."
          ]
        }
      }
    },
    "CloudSecurityZerotrustApplinkLogagentProtoLogAgentDetails": {
      "id": "CloudSecurityZerotrustApplinkLogagentProtoLogAgentDetails",
      "type": "object",
      "properties": {},
      "description": "LogAgentDetails reflects the details of a log agent."
    },
    "ReportStatusRequest": {
      "id": "ReportStatusRequest",
      "properties": {
        "resourceInfo": {
          "description": "Required. Resource info of the connector.",
          "$ref": "ResourceInfo"
        },
        "requestId": {
          "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).",
          "type": "string"
        },
        "validateOnly": {
          "type": "boolean",
          "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way."
        }
      },
      "description": "Request report the connector status.",
      "type": "object"
    },
    "Connection": {
      "type": "object",
      "id": "Connection",
      "description": "A BeyondCorp Connection resource represents a BeyondCorp protected connection to a remote application. It creates all the necessary GCP components needed for creating a BeyondCorp protected connection. Multiple connectors can be authorised for a single Connection.",
      "properties": {
        "updateTime": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Timestamp when the resource was last modified.",
          "format": "google-datetime"
        },
        "type": {
          "description": "Required. The type of network connectivity used by the connection.",
          "enum": [
            "TYPE_UNSPECIFIED",
            "TCP_PROXY"
          ],
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "TCP Proxy based BeyondCorp Connection. API will default to this if unset."
          ]
        },
        "name": {
          "description": "Required. Unique resource name of the connection. The name is ignored when creating a connection.",
          "type": "string"
        },
        "applicationEndpoint": {
          "$ref": "ApplicationEndpoint",
          "description": "Required. Address of the remote application endpoint for the BeyondCorp Connection."
        },
        "gateway": {
          "description": "Optional. Gateway used by the connection.",
          "$ref": "Gateway"
        },
        "displayName": {
          "description": "Optional. An arbitrary user-provided name for the connection. Cannot exceed 64 characters.",
          "type": "string"
        },
        "createTime": {
          "format": "google-datetime",
          "description": "Output only. Timestamp when the resource was created.",
          "type": "string",
          "readOnly": true
        },
        "connectors": {
          "items": {
            "type": "string"
          },
          "description": "Optional. List of [google.cloud.beyondcorp.v1main.Connector.name] that are authorised to be associated with this Connection.",
          "type": "array"
        },
        "state": {
          "type": "string",
          "description": "Output only. The current state of the connection.",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Connection is being created.",
            "Connection has been created.",
            "Connection's configuration is being updated.",
            "Connection is being deleted.",
            "Connection is down and may be restored in the future. This happens when CCFE sends ProjectState = OFF."
          ],
          "readOnly": true,
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "CREATED",
            "UPDATING",
            "DELETING",
            "DOWN"
          ]
        },
        "uid": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. A unique identifier for the instance generated by the system."
        },
        "labels": {
          "description": "Optional. Resource labels to represent user provided metadata.",
          "additionalProperties": {
            "type": "string"
          },
          "type": "object"
        }
      }
    },
    "AppGatewayOperationMetadata": {
      "properties": {
        "endTime": {
          "type": "string",
          "description": "Output only. The time the operation finished running.",
          "format": "google-datetime",
          "readOnly": true
        },
        "createTime": {
          "format": "google-datetime",
          "readOnly": true,
          "type": "string",
          "description": "Output only. The time the operation was created."
        },
        "apiVersion": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. API version used to start the operation."
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "verb": {
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true,
          "type": "string"
        },
        "statusMessage": {
          "description": "Output only. Human-readable status of the operation, if any.",
          "type": "string",
          "readOnly": true
        },
        "requestedCancellation": {
          "type": "boolean",
          "readOnly": true,
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`."
        }
      },
      "type": "object",
      "id": "AppGatewayOperationMetadata",
      "description": "Represents the metadata of the long-running operation."
    },
    "ListConnectionsResponse": {
      "id": "ListConnectionsResponse",
      "description": "Response message for BeyondCorp.ListConnections.",
      "properties": {
        "nextPageToken": {
          "type": "string",
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list."
        },
        "connections": {
          "description": "A list of BeyondCorp Connections in the project.",
          "items": {
            "$ref": "Connection"
          },
          "type": "array"
        },
        "unreachable": {
          "type": "array",
          "description": "A list of locations that could not be reached.",
          "items": {
            "type": "string"
          }
        }
      },
      "type": "object"
    },
    "ImageConfig": {
      "id": "ImageConfig",
      "type": "object",
      "description": "ImageConfig defines the control plane images to run.",
      "properties": {
        "targetImage": {
          "description": "The initial image the remote agent will attempt to run for the control plane.",
          "type": "string"
        },
        "stableImage": {
          "description": "The stable image that the remote agent will fallback to if the target image fails.",
          "type": "string"
        }
      }
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpointMatcher": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpointMatcher",
      "type": "object",
      "properties": {
        "hostname": {
          "type": "string",
          "description": "Required. Hostname of the application."
        },
        "ports": {
          "items": {
            "format": "int32",
            "type": "integer"
          },
          "type": "array",
          "description": "Required. The ports of the application."
        }
      },
      "description": "EndpointMatcher contains the information of the endpoint that will match the application."
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionApplicationEndpoint": {
      "properties": {
        "host": {
          "description": "Required. Hostname or IP address of the remote application endpoint.",
          "type": "string"
        },
        "port": {
          "description": "Required. Port of the remote application endpoint.",
          "format": "int32",
          "type": "integer"
        }
      },
      "type": "object",
      "description": "ApplicationEndpoint represents a remote application endpoint.",
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionApplicationEndpoint"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedUserInfo": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedUserInfo",
      "properties": {
        "outputType": {
          "enum": [
            "OUTPUT_TYPE_UNSPECIFIED",
            "PROTOBUF",
            "JSON",
            "NONE"
          ],
          "type": "string",
          "description": "Optional. The delegated user's information.",
          "enumDescriptions": [
            "The unspecified output type.",
            "Protobuf output type.",
            "JSON output type.",
            "Explicitly disable header output."
          ]
        }
      },
      "type": "object",
      "description": "The configuration information for the delegated user."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEgressPolicy": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEgressPolicy",
      "type": "object",
      "properties": {
        "regions": {
          "items": {
            "type": "string"
          },
          "type": "array",
          "description": "Required. List of the regions where the application sends traffic."
        }
      },
      "description": "Routing policy information."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamNetwork": {
      "type": "object",
      "properties": {
        "name": {
          "type": "string",
          "description": "Required. Network name is of the format: `projects/{project}/global/networks/{network}"
        }
      },
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamNetwork",
      "description": "Network to forward traffic to."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGateway": {
      "description": "If Service Discovery is done through API, defines its settings.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGateway",
      "type": "object",
      "properties": {
        "resourceOverride": {
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGatewayOperationDescriptor",
          "description": "Optional. Enables fetching resource model updates to alter service behavior per Chrome profile."
        }
      }
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRow": {
      "description": "Row of the fetch response consisting of a set of entries.",
      "type": "object",
      "properties": {
        "fieldValues": {
          "readOnly": true,
          "type": "array",
          "description": "Output only. Columns/entries/key-vals in the result.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRowFieldVal"
          }
        }
      },
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRow"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListSecurityGatewaysResponse": {
      "properties": {
        "unreachable": {
          "items": {
            "type": "string"
          },
          "description": "A list of locations that could not be reached.",
          "type": "array"
        },
        "securityGateways": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway"
          },
          "type": "array",
          "description": "A list of BeyondCorp SecurityGateway in the project."
        },
        "nextPageToken": {
          "type": "string",
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list."
        }
      },
      "type": "object",
      "description": "Message for response to listing SecurityGateways.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListSecurityGatewaysResponse"
    },
    "GoogleIamV1Policy": {
      "id": "GoogleIamV1Policy",
      "type": "object",
      "description": "An Identity and Access Management (IAM) policy, which specifies access controls for Google Cloud resources. A `Policy` is a collection of `bindings`. A `binding` binds one or more `members`, or principals, to a single `role`. Principals can be user accounts, service accounts, Google groups, and domains (such as G Suite). A `role` is a named list of permissions; each `role` can be an IAM predefined role or a user-created custom role. For some types of Google Cloud resources, a `binding` can also specify a `condition`, which is a logical expression that allows access to a resource only if the expression evaluates to `true`. A condition can add constraints based on attributes of the request, the resource, or both. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). **JSON example:** ``` { \"bindings\": [ { \"role\": \"roles/resourcemanager.organizationAdmin\", \"members\": [ \"user:mike@example.com\", \"group:admins@example.com\", \"domain:google.com\", \"serviceAccount:my-project-id@appspot.gserviceaccount.com\" ] }, { \"role\": \"roles/resourcemanager.organizationViewer\", \"members\": [ \"user:eve@example.com\" ], \"condition\": { \"title\": \"expirable access\", \"description\": \"Does not grant access after Sep 2020\", \"expression\": \"request.time \u003c timestamp('2020-10-01T00:00:00.000Z')\", } } ], \"etag\": \"BwWWja0YfJA=\", \"version\": 3 } ``` **YAML example:** ``` bindings: - members: - user:mike@example.com - group:admins@example.com - domain:google.com - serviceAccount:my-project-id@appspot.gserviceaccount.com role: roles/resourcemanager.organizationAdmin - members: - user:eve@example.com role: roles/resourcemanager.organizationViewer condition: title: expirable access description: Does not grant access after Sep 2020 expression: request.time \u003c timestamp('2020-10-01T00:00:00.000Z') etag: BwWWja0YfJA= version: 3 ``` For a description of IAM and its features, see the [IAM documentation](https://cloud.google.com/iam/docs/).",
      "properties": {
        "version": {
          "type": "integer",
          "description": "Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
          "format": "int32"
        },
        "bindings": {
          "type": "array",
          "items": {
            "$ref": "GoogleIamV1Binding"
          },
          "description": "Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`."
        },
        "auditConfigs": {
          "type": "array",
          "description": "Specifies cloud audit logging configuration for this policy.",
          "items": {
            "$ref": "GoogleIamV1AuditConfig"
          }
        },
        "etag": {
          "type": "string",
          "description": "`etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost.",
          "format": "byte"
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaListAppConnectorsResponse": {
      "description": "Response message for BeyondCorp.ListAppConnectors.",
      "properties": {
        "unreachable": {
          "description": "A list of locations that could not be reached.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        },
        "appConnectors": {
          "type": "array",
          "description": "A list of BeyondCorp AppConnectors in the project.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector"
          }
        }
      },
      "type": "object",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaListAppConnectorsResponse"
    },
    "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription": {
      "description": "A BeyondCorp Subscription resource represents BeyondCorp Enterprise Subscription. BeyondCorp Enterprise Subscription enables BeyondCorp Enterprise permium features for an organization.",
      "type": "object",
      "properties": {
        "csgCustomer": {
          "description": "Optional. Whether the subscription is being created as part of the Citrix flow. If this field is set to true, the subscription should have both the start_time and end_time set in the request and the billing account used will be the Citrix master billing account regardless of what its set to in the request. This field can only be set to true in create requests.",
          "type": "boolean"
        },
        "billingAccount": {
          "description": "Optional. Name of the billing account in the format. e.g. billingAccounts/123456-123456-123456 Required if Subscription is of Paid type.",
          "type": "string"
        },
        "sku": {
          "enum": [
            "SKU_UNSPECIFIED",
            "BCE_STANDARD_SKU"
          ],
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Represents BeyondCorp Standard SKU."
          ],
          "description": "Required. SKU of subscription."
        },
        "startTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Optional. Start time of the subscription."
        },
        "autoRenewEnabled": {
          "type": "boolean",
          "description": "Output only. Represents that, if subscription will renew or end when the term ends.",
          "readOnly": true
        },
        "state": {
          "description": "Output only. The current state of the subscription.",
          "enum": [
            "STATE_UNSPECIFIED",
            "ACTIVE",
            "INACTIVE",
            "COMPLETED"
          ],
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Represents an active subscription.",
            "Represents an upcomming subscription.",
            "Represents a completed subscription."
          ],
          "readOnly": true,
          "type": "string"
        },
        "endTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Optional. End time of the subscription."
        },
        "name": {
          "description": "Identifier. Unique resource name of the Subscription. The name is ignored when creating a subscription.",
          "type": "string"
        },
        "seatCount": {
          "type": "string",
          "format": "int64",
          "description": "Optional. Number of seats in the subscription."
        },
        "createTime": {
          "format": "google-datetime",
          "description": "Output only. Create time of the subscription.",
          "type": "string",
          "readOnly": true
        },
        "signupSource": {
          "description": "Optional. Input only. The source from which the subscription was initiated, for example \"admin-console-browser-overview\" or \"admin-console-security-insights\".",
          "type": "string"
        },
        "type": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Represents a trial subscription.",
            "Represents a paid subscription.",
            "Reresents an allowlisted subscription."
          ],
          "type": "string",
          "enum": [
            "TYPE_UNSPECIFIED",
            "TRIAL",
            "PAID",
            "ALLOWLIST"
          ],
          "description": "Required. Type of subscription."
        },
        "subscriberType": {
          "enum": [
            "SUBSCRIBER_TYPE_UNSPECIFIED",
            "ONLINE",
            "OFFLINE",
            "CEP_TRIAL"
          ],
          "readOnly": true,
          "description": "Output only. Type of subscriber.",
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Represents an online subscription.",
            "Represents an offline subscription.",
            "Represents a trial subscription. This maps to the 'TRIAL' subscriber_type in the Entitler proto (google3/identity/cloud/contextawareaccess/billing/proto/enums.proto), but is named 'CEP_TRIAL' here to avoid a name collision with the 'Type' enum defined above."
          ]
        }
      },
      "id": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeaders": {
      "description": "Contextual headers configuration.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeaders",
      "properties": {
        "deviceInfo": {
          "description": "Optional. The device information configuration.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDeviceInfo"
        },
        "dispatchInfo": {
          "description": "Optional. The dispatch information configuration.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDispatchInfo"
        },
        "outputType": {
          "enumDescriptions": [
            "The unspecified output type.",
            "Protobuf output type.",
            "JSON output type.",
            "Explicitly disable header output."
          ],
          "description": "Optional. Default output type for all enabled headers.",
          "type": "string",
          "enum": [
            "OUTPUT_TYPE_UNSPECIFIED",
            "PROTOBUF",
            "JSON",
            "NONE"
          ]
        },
        "groupInfo": {
          "description": "Optional. Group details.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedGroupInfo"
        },
        "userInfo": {
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedUserInfo",
          "description": "Optional. User details."
        }
      },
      "type": "object"
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection": {
      "properties": {
        "type": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "TCP Proxy based BeyondCorp AppConnection. API will default to this if unset."
          ],
          "description": "Required. The type of network connectivity used by the AppConnection.",
          "type": "string",
          "enum": [
            "TYPE_UNSPECIFIED",
            "TCP_PROXY"
          ]
        },
        "applicationEndpoint": {
          "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionApplicationEndpoint",
          "description": "Required. Address of the remote application endpoint for the BeyondCorp AppConnection."
        },
        "displayName": {
          "type": "string",
          "description": "Optional. An arbitrary user-provided name for the AppConnection. Cannot exceed 64 characters."
        },
        "state": {
          "type": "string",
          "readOnly": true,
          "enumDescriptions": [
            "Default value. This value is unused.",
            "AppConnection is being created.",
            "AppConnection has been created.",
            "AppConnection's configuration is being updated.",
            "AppConnection is being deleted.",
            "AppConnection is down and may be restored in the future. This happens when CCFE sends ProjectState = OFF."
          ],
          "description": "Output only. The current state of the AppConnection.",
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "CREATED",
            "UPDATING",
            "DELETING",
            "DOWN"
          ]
        },
        "createTime": {
          "description": "Output only. Timestamp when the resource was created.",
          "type": "string",
          "readOnly": true,
          "format": "google-datetime"
        },
        "uid": {
          "readOnly": true,
          "description": "Output only. A unique identifier for the instance generated by the system.",
          "type": "string"
        },
        "gateway": {
          "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionGateway",
          "description": "Optional. Gateway used by the AppConnection."
        },
        "satisfiesPzs": {
          "type": "boolean",
          "description": "Output only. Reserved for future use.",
          "readOnly": true
        },
        "updateTime": {
          "readOnly": true,
          "format": "google-datetime",
          "type": "string",
          "description": "Output only. Timestamp when the resource was last modified."
        },
        "name": {
          "description": "Required. Unique resource name of the AppConnection. The name is ignored when creating a AppConnection.",
          "type": "string"
        },
        "connectors": {
          "items": {
            "type": "string"
          },
          "description": "Optional. List of [google.cloud.beyondcorp.v1main.Connector.name] that are authorized to be associated with this AppConnection.",
          "type": "array"
        },
        "satisfiesPzi": {
          "readOnly": true,
          "description": "Output only. Reserved for future use.",
          "type": "boolean"
        },
        "labels": {
          "additionalProperties": {
            "type": "string"
          },
          "type": "object",
          "description": "Optional. Resource labels to represent user provided metadata."
        }
      },
      "description": "A BeyondCorp AppConnection resource represents a BeyondCorp protected AppConnection to a remote application. It creates all the necessary GCP components needed for creating a BeyondCorp protected AppConnection. Multiple connectors can be authorized for a single AppConnection.",
      "type": "object",
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway": {
      "type": "object",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGateway",
      "properties": {
        "logging": {
          "description": "Optional. Configuration for Cloud Logging. If this field is present, the logging will be enabled.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaLoggingConfig"
        },
        "delegatingServiceAccount": {
          "description": "Output only. Service account used for operations that involve resources in consumer projects.",
          "readOnly": true,
          "type": "string"
        },
        "updateTime": {
          "readOnly": true,
          "description": "Output only. Timestamp when the resource was last modified.",
          "type": "string",
          "format": "google-datetime"
        },
        "hubs": {
          "additionalProperties": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaHub"
          },
          "description": "Optional. Map of Hubs that represents regional data path deployment with GCP region as a key.",
          "type": "object"
        },
        "serviceDiscovery": {
          "description": "Optional. Settings related to the Service Discovery.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscovery"
        },
        "name": {
          "type": "string",
          "description": "Identifier. Name of the resource."
        },
        "externalIps": {
          "type": "array",
          "readOnly": true,
          "items": {
            "type": "string"
          },
          "description": "Output only. IP addresses that will be used for establishing connection to the endpoints."
        },
        "createTime": {
          "readOnly": true,
          "format": "google-datetime",
          "description": "Output only. Timestamp when the resource was created.",
          "type": "string"
        },
        "displayName": {
          "description": "Optional. An arbitrary user-provided name for the SecurityGateway. Cannot exceed 64 characters.",
          "type": "string"
        },
        "proxyProtocolConfig": {
          "description": "Optional. Shared proxy configuration for all apps.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaProxyProtocolConfig"
        },
        "state": {
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "UPDATING",
            "DELETING",
            "RUNNING",
            "DOWN",
            "ERROR"
          ],
          "readOnly": true,
          "description": "Output only. The operational state of the SecurityGateway.",
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "SecurityGateway is being created.",
            "SecurityGateway is being updated.",
            "SecurityGateway is being deleted.",
            "SecurityGateway is running.",
            "SecurityGateway is down and may be restored in the future.",
            "SecurityGateway encountered an error and is in an indeterministic state."
          ]
        }
      },
      "description": "The information about a security gateway resource."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaContainerHealthDetails": {
      "properties": {
        "currentConfigVersion": {
          "type": "string",
          "description": "The version of the current config."
        },
        "errorMsg": {
          "type": "string",
          "description": "The latest error message."
        },
        "extendedStatus": {
          "type": "object",
          "additionalProperties": {
            "type": "string"
          },
          "description": "The extended status. Such as ExitCode, StartedAt, FinishedAt, etc."
        },
        "expectedConfigVersion": {
          "type": "string",
          "description": "The version of the expected config."
        }
      },
      "type": "object",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaContainerHealthDetails",
      "description": "ContainerHealthDetails reflects the health details of a container."
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadata": {
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadata",
      "properties": {
        "aggregations": {
          "description": "Output only. List of aggregation types available for insight.",
          "readOnly": true,
          "items": {
            "enumDescriptions": [
              "Unspecified.",
              "Insight should be aggregated at hourly level.",
              "Insight should be aggregated at daily level.",
              "Insight should be aggregated at weekly level.",
              "Insight should be aggregated at monthly level.",
              "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
            ],
            "enum": [
              "AGGREGATION_UNSPECIFIED",
              "HOURLY",
              "DAILY",
              "WEEKLY",
              "MONTHLY",
              "CUSTOM_DATE_RANGE"
            ],
            "type": "string"
          },
          "type": "array"
        },
        "category": {
          "type": "string",
          "description": "Output only. Category of the insight.",
          "readOnly": true
        },
        "fields": {
          "type": "array",
          "readOnly": true,
          "description": "Output only. List of fields available for insight.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadataField"
          }
        },
        "groups": {
          "readOnly": true,
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Output only. List of groupings available for insight."
        },
        "type": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Type of the insight. It is metadata describing whether the insight is a metric (e.g. count) or a report (e.g. list, status)."
        },
        "displayName": {
          "type": "string",
          "description": "Output only. Common name of the insight.",
          "readOnly": true
        },
        "subCategory": {
          "description": "Output only. Sub-Category of the insight.",
          "readOnly": true,
          "type": "string"
        }
      },
      "type": "object",
      "description": "Insight filters, groupings and aggregations that can be applied for the insight. Examples: aggregations, groups, field filters."
    },
    "GoogleLongrunningListOperationsResponse": {
      "description": "The response message for Operations.ListOperations.",
      "id": "GoogleLongrunningListOperationsResponse",
      "type": "object",
      "properties": {
        "operations": {
          "description": "A list of operations that matches the specified filter in the request.",
          "items": {
            "$ref": "GoogleLongrunningOperation"
          },
          "type": "array"
        },
        "unreachable": {
          "items": {
            "type": "string"
          },
          "type": "array",
          "description": "Unordered list. Unreachable resources. Populated when the request sets `ListOperationsRequest.return_partial_success` and reads across collections. For example, when attempting to list all resources across all supported locations."
        },
        "nextPageToken": {
          "description": "The standard List next-page token.",
          "type": "string"
        }
      }
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadataField": {
      "properties": {
        "filterAlias": {
          "description": "Output only. Field name to be used in filter while requesting configured insight filtered on this field.",
          "readOnly": true,
          "type": "string"
        },
        "description": {
          "type": "string",
          "description": "Output only. Description of the field.",
          "readOnly": true
        },
        "groupable": {
          "type": "boolean",
          "readOnly": true,
          "description": "Output only. Indicates whether the field can be used for grouping in custom grouping request."
        },
        "id": {
          "description": "Output only. Field id for which this is the metadata.",
          "type": "string",
          "readOnly": true
        },
        "filterable": {
          "readOnly": true,
          "type": "boolean",
          "description": "Output only. Indicates whether the field can be used for filtering."
        },
        "displayName": {
          "description": "Output only. Name of the field.",
          "readOnly": true,
          "type": "string"
        }
      },
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadataField",
      "description": "Field metadata. Commonly understandable name and description for the field. Multiple such fields constitute the Insight.",
      "type": "object"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDispatchInfo": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDispatchInfo",
      "properties": {
        "outputType": {
          "enumDescriptions": [
            "The unspecified output type.",
            "Protobuf output type.",
            "JSON output type.",
            "Explicitly disable header output."
          ],
          "enum": [
            "OUTPUT_TYPE_UNSPECIFIED",
            "PROTOBUF",
            "JSON",
            "NONE"
          ],
          "description": "Optional. The output type details for the delegated dispatch information.",
          "type": "string"
        }
      },
      "type": "object",
      "description": "The delegated dispatch information configuration."
    },
    "GoogleIamV1TestIamPermissionsResponse": {
      "properties": {
        "permissions": {
          "description": "A subset of `TestPermissionsRequest.permissions` that the caller is allowed.",
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "id": "GoogleIamV1TestIamPermissionsResponse",
      "type": "object",
      "description": "Response message for `TestIamPermissions` method."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfo": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfo",
      "description": "PrincipalInfo represents an Identity oneof.",
      "type": "object",
      "properties": {
        "serviceAccount": {
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfoServiceAccount",
          "description": "A GCP service account."
        }
      }
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaAppliedConfig": {
      "properties": {
        "customGrouping": {
          "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaCustomGrouping",
          "readOnly": true,
          "description": "Output only. Customised grouping applied."
        },
        "fieldFilter": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Filters applied."
        },
        "group": {
          "description": "Output only. Group id of the grouping applied.",
          "readOnly": true,
          "type": "string"
        },
        "startTime": {
          "readOnly": true,
          "description": "Output only. Starting time for the duration for which insight was pulled.",
          "type": "string",
          "format": "google-datetime"
        },
        "endTime": {
          "format": "google-datetime",
          "readOnly": true,
          "description": "Output only. Ending time for the duration for which insight was pulled.",
          "type": "string"
        },
        "aggregation": {
          "enum": [
            "AGGREGATION_UNSPECIFIED",
            "HOURLY",
            "DAILY",
            "WEEKLY",
            "MONTHLY",
            "CUSTOM_DATE_RANGE"
          ],
          "enumDescriptions": [
            "Unspecified.",
            "Insight should be aggregated at hourly level.",
            "Insight should be aggregated at daily level.",
            "Insight should be aggregated at weekly level.",
            "Insight should be aggregated at monthly level.",
            "Insight should be aggregated at the custom date range passed in as the start and end time in the request."
          ],
          "readOnly": true,
          "description": "Output only. Aggregation type applied.",
          "type": "string"
        }
      },
      "type": "object",
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaAppliedConfig",
      "description": "The configuration that was applied to generate the result."
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaListInsightsResponse": {
      "properties": {
        "insights": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsight"
          },
          "type": "array",
          "description": "Output only. List of all insights.",
          "readOnly": true
        },
        "nextPageToken": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Next page token to be fetched. Set to empty or NULL if there are no more pages available."
        }
      },
      "description": "The response for the list of insights.",
      "type": "object",
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaListInsightsResponse"
    },
    "Gateway": {
      "properties": {
        "uri": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Server-defined URI for this resource."
        },
        "userPort": {
          "readOnly": true,
          "format": "int32",
          "description": "Output only. User port reserved on the gateways for this connection, if not specified or zero, the default port is 19443.",
          "type": "integer"
        },
        "type": {
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Gateway hosted in a GCP regional managed instance group."
          ],
          "description": "Required. The type of hosting used by the gateway.",
          "enum": [
            "TYPE_UNSPECIFIED",
            "GCP_REGIONAL_MIG"
          ]
        }
      },
      "description": "Gateway represents a user facing component that serves as an entrance to enable connectivity.",
      "type": "object",
      "id": "Gateway"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorInstanceConfig": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorInstanceConfig",
      "type": "object",
      "properties": {
        "notificationConfig": {
          "description": "NotificationConfig defines the notification mechanism that the remote instance should subscribe to in order to receive notification.",
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfig"
        },
        "imageConfig": {
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaImageConfig",
          "description": "ImageConfig defines the GCR images to run for the remote agent's control plane."
        },
        "sequenceNumber": {
          "description": "Required. A monotonically increasing number generated and maintained by the API provider. Every time a config changes in the backend, the sequenceNumber should be bumped up to reflect the change.",
          "format": "int64",
          "type": "string"
        },
        "instanceConfig": {
          "additionalProperties": {
            "description": "Properties of the object. Contains field @type with type URL.",
            "type": "any"
          },
          "description": "The SLM instance agent configuration.",
          "type": "object"
        }
      },
      "description": "AppConnectorInstanceConfig defines the instance config of a AppConnector."
    },
    "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaRestartSubscriptionResponse": {
      "id": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaRestartSubscriptionResponse",
      "type": "object",
      "description": "Response message for BeyondCorp.RestartSubscription",
      "properties": {}
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaLoggingConfig": {
      "properties": {},
      "type": "object",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaLoggingConfig",
      "description": "Configuration for Cloud Logging."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfoServiceAccount": {
      "type": "object",
      "properties": {
        "email": {
          "description": "Email address of the service account.",
          "type": "string"
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfoServiceAccount",
      "description": "ServiceAccount represents a GCP service account."
    },
    "Connector": {
      "properties": {
        "resourceInfo": {
          "description": "Optional. Resource info of the connector.",
          "$ref": "ResourceInfo"
        },
        "createTime": {
          "description": "Output only. Timestamp when the resource was created.",
          "type": "string",
          "format": "google-datetime",
          "readOnly": true
        },
        "state": {
          "description": "Output only. The current state of the connector.",
          "readOnly": true,
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Connector is being created.",
            "Connector has been created.",
            "Connector's configuration is being updated.",
            "Connector is being deleted.",
            "Connector is down and may be restored in the future. This happens when CCFE sends ProjectState = OFF."
          ],
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "CREATED",
            "UPDATING",
            "DELETING",
            "DOWN"
          ]
        },
        "displayName": {
          "type": "string",
          "description": "Optional. An arbitrary user-provided name for the connector. Cannot exceed 64 characters."
        },
        "updateTime": {
          "readOnly": true,
          "type": "string",
          "format": "google-datetime",
          "description": "Output only. Timestamp when the resource was last modified."
        },
        "name": {
          "type": "string",
          "description": "Required. Unique resource name of the connector. The name is ignored when creating a connector."
        },
        "labels": {
          "description": "Optional. Resource labels to represent user provided metadata.",
          "additionalProperties": {
            "type": "string"
          },
          "type": "object"
        },
        "uid": {
          "readOnly": true,
          "description": "Output only. A unique identifier for the instance generated by the system.",
          "type": "string"
        },
        "principalInfo": {
          "description": "Required. Principal information about the Identity of the connector.",
          "$ref": "PrincipalInfo"
        }
      },
      "type": "object",
      "id": "Connector",
      "description": "A BeyondCorp connector resource that represents an application facing component deployed proximal to and with direct access to the application instances. It is used to establish connectivity between the remote enterprise environment and GCP. It initiates connections to the applications and can proxy the data from users over the connection."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDeviceInfo": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeadersDelegatedDeviceInfo",
      "description": "The delegated device information configuration.",
      "properties": {
        "outputType": {
          "description": "Optional. The output type details for the delegated device.",
          "enum": [
            "OUTPUT_TYPE_UNSPECIFIED",
            "PROTOBUF",
            "JSON",
            "NONE"
          ],
          "type": "string",
          "enumDescriptions": [
            "The unspecified output type.",
            "Protobuf output type.",
            "JSON output type.",
            "Explicitly disable header output."
          ]
        }
      },
      "type": "object"
    },
    "PrincipalInfo": {
      "description": "PrincipalInfo represents an Identity oneof.",
      "type": "object",
      "id": "PrincipalInfo",
      "properties": {
        "serviceAccount": {
          "$ref": "ServiceAccount",
          "description": "A GCP service account."
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionGateway": {
      "description": "Gateway represents a user facing component that serves as an entrance to enable connectivity.",
      "type": "object",
      "properties": {
        "l7psc": {
          "readOnly": true,
          "description": "Output only. L7 private service connection for this resource.",
          "type": "string"
        },
        "appGateway": {
          "description": "Required. AppGateway name in following format: `projects/{project_id}/locations/{location_id}/appgateways/{gateway_id}`",
          "type": "string"
        },
        "uri": {
          "description": "Output only. Server-defined URI for this resource.",
          "readOnly": true,
          "type": "string"
        },
        "type": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Gateway hosted in a GCP regional managed instance group."
          ],
          "description": "Required. The type of hosting used by the gateway.",
          "type": "string",
          "enum": [
            "TYPE_UNSPECIFIED",
            "GCP_REGIONAL_MIG"
          ]
        },
        "ingressPort": {
          "format": "int32",
          "readOnly": true,
          "type": "integer",
          "description": "Output only. Ingress port reserved on the gateways for this AppConnection, if not specified or zero, the default port is 19443."
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionGateway"
    },
    "CloudSecurityZerotrustApplinkAppConnectorProtoConnectionConfig": {
      "id": "CloudSecurityZerotrustApplinkAppConnectorProtoConnectionConfig",
      "description": "ConnectionConfig represents a Connection Configuration object.",
      "properties": {
        "userPort": {
          "type": "integer",
          "format": "int32",
          "description": "user_port specifies the reserved port on gateways for user connections."
        },
        "tunnelsPerGateway": {
          "type": "integer",
          "format": "uint32",
          "description": "tunnels_per_gateway reflects the number of tunnels between a connector and a gateway."
        },
        "applicationEndpoint": {
          "description": "application_endpoint is the endpoint of the application the form of host:port. For example, \"localhost:80\".",
          "type": "string"
        },
        "project": {
          "description": "project represents the consumer project the connection belongs to.",
          "type": "string"
        },
        "name": {
          "type": "string",
          "description": "name is the unique ID for each connection. TODO(b/190732451) returns connection name from user-specified name in config. Now, name = ${application_name}:${application_endpoint}"
        },
        "applicationName": {
          "type": "string",
          "description": "application_name represents the given name of the application the connection is connecting with."
        },
        "gateway": {
          "description": "gateway lists all instances running a gateway in GCP. They all connect to a connector on the host.",
          "type": "array",
          "items": {
            "$ref": "CloudSecurityZerotrustApplinkAppConnectorProtoGateway"
          }
        }
      },
      "type": "object"
    },
    "GoogleCloudBeyondcorpAppgatewaysV1AppGatewayOperationMetadata": {
      "properties": {
        "endTime": {
          "readOnly": true,
          "description": "Output only. The time the operation finished running.",
          "format": "google-datetime",
          "type": "string"
        },
        "statusMessage": {
          "description": "Output only. Human-readable status of the operation, if any.",
          "readOnly": true,
          "type": "string"
        },
        "requestedCancellation": {
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`.",
          "type": "boolean",
          "readOnly": true
        },
        "verb": {
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true,
          "type": "string"
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "createTime": {
          "description": "Output only. The time the operation was created.",
          "readOnly": true,
          "type": "string",
          "format": "google-datetime"
        },
        "apiVersion": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. API version used to start the operation."
        }
      },
      "id": "GoogleCloudBeyondcorpAppgatewaysV1AppGatewayOperationMetadata",
      "type": "object",
      "description": "Represents the metadata of the long-running operation."
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponse": {
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponse",
      "properties": {
        "nextPageToken": {
          "type": "string",
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list."
        },
        "unreachable": {
          "description": "A list of locations that could not be reached.",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "appConnectionDetails": {
          "type": "array",
          "description": "A list of BeyondCorp AppConnections with details in the project.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponseAppConnectionDetails"
          }
        }
      },
      "description": "Response message for BeyondCorp.ResolveAppConnections.",
      "type": "object"
    },
    "GoogleCloudLocationLocation": {
      "id": "GoogleCloudLocationLocation",
      "properties": {
        "displayName": {
          "type": "string",
          "description": "The friendly name for this location, typically a nearby city name. For example, \"Tokyo\"."
        },
        "labels": {
          "description": "Cross-service attributes for the location. For example {\"cloud.googleapis.com/region\": \"us-east1\"}",
          "additionalProperties": {
            "type": "string"
          },
          "type": "object"
        },
        "metadata": {
          "type": "object",
          "description": "Service-specific metadata. For example the available capacity at the given location.",
          "additionalProperties": {
            "description": "Properties of the object. Contains field @type with type URL.",
            "type": "any"
          }
        },
        "name": {
          "description": "Resource name for the location, which may vary between implementations. For example: `\"projects/example-project/locations/us-east1\"`",
          "type": "string"
        },
        "locationId": {
          "description": "The canonical id for this location. For example: `\"us-east1\"`.",
          "type": "string"
        }
      },
      "type": "object",
      "description": "A resource that represents a Google Cloud location."
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaCustomGrouping": {
      "type": "object",
      "description": "Customised grouping option that allows setting the group_by fields and also the filters togather for a configured insight request.",
      "properties": {
        "fieldFilter": {
          "description": "Optional. Filterable parameters to be added to the grouping clause. Available fields could be fetched by calling insight list and get APIs in `BASIC` view. `=` is the only comparison operator supported. `AND` is the only logical operator supported. Usage: field_filter=\"fieldName1=fieldVal1 AND fieldName2=fieldVal2\". NOTE: Only `AND` conditions are allowed. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for the filtering the corresponding fields in this filter field. (These expressions are based on the filter language described at https://google.aip.dev/160).",
          "type": "string"
        },
        "groupFields": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "Required. Fields to be used for grouping. NOTE: Use the `filter_alias` from `Insight.Metadata.Field` message for declaring the fields to be grouped-by here."
        }
      },
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaCustomGrouping"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaInternetGateway": {
      "description": "Represents the Internet Gateway configuration.",
      "properties": {
        "assignedIps": {
          "description": "Output only. List of IP addresses assigned to the Cloud NAT.",
          "readOnly": true,
          "type": "array",
          "items": {
            "type": "string"
          }
        }
      },
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaInternetGateway",
      "type": "object"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1AppConnectorOperationMetadata": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1AppConnectorOperationMetadata",
      "type": "object",
      "properties": {
        "requestedCancellation": {
          "type": "boolean",
          "readOnly": true,
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`."
        },
        "createTime": {
          "readOnly": true,
          "type": "string",
          "format": "google-datetime",
          "description": "Output only. The time the operation was created."
        },
        "apiVersion": {
          "description": "Output only. API version used to start the operation.",
          "readOnly": true,
          "type": "string"
        },
        "endTime": {
          "type": "string",
          "format": "google-datetime",
          "description": "Output only. The time the operation finished running.",
          "readOnly": true
        },
        "verb": {
          "description": "Output only. Name of the verb executed by the operation.",
          "type": "string",
          "readOnly": true
        },
        "statusMessage": {
          "type": "string",
          "description": "Output only. Human-readable status of the operation, if any.",
          "readOnly": true
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "readOnly": true,
          "type": "string"
        }
      },
      "description": "Represents the metadata of the long-running operation."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1RemoteAgentDetails": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1RemoteAgentDetails",
      "type": "object",
      "description": "RemoteAgentDetails reflects the details of a remote agent.",
      "properties": {}
    },
    "Tunnelv1ProtoTunnelerError": {
      "id": "Tunnelv1ProtoTunnelerError",
      "description": "TunnelerError is an error proto for errors returned by the connection manager.",
      "properties": {
        "retryable": {
          "description": "retryable isn't used for now, but we may want to reuse it in the future.",
          "type": "boolean"
        },
        "err": {
          "description": "Original raw error",
          "type": "string"
        }
      },
      "type": "object"
    },
    "GoogleCloudBeyondcorpPartnerservicesV1alphaPartnerServiceOperationMetadata": {
      "deprecated": true,
      "properties": {
        "endTime": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. The time the operation finished running.",
          "format": "google-datetime"
        },
        "createTime": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. The time the operation was created.",
          "format": "google-datetime"
        },
        "apiVersion": {
          "description": "Output only. API version used to start the operation.",
          "readOnly": true,
          "type": "string"
        },
        "target": {
          "readOnly": true,
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string"
        },
        "requestedCancellation": {
          "readOnly": true,
          "description": "Output only. Identifies whether the caller has requested cancellation of the operation. Operations that have successfully been cancelled have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "type": "boolean"
        },
        "statusMessage": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Human-readable status of the operation, if any."
        },
        "verb": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation."
        }
      },
      "id": "GoogleCloudBeyondcorpPartnerservicesV1alphaPartnerServiceOperationMetadata",
      "type": "object",
      "description": "Represents the metadata of the long-running operation."
    },
    "ResourceInfo": {
      "properties": {
        "status": {
          "enumDescriptions": [
            "Health status is unknown: not initialized or failed to retrieve.",
            "The resource is healthy.",
            "The resource is unhealthy.",
            "The resource is unresponsive.",
            "Some sub-resources are UNHEALTHY."
          ],
          "description": "Overall health status. Overall status is derived based on the status of each sub level resources.",
          "enum": [
            "HEALTH_STATUS_UNSPECIFIED",
            "HEALTHY",
            "UNHEALTHY",
            "UNRESPONSIVE",
            "DEGRADED"
          ],
          "type": "string"
        },
        "sub": {
          "items": {
            "$ref": "ResourceInfo"
          },
          "type": "array",
          "description": "List of Info for the sub level resources."
        },
        "id": {
          "type": "string",
          "description": "Required. Unique Id for the resource."
        },
        "time": {
          "format": "google-datetime",
          "description": "The timestamp to collect the info. It is suggested to be set by the topmost level resource only.",
          "type": "string"
        },
        "resource": {
          "description": "Specific details for the resource.",
          "type": "object",
          "additionalProperties": {
            "type": "any",
            "description": "Properties of the object. Contains field @type with type URL."
          }
        }
      },
      "description": "ResourceInfo represents the information/status of the associated resource.",
      "type": "object",
      "id": "ResourceInfo"
    },
    "GoogleRpcStatus": {
      "type": "object",
      "properties": {
        "details": {
          "items": {
            "type": "object",
            "additionalProperties": {
              "type": "any",
              "description": "Properties of the object. Contains field @type with type URL."
            }
          },
          "description": "A list of messages that carry the error details. There is a common set of message types for APIs to use.",
          "type": "array"
        },
        "message": {
          "description": "A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.",
          "type": "string"
        },
        "code": {
          "format": "int32",
          "type": "integer",
          "description": "The status code, which should be an enum value of google.rpc.Code."
        }
      },
      "id": "GoogleRpcStatus",
      "description": "The `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors)."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaResolveInstanceConfigResponse": {
      "description": "Response message for BeyondCorp.ResolveInstanceConfig.",
      "type": "object",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaResolveInstanceConfigResponse",
      "properties": {
        "instanceConfig": {
          "description": "AppConnectorInstanceConfig.",
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorInstanceConfig"
        }
      }
    },
    "GoogleIamV1SetIamPolicyRequest": {
      "properties": {
        "policy": {
          "$ref": "GoogleIamV1Policy",
          "description": "REQUIRED: The complete policy to be applied to the `resource`. The size of the policy is limited to a few 10s of KB. An empty policy is a valid policy but certain Google Cloud services (such as Projects) might reject them."
        },
        "updateMask": {
          "description": "OPTIONAL: A FieldMask specifying which fields of the policy to modify. Only the fields in the mask will be modified. If no mask is provided, the following default mask is used: `paths: \"bindings, etag\"`",
          "format": "google-fieldmask",
          "type": "string"
        }
      },
      "type": "object",
      "id": "GoogleIamV1SetIamPolicyRequest",
      "description": "Request message for `SetIamPolicy` method."
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfig": {
      "type": "object",
      "description": "NotificationConfig defines the mechanisms to notify instance agent.",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfig",
      "properties": {
        "pubsubNotification": {
          "description": "Cloud Pub/Sub Configuration to receive notifications.",
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfigCloudPubSubNotificationConfig"
        }
      }
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpoint": {
      "type": "object",
      "properties": {
        "hostname": {
          "type": "string",
          "description": "Required. Hostname of the endpoint."
        },
        "port": {
          "format": "int32",
          "type": "integer",
          "description": "Required. Port of the endpoint."
        }
      },
      "description": "Internet Gateway endpoint to forward traffic to.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpoint"
    },
    "GoogleTypeExpr": {
      "type": "object",
      "description": "Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: \"Summary size limit\" description: \"Determines if a summary is less than 100 chars\" expression: \"document.summary.size() \u003c 100\" Example (Equality): title: \"Requestor is owner\" description: \"Determines if requestor is the document owner\" expression: \"document.owner == request.auth.claims.email\" Example (Logic): title: \"Public documents\" description: \"Determine whether the document should be publicly visible\" expression: \"document.type != 'private' && document.type != 'internal'\" Example (Data Manipulation): title: \"Notification string\" description: \"Create a notification string with a timestamp.\" expression: \"'New message received at ' + string(document.create_time)\" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.",
      "properties": {
        "description": {
          "description": "Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.",
          "type": "string"
        },
        "location": {
          "description": "Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file.",
          "type": "string"
        },
        "title": {
          "description": "Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.",
          "type": "string"
        },
        "expression": {
          "type": "string",
          "description": "Textual representation of an expression in Common Expression Language syntax."
        }
      },
      "id": "GoogleTypeExpr"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaResourceInfo": {
      "type": "object",
      "description": "ResourceInfo represents the information or status of an app connector resource component that's used to report on various parts of the system. For example, ResourceInfo can be used to convey the status of a remote_agent, including the status of an appgateway for an runtime environment in a container instance.",
      "properties": {
        "time": {
          "description": "The timestamp to collect the info. It is suggested to be set by the topmost level resource only.",
          "format": "google-datetime",
          "type": "string"
        },
        "id": {
          "description": "Required. Unique Id for the resource.",
          "type": "string"
        },
        "status": {
          "description": "Overall health status. Overall status is derived based on the status of each sub level resources.",
          "type": "string",
          "enumDescriptions": [
            "Health status is unknown: not initialized or failed to retrieve.",
            "The resource is healthy.",
            "The resource is unhealthy.",
            "The resource is unresponsive.",
            "Some sub-resources are UNHEALTHY."
          ],
          "enum": [
            "HEALTH_STATUS_UNSPECIFIED",
            "HEALTHY",
            "UNHEALTHY",
            "UNRESPONSIVE",
            "DEGRADED"
          ]
        },
        "sub": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaResourceInfo"
          },
          "type": "array",
          "description": "List of Info for the sub level resources."
        },
        "resource": {
          "type": "object",
          "additionalProperties": {
            "type": "any",
            "description": "Properties of the object. Contains field @type with type URL."
          },
          "description": "Specific details for the resource. This is for internal use only."
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaResourceInfo"
    },
    "GoogleIamV1TestIamPermissionsRequest": {
      "properties": {
        "permissions": {
          "items": {
            "type": "string"
          },
          "type": "array",
          "description": "The set of permissions to check for the `resource`. Permissions with wildcards (such as `*` or `storage.*`) are not allowed. For more information see [IAM Overview](https://cloud.google.com/iam/docs/overview#permissions)."
        }
      },
      "description": "Request message for `TestIamPermissions` method.",
      "type": "object",
      "id": "GoogleIamV1TestIamPermissionsRequest"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaHub": {
      "properties": {
        "internetGateway": {
          "description": "Optional. Internet Gateway configuration.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaInternetGateway"
        }
      },
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaHub",
      "type": "object",
      "description": "The Hub message contains information pertaining to the regional data path deployments."
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsight": {
      "type": "object",
      "description": "The Insight object with configuration that was returned and actual list of records.",
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsight",
      "properties": {
        "metadata": {
          "description": "Output only. Metadata for the Insight.",
          "readOnly": true,
          "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaInsightMetadata"
        },
        "appliedConfig": {
          "readOnly": true,
          "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaAppliedConfig",
          "description": "Output only. Applied insight config to generate the result data rows."
        },
        "name": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. The insight resource name. e.g. `organizations/{organization_id}/locations/{location_id}/insights/{insight_id}` OR `projects/{project_id}/locations/{location_id}/insights/{insight_id}`."
        },
        "rows": {
          "readOnly": true,
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRow"
          },
          "type": "array",
          "description": "Output only. Result rows returned containing the required value(s)."
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaRemoteAgentDetails": {
      "type": "object",
      "description": "RemoteAgentDetails reflects the details of a remote agent.",
      "properties": {},
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaRemoteAgentDetails"
    },
    "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaListSubscriptionsResponse": {
      "type": "object",
      "id": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaListSubscriptionsResponse",
      "description": "Response message for BeyondCorp.ListSubscriptions.",
      "properties": {
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        },
        "subscriptions": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformSubscriptionsV1alphaSubscription"
          },
          "type": "array",
          "description": "A list of BeyondCorp Subscriptions in the organization."
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorOperationMetadata": {
      "description": "Represents the metadata of the long-running operation.",
      "type": "object",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorOperationMetadata",
      "properties": {
        "verb": {
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true
        },
        "statusMessage": {
          "description": "Output only. Human-readable status of the operation, if any.",
          "type": "string",
          "readOnly": true
        },
        "createTime": {
          "format": "google-datetime",
          "readOnly": true,
          "type": "string",
          "description": "Output only. The time the operation was created."
        },
        "apiVersion": {
          "description": "Output only. API version used to start the operation.",
          "type": "string",
          "readOnly": true
        },
        "target": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Server-defined resource path for the target of the operation."
        },
        "endTime": {
          "description": "Output only. The time the operation finished running.",
          "format": "google-datetime",
          "type": "string",
          "readOnly": true
        },
        "requestedCancellation": {
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of `1`, corresponding to `Code.CANCELLED`.",
          "type": "boolean",
          "readOnly": true
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaListAppConnectionsResponse": {
      "type": "object",
      "description": "Response message for BeyondCorp.ListAppConnections.",
      "properties": {
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        },
        "unreachable": {
          "type": "array",
          "description": "A list of locations that could not be reached.",
          "items": {
            "type": "string"
          }
        },
        "appConnections": {
          "type": "array",
          "description": "A list of BeyondCorp AppConnections in the project.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection"
          }
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaListAppConnectionsResponse"
    },
    "Empty": {
      "id": "Empty",
      "properties": {},
      "type": "object",
      "description": "A generic empty message that you can re-use to avoid defining duplicated empty messages in your APIs. A typical example is to use it as the request or the response type of an API method. For instance: service Foo { rpc Bar(google.protobuf.Empty) returns (google.protobuf.Empty); }"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnector",
      "type": "object",
      "description": "A BeyondCorp connector resource that represents an application facing component deployed proximal to and with direct access to the application instances. It is used to establish connectivity between the remote enterprise environment and GCP. It initiates connections to the applications and can proxy the data from users over the connection.",
      "properties": {
        "principalInfo": {
          "description": "Required. Principal information about the Identity of the AppConnector.",
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaAppConnectorPrincipalInfo"
        },
        "state": {
          "readOnly": true,
          "description": "Output only. The current state of the AppConnector.",
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "CREATED",
            "UPDATING",
            "DELETING",
            "DOWN"
          ],
          "enumDescriptions": [
            "Default value. This value is unused.",
            "AppConnector is being created.",
            "AppConnector has been created.",
            "AppConnector's configuration is being updated.",
            "AppConnector is being deleted.",
            "AppConnector is down and may be restored in the future. This happens when CCFE sends ProjectState = OFF."
          ],
          "type": "string"
        },
        "updateTime": {
          "description": "Output only. Timestamp when the resource was last modified.",
          "format": "google-datetime",
          "readOnly": true,
          "type": "string"
        },
        "createTime": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Timestamp when the resource was created.",
          "format": "google-datetime"
        },
        "resourceInfo": {
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaResourceInfo",
          "description": "Optional. Resource info of the connector."
        },
        "uid": {
          "type": "string",
          "description": "Output only. A unique identifier for the instance generated by the system.",
          "readOnly": true
        },
        "displayName": {
          "type": "string",
          "description": "Optional. An arbitrary user-provided name for the AppConnector. Cannot exceed 64 characters."
        },
        "name": {
          "description": "Required. Unique resource name of the AppConnector. The name is ignored when creating a AppConnector.",
          "type": "string"
        },
        "labels": {
          "description": "Optional. Resource labels to represent user provided metadata.",
          "additionalProperties": {
            "type": "string"
          },
          "type": "object"
        }
      }
    },
    "ListConnectorsResponse": {
      "id": "ListConnectorsResponse",
      "properties": {
        "connectors": {
          "type": "array",
          "items": {
            "$ref": "Connector"
          },
          "description": "A list of BeyondCorp Connectors in the project."
        },
        "nextPageToken": {
          "type": "string",
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list."
        },
        "unreachable": {
          "description": "A list of locations that could not be reached.",
          "items": {
            "type": "string"
          },
          "type": "array"
        }
      },
      "type": "object",
      "description": "Response message for BeyondCorp.ListConnectors."
    },
    "GoogleCloudLocationListLocationsResponse": {
      "id": "GoogleCloudLocationListLocationsResponse",
      "description": "The response message for Locations.ListLocations.",
      "type": "object",
      "properties": {
        "locations": {
          "type": "array",
          "description": "A list of locations that matches the specified filter in the request.",
          "items": {
            "$ref": "GoogleCloudLocationLocation"
          }
        },
        "nextPageToken": {
          "description": "The standard List next-page token.",
          "type": "string"
        }
      }
    },
    "ConnectorOperationMetadata": {
      "properties": {
        "requestedCancellation": {
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "readOnly": true,
          "type": "boolean"
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "statusMessage": {
          "type": "string",
          "description": "Output only. Human-readable status of the operation, if any.",
          "readOnly": true
        },
        "createTime": {
          "type": "string",
          "format": "google-datetime",
          "description": "Output only. The time the operation was created.",
          "readOnly": true
        },
        "apiVersion": {
          "type": "string",
          "description": "Output only. API version used to start the operation.",
          "readOnly": true
        },
        "endTime": {
          "description": "Output only. The time the operation finished running.",
          "type": "string",
          "format": "google-datetime",
          "readOnly": true
        },
        "verb": {
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true,
          "type": "string"
        }
      },
      "id": "ConnectorOperationMetadata",
      "type": "object",
      "description": "Represents the metadata of the long-running operation."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGatewayOperationDescriptor": {
      "properties": {
        "path": {
          "description": "Optional. Contains the URI path fragment where HTTP request is sent.",
          "type": "string"
        }
      },
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGatewayOperationDescriptor",
      "type": "object",
      "description": "API operation descriptor."
    },
    "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaConfiguredInsightResponse": {
      "properties": {
        "appliedConfig": {
          "description": "Output only. Applied insight config to generate the result data rows.",
          "readOnly": true,
          "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaAppliedConfig"
        },
        "rows": {
          "description": "Output only. Result rows returned containing the required value(s) for configured insight.",
          "readOnly": true,
          "type": "array",
          "items": {
            "$ref": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaRow"
          }
        },
        "nextPageToken": {
          "description": "Output only. Next page token to be fetched. Set to empty or NULL if there are no more pages available.",
          "type": "string",
          "readOnly": true
        }
      },
      "type": "object",
      "id": "GoogleCloudBeyondcorpSaasplatformInsightsV1alphaConfiguredInsightResponse",
      "description": "The response for the configured insight."
    },
    "AppGateway": {
      "properties": {
        "displayName": {
          "type": "string",
          "description": "Optional. An arbitrary user-provided name for the AppGateway. Cannot exceed 64 characters."
        },
        "name": {
          "description": "Required. Unique resource name of the AppGateway. The name is ignored when creating an AppGateway.",
          "type": "string"
        },
        "satisfiesPzi": {
          "readOnly": true,
          "type": "boolean",
          "description": "Output only. Reserved for future use."
        },
        "updateTime": {
          "description": "Output only. Timestamp when the resource was last modified.",
          "format": "google-datetime",
          "readOnly": true,
          "type": "string"
        },
        "satisfiesPzs": {
          "readOnly": true,
          "description": "Output only. Reserved for future use.",
          "type": "boolean"
        },
        "uri": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Server-defined URI for this resource."
        },
        "allocatedConnections": {
          "description": "Output only. A list of connections allocated for the Gateway",
          "type": "array",
          "items": {
            "$ref": "AllocatedConnection"
          },
          "readOnly": true
        },
        "type": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "TCP Proxy based BeyondCorp Connection. API will default to this if unset."
          ],
          "enum": [
            "TYPE_UNSPECIFIED",
            "TCP_PROXY"
          ],
          "description": "Required. The type of network connectivity used by the AppGateway.",
          "type": "string"
        },
        "state": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "AppGateway is being created.",
            "AppGateway has been created.",
            "AppGateway's configuration is being updated.",
            "AppGateway is being deleted.",
            "AppGateway is down and may be restored in the future. This happens when CCFE sends ProjectState = OFF."
          ],
          "readOnly": true,
          "enum": [
            "STATE_UNSPECIFIED",
            "CREATING",
            "CREATED",
            "UPDATING",
            "DELETING",
            "DOWN"
          ],
          "type": "string",
          "description": "Output only. The current state of the AppGateway."
        },
        "labels": {
          "additionalProperties": {
            "type": "string"
          },
          "description": "Optional. Resource labels to represent user provided metadata.",
          "type": "object"
        },
        "createTime": {
          "format": "google-datetime",
          "type": "string",
          "readOnly": true,
          "description": "Output only. Timestamp when the resource was created."
        },
        "uid": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. A unique identifier for the instance generated by the system."
        },
        "hostType": {
          "description": "Required. The type of hosting used by the AppGateway.",
          "type": "string",
          "enumDescriptions": [
            "Default value. This value is unused.",
            "AppGateway hosted in a GCP regional managed instance group."
          ],
          "enum": [
            "HOST_TYPE_UNSPECIFIED",
            "GCP_REGIONAL_MIG"
          ]
        }
      },
      "id": "AppGateway",
      "type": "object",
      "description": "A BeyondCorp AppGateway resource represents a BeyondCorp protected AppGateway to a remote application. It creates all the necessary GCP components needed for creating a BeyondCorp protected AppGateway. Multiple connectors can be authorised for a single AppGateway."
    },
    "Tunnelv1ProtoTunnelerInfo": {
      "type": "object",
      "description": "TunnelerInfo contains metadata about tunneler launched by connection manager.",
      "properties": {
        "backoffRetryCount": {
          "description": "backoff_retry_count stores the number of times the tunneler has been retried by tunManager for current backoff sequence. Gets reset to 0 if time difference between 2 consecutive retries exceeds backoffRetryResetTime.",
          "format": "uint32",
          "type": "integer"
        },
        "latestErr": {
          "description": "latest_err stores the Error for the latest tunneler failure. Gets reset everytime the tunneler is retried by tunManager.",
          "$ref": "Tunnelv1ProtoTunnelerError"
        },
        "latestRetryTime": {
          "type": "string",
          "description": "latest_retry_time stores the time when the tunneler was last restarted.",
          "format": "google-datetime"
        },
        "id": {
          "type": "string",
          "description": "id is the unique id of a tunneler."
        },
        "totalRetryCount": {
          "type": "integer",
          "description": "total_retry_count stores the total number of times the tunneler has been retried by tunManager.",
          "format": "uint32"
        }
      },
      "id": "Tunnelv1ProtoTunnelerInfo"
    },
    "GoogleIamV1AuditConfig": {
      "type": "object",
      "description": "Specifies the audit configuration for a service. The configuration determines which permission types are logged, and what identities, if any, are exempted from logging. An AuditConfig must have one or more AuditLogConfigs. If there are AuditConfigs for both `allServices` and a specific service, the union of the two AuditConfigs is used for that service: the log_types specified in each AuditConfig are enabled, and the exempted_members in each AuditLogConfig are exempted. Example Policy with multiple AuditConfigs: { \"audit_configs\": [ { \"service\": \"allServices\", \"audit_log_configs\": [ { \"log_type\": \"DATA_READ\", \"exempted_members\": [ \"user:jose@example.com\" ] }, { \"log_type\": \"DATA_WRITE\" }, { \"log_type\": \"ADMIN_READ\" } ] }, { \"service\": \"sampleservice.googleapis.com\", \"audit_log_configs\": [ { \"log_type\": \"DATA_READ\" }, { \"log_type\": \"DATA_WRITE\", \"exempted_members\": [ \"user:aliya@example.com\" ] } ] } ] } For sampleservice, this policy enables DATA_READ, DATA_WRITE and ADMIN_READ logging. It also exempts `jose@example.com` from DATA_READ logging, and `aliya@example.com` from DATA_WRITE logging.",
      "id": "GoogleIamV1AuditConfig",
      "properties": {
        "auditLogConfigs": {
          "items": {
            "$ref": "GoogleIamV1AuditLogConfig"
          },
          "description": "The configuration for logging of each type of permission.",
          "type": "array"
        },
        "service": {
          "description": "Specifies a service that will be enabled for audit logging. For example, `storage.googleapis.com`, `cloudsql.googleapis.com`. `allServices` is a special value that covers all services.",
          "type": "string"
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectionsV1AppConnectionOperationMetadata": {
      "description": "Represents the metadata of the long-running operation.",
      "type": "object",
      "properties": {
        "verb": {
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "statusMessage": {
          "readOnly": true,
          "description": "Output only. Human-readable status of the operation, if any.",
          "type": "string"
        },
        "endTime": {
          "description": "Output only. The time the operation finished running.",
          "format": "google-datetime",
          "readOnly": true,
          "type": "string"
        },
        "requestedCancellation": {
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "readOnly": true,
          "type": "boolean"
        },
        "createTime": {
          "description": "Output only. The time the operation was created.",
          "readOnly": true,
          "type": "string",
          "format": "google-datetime"
        },
        "apiVersion": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. API version used to start the operation."
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectionsV1AppConnectionOperationMetadata"
    },
    "ApplicationEndpoint": {
      "id": "ApplicationEndpoint",
      "type": "object",
      "description": "ApplicationEndpoint represents a remote application endpoint.",
      "properties": {
        "host": {
          "description": "Required. Hostname or IP address of the remote application endpoint.",
          "type": "string"
        },
        "port": {
          "description": "Required. Port of the remote application endpoint.",
          "type": "integer",
          "format": "int32"
        }
      }
    },
    "GoogleIamV1AuditLogConfig": {
      "description": "Provides the configuration for logging a type of permissions. Example: { \"audit_log_configs\": [ { \"log_type\": \"DATA_READ\", \"exempted_members\": [ \"user:jose@example.com\" ] }, { \"log_type\": \"DATA_WRITE\" } ] } This enables 'DATA_READ' and 'DATA_WRITE' logging, while exempting jose@example.com from DATA_READ logging.",
      "id": "GoogleIamV1AuditLogConfig",
      "properties": {
        "logType": {
          "description": "The log type that this config enables.",
          "enum": [
            "LOG_TYPE_UNSPECIFIED",
            "ADMIN_READ",
            "DATA_WRITE",
            "DATA_READ"
          ],
          "type": "string",
          "enumDescriptions": [
            "Default case. Should never be this.",
            "Admin reads. Example: CloudIAM getIamPolicy",
            "Data writes. Example: CloudSQL Users create",
            "Data reads. Example: CloudSQL Users list"
          ]
        },
        "exemptedMembers": {
          "type": "array",
          "description": "Specifies the identities that do not cause logging for this type of permission. Follows the same format of Binding.members.",
          "items": {
            "type": "string"
          }
        }
      },
      "type": "object"
    },
    "GoogleIamV1Binding": {
      "type": "object",
      "description": "Associates `members`, or principals, with a `role`.",
      "properties": {
        "members": {
          "type": "array",
          "description": "Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `principal://iam.googleapis.com/locations/global/workforcePools/{pool_id}/subject/{subject_attribute_value}`: A single identity in a workforce identity pool. * `principalSet://iam.googleapis.com/locations/global/workforcePools/{pool_id}/group/{group_id}`: All workforce identities in a group. * `principalSet://iam.googleapis.com/locations/global/workforcePools/{pool_id}/attribute.{attribute_name}/{attribute_value}`: All workforce identities with a specific attribute value. * `principalSet://iam.googleapis.com/locations/global/workforcePools/{pool_id}/*`: All identities in a workforce identity pool. * `principal://iam.googleapis.com/projects/{project_number}/locations/global/workloadIdentityPools/{pool_id}/subject/{subject_attribute_value}`: A single identity in a workload identity pool. * `principalSet://iam.googleapis.com/projects/{project_number}/locations/global/workloadIdentityPools/{pool_id}/group/{group_id}`: A workload identity pool group. * `principalSet://iam.googleapis.com/projects/{project_number}/locations/global/workloadIdentityPools/{pool_id}/attribute.{attribute_name}/{attribute_value}`: All identities in a workload identity pool with a certain attribute. * `principalSet://iam.googleapis.com/projects/{project_number}/locations/global/workloadIdentityPools/{pool_id}/*`: All identities in a workload identity pool. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. * `deleted:principal://iam.googleapis.com/locations/global/workforcePools/{pool_id}/subject/{subject_attribute_value}`: Deleted single identity in a workforce identity pool. For example, `deleted:principal://iam.googleapis.com/locations/global/workforcePools/my-pool-id/subject/my-subject-attribute-value`.",
          "items": {
            "type": "string"
          }
        },
        "role": {
          "description": "Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. For an overview of the IAM roles and permissions, see the [IAM documentation](https://cloud.google.com/iam/docs/roles-overview). For a list of the available pre-defined roles, see [here](https://cloud.google.com/iam/docs/understanding-roles).",
          "type": "string"
        },
        "condition": {
          "description": "The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).",
          "$ref": "GoogleTypeExpr"
        }
      },
      "id": "GoogleIamV1Binding"
    },
    "RemoteAgentDetails": {
      "type": "object",
      "id": "RemoteAgentDetails",
      "description": "RemoteAgentDetails reflects the details of a remote agent.",
      "properties": {}
    },
    "ContainerHealthDetails": {
      "id": "ContainerHealthDetails",
      "properties": {
        "expectedConfigVersion": {
          "type": "string",
          "description": "The version of the expected config."
        },
        "currentConfigVersion": {
          "description": "The version of the current config.",
          "type": "string"
        },
        "extendedStatus": {
          "additionalProperties": {
            "type": "string"
          },
          "description": "The extended status. Such as ExitCode, StartedAt, FinishedAt, etc.",
          "type": "object"
        },
        "errorMsg": {
          "description": "The latest error message.",
          "type": "string"
        }
      },
      "description": "ContainerHealthDetails reflects the health details of a container.",
      "type": "object"
    },
    "ResolveConnectionsResponse": {
      "properties": {
        "unreachable": {
          "items": {
            "type": "string"
          },
          "type": "array",
          "description": "A list of locations that could not be reached."
        },
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        },
        "connectionDetails": {
          "type": "array",
          "items": {
            "$ref": "ConnectionDetails"
          },
          "description": "A list of BeyondCorp Connections with details in the project."
        }
      },
      "id": "ResolveConnectionsResponse",
      "description": "Response message for BeyondCorp.ResolveConnections.",
      "type": "object"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaProxyProtocolConfig": {
      "description": "The configuration for the proxy.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaProxyProtocolConfig",
      "type": "object",
      "properties": {
        "gatewayIdentity": {
          "enumDescriptions": [
            "Unspecified gateway identity.",
            "Resource name for gateway identity, in the format: projects/{project_id}/locations/{location_id}/securityGateways/{security_gateway_id}"
          ],
          "enum": [
            "GATEWAY_IDENTITY_UNSPECIFIED",
            "RESOURCE_NAME"
          ],
          "type": "string",
          "description": "Optional. The security gateway identity configuration."
        },
        "clientIp": {
          "type": "boolean",
          "description": "Optional. Client IP configuration. The client IP address is included if true."
        },
        "contextualHeaders": {
          "description": "Optional. Configuration for the contextual headers.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaContextualHeaders"
        },
        "metadataHeaders": {
          "description": "Optional. Custom resource specific headers along with the values. The names should conform to RFC 9110: \u003eField names can contain alphanumeric characters, hyphens, and periods, can contain only ASCII-printable characters and tabs, and must start with a letter.",
          "type": "object",
          "additionalProperties": {
            "type": "string"
          }
        },
        "allowedClientHeaders": {
          "type": "array",
          "description": "Optional. List of the allowed client header names.",
          "items": {
            "type": "string"
          }
        }
      }
    },
    "ConnectionDetails": {
      "description": "Details of the Connection.",
      "properties": {
        "recentMigVms": {
          "description": "If type=GCP_REGIONAL_MIG, contains most recent VM instances, like \"https://www.googleapis.com/compute/v1/projects/{project_id}/zones/{zone_id}/instances/{instance_id}\".",
          "items": {
            "type": "string"
          },
          "type": "array"
        },
        "connection": {
          "$ref": "Connection",
          "description": "A BeyondCorp Connection in the project."
        }
      },
      "type": "object",
      "id": "ConnectionDetails"
    },
    "GoogleLongrunningCancelOperationRequest": {
      "description": "The request message for Operations.CancelOperation.",
      "type": "object",
      "id": "GoogleLongrunningCancelOperationRequest",
      "properties": {}
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1SecurityGatewayOperationMetadata": {
      "type": "object",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1SecurityGatewayOperationMetadata",
      "description": "Represents the metadata of the long-running operation.",
      "properties": {
        "endTime": {
          "format": "google-datetime",
          "description": "Output only. The time the operation finished running.",
          "type": "string",
          "readOnly": true
        },
        "requestedCancellation": {
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have been cancelled successfully have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "type": "boolean",
          "readOnly": true
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "statusMessage": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. Human-readable status of the operation, if any."
        },
        "createTime": {
          "readOnly": true,
          "format": "google-datetime",
          "description": "Output only. The time the operation was created.",
          "type": "string"
        },
        "apiVersion": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. API version used to start the operation."
        },
        "verb": {
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaReportStatusRequest": {
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaReportStatusRequest",
      "properties": {
        "resourceInfo": {
          "$ref": "GoogleCloudBeyondcorpAppconnectorsV1alphaResourceInfo",
          "description": "Required. Resource info of the connector."
        },
        "validateOnly": {
          "description": "Optional. If set, validates request by executing a dry-run which would not alter the resource in any way.",
          "type": "boolean"
        },
        "requestId": {
          "type": "string",
          "description": "Optional. An optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000)."
        }
      },
      "description": "Request report the connector status.",
      "type": "object"
    },
    "AllocatedConnection": {
      "type": "object",
      "properties": {
        "ingressPort": {
          "format": "int32",
          "description": "Required. The ingress port of an allocated connection",
          "type": "integer"
        },
        "pscUri": {
          "description": "Required. The PSC uri of an allocated connection",
          "type": "string"
        }
      },
      "description": "Allocated connection of the AppGateway.",
      "id": "AllocatedConnection"
    },
    "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfigCloudPubSubNotificationConfig": {
      "type": "object",
      "description": "The configuration for Pub/Sub messaging for the AppConnector.",
      "id": "GoogleCloudBeyondcorpAppconnectorsV1alphaNotificationConfigCloudPubSubNotificationConfig",
      "properties": {
        "pubsubSubscription": {
          "type": "string",
          "description": "The Pub/Sub subscription the AppConnector uses to receive notifications."
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponseAppConnectionDetails": {
      "properties": {
        "appConnection": {
          "$ref": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnection",
          "description": "A BeyondCorp AppConnection in the project."
        },
        "recentMigVms": {
          "items": {
            "type": "string"
          },
          "description": "If type=GCP_REGIONAL_MIG, contains most recent VM instances, like `https://www.googleapis.com/compute/v1/projects/{project_id}/zones/{zone_id}/instances/{instance_id}`.",
          "type": "array"
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaResolveAppConnectionsResponseAppConnectionDetails",
      "type": "object",
      "description": "Details of the AppConnection."
    },
    "NotificationConfig": {
      "id": "NotificationConfig",
      "type": "object",
      "description": "NotificationConfig defines the mechanisms to notify instance agent.",
      "properties": {
        "pubsubNotification": {
          "$ref": "CloudPubSubNotificationConfig",
          "description": "Pub/Sub topic for Connector to subscribe and receive notifications from `projects/{project}/topics/{pubsub_topic}`"
        }
      }
    },
    "GoogleCloudBeyondcorpAppconnectorsV1ContainerHealthDetails": {
      "type": "object",
      "description": "ContainerHealthDetails reflects the health details of a container.",
      "properties": {
        "expectedConfigVersion": {
          "type": "string",
          "description": "The version of the expected config."
        },
        "currentConfigVersion": {
          "type": "string",
          "description": "The version of the current config."
        },
        "errorMsg": {
          "type": "string",
          "description": "The latest error message."
        },
        "extendedStatus": {
          "description": "The extended status. Such as ExitCode, StartedAt, FinishedAt, etc.",
          "type": "object",
          "additionalProperties": {
            "type": "string"
          }
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectorsV1ContainerHealthDetails"
    },
    "GoogleLongrunningOperation": {
      "properties": {
        "done": {
          "description": "If the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.",
          "type": "boolean"
        },
        "response": {
          "type": "object",
          "additionalProperties": {
            "description": "Properties of the object. Contains field @type with type URL.",
            "type": "any"
          },
          "description": "The normal, successful response of the operation. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`."
        },
        "name": {
          "type": "string",
          "description": "The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`."
        },
        "error": {
          "description": "The error result of the operation in case of failure or cancellation.",
          "$ref": "GoogleRpcStatus"
        },
        "metadata": {
          "description": "Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any.",
          "type": "object",
          "additionalProperties": {
            "type": "any",
            "description": "Properties of the object. Contains field @type with type URL."
          }
        }
      },
      "type": "object",
      "id": "GoogleLongrunningOperation",
      "description": "This resource represents a long-running operation that is the result of a network API call."
    },
    "CloudSecurityZerotrustApplinkAppConnectorProtoConnectorDetails": {
      "id": "CloudSecurityZerotrustApplinkAppConnectorProtoConnectorDetails",
      "description": "ConnectorDetails reflects the details of a connector.",
      "properties": {},
      "type": "object"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstream": {
      "description": "Which upstream resource to forward traffic to.",
      "type": "object",
      "properties": {
        "network": {
          "description": "Network to forward traffic to.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamNetwork"
        },
        "proxyProtocol": {
          "description": "Optional. Enables proxy protocol configuration for the upstream.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaProxyProtocolConfig"
        },
        "external": {
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstreamExternal",
          "description": "List of the external endpoints to forward traffic to."
        },
        "egressPolicy": {
          "description": "Optional. Routing policy information.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEgressPolicy"
        }
      },
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstream"
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListApplicationsResponse": {
      "properties": {
        "nextPageToken": {
          "description": "A token to retrieve the next page of results, or empty if there are no more results in the list.",
          "type": "string"
        },
        "unreachable": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "description": "A list of locations that could not be reached."
        },
        "applications": {
          "description": "A list of BeyondCorp Application in the project.",
          "items": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication"
          },
          "type": "array"
        }
      },
      "type": "object",
      "description": "Message for response to listing Applications.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaListApplicationsResponse"
    },
    "ConnectorInstanceConfig": {
      "type": "object",
      "properties": {
        "sequenceNumber": {
          "format": "int64",
          "description": "Required. A monotonically increasing number generated and maintained by the API provider. Every time a config changes in the backend, the sequenceNumber should be bumped up to reflect the change.",
          "type": "string"
        },
        "instanceConfig": {
          "additionalProperties": {
            "type": "any",
            "description": "Properties of the object. Contains field @type with type URL."
          },
          "description": "The SLM instance agent configuration.",
          "type": "object"
        },
        "imageConfig": {
          "$ref": "ImageConfig",
          "description": "ImageConfig defines the GCR images to run for the remote agent's control plane."
        },
        "notificationConfig": {
          "$ref": "NotificationConfig",
          "description": "NotificationConfig defines the notification mechanism that the remote instance should subscribe to in order to receive notification."
        }
      },
      "id": "ConnectorInstanceConfig",
      "description": "ConnectorInstanceConfig defines the instance config of a connector."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplication",
      "properties": {
        "upstreams": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaApplicationUpstream"
          },
          "type": "array",
          "description": "Optional. Which upstream resources to forward traffic to."
        },
        "schema": {
          "enumDescriptions": [
            "Default value. This value is unused.",
            "Proxy which routes traffic to actual applications, like Netscaler Gateway.",
            "Service Discovery API endpoint when Service Discovery is enabled in Gateway."
          ],
          "description": "Optional. Type of the external application.",
          "enum": [
            "SCHEMA_UNSPECIFIED",
            "PROXY_GATEWAY",
            "API_GATEWAY"
          ],
          "type": "string"
        },
        "updateTime": {
          "description": "Output only. Timestamp when the resource was last modified.",
          "type": "string",
          "readOnly": true,
          "format": "google-datetime"
        },
        "endpointMatchers": {
          "items": {
            "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaEndpointMatcher"
          },
          "type": "array",
          "description": "Optional. An array of conditions to match the application's network endpoint. Each element in the array is an EndpointMatcher object, which defines a specific combination of a hostname pattern and one or more ports. The application is considered matched if at least one of the EndpointMatcher conditions in this array is met (the conditions are combined using OR logic). Each EndpointMatcher must contain a hostname pattern, such as \"example.com\", and one or more port numbers specified as a string, such as \"443\". Hostname and port number examples: \"*.example.com\", \"443\" \"example.com\" and \"22\" \"example.com\" and \"22,33\""
        },
        "displayName": {
          "type": "string",
          "description": "Optional. An arbitrary user-provided name for the application resource. Cannot exceed 64 characters."
        },
        "name": {
          "type": "string",
          "description": "Identifier. Name of the resource."
        },
        "createTime": {
          "readOnly": true,
          "description": "Output only. Timestamp when the resource was created.",
          "type": "string",
          "format": "google-datetime"
        }
      },
      "type": "object",
      "description": "The information about an application resource."
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscovery": {
      "type": "object",
      "properties": {
        "apiGateway": {
          "description": "Optional. External API configuration.",
          "$ref": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscoveryApiGateway"
        }
      },
      "description": "Settings related to the Service Discovery.",
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaServiceDiscovery"
    },
    "ConnectionOperationMetadata": {
      "properties": {
        "endTime": {
          "format": "google-datetime",
          "type": "string",
          "description": "Output only. The time the operation finished running.",
          "readOnly": true
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "statusMessage": {
          "readOnly": true,
          "description": "Output only. Human-readable status of the operation, if any.",
          "type": "string"
        },
        "requestedCancellation": {
          "readOnly": true,
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "type": "boolean"
        },
        "verb": {
          "description": "Output only. Name of the verb executed by the operation.",
          "readOnly": true,
          "type": "string"
        },
        "createTime": {
          "description": "Output only. The time the operation was created.",
          "format": "google-datetime",
          "readOnly": true,
          "type": "string"
        },
        "apiVersion": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. API version used to start the operation."
        }
      },
      "id": "ConnectionOperationMetadata",
      "description": "Represents the metadata of the long-running operation.",
      "type": "object"
    },
    "ResolveInstanceConfigResponse": {
      "type": "object",
      "description": "Response message for BeyondCorp.ResolveInstanceConfig.",
      "id": "ResolveInstanceConfigResponse",
      "properties": {
        "instanceConfig": {
          "description": "ConnectorInstanceConfig.",
          "$ref": "ConnectorInstanceConfig"
        }
      }
    },
    "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGatewayOperationMetadata": {
      "id": "GoogleCloudBeyondcorpSecuritygatewaysV1alphaSecurityGatewayOperationMetadata",
      "type": "object",
      "properties": {
        "statusMessage": {
          "description": "Output only. Human-readable status of the operation, if any.",
          "readOnly": true,
          "type": "string"
        },
        "createTime": {
          "type": "string",
          "readOnly": true,
          "description": "Output only. The time the operation was created.",
          "format": "google-datetime"
        },
        "apiVersion": {
          "type": "string",
          "description": "Output only. API version used to start the operation.",
          "readOnly": true
        },
        "requestedCancellation": {
          "type": "boolean",
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have been cancelled successfully have Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "readOnly": true
        },
        "endTime": {
          "readOnly": true,
          "format": "google-datetime",
          "description": "Output only. The time the operation finished running.",
          "type": "string"
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "verb": {
          "readOnly": true,
          "description": "Output only. Name of the verb executed by the operation.",
          "type": "string"
        }
      },
      "description": "Represents the metadata of the long-running operation."
    },
    "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionOperationMetadata": {
      "type": "object",
      "properties": {
        "createTime": {
          "type": "string",
          "readOnly": true,
          "format": "google-datetime",
          "description": "Output only. The time the operation was created."
        },
        "apiVersion": {
          "description": "Output only. API version used to start the operation.",
          "readOnly": true,
          "type": "string"
        },
        "statusMessage": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Human-readable status of the operation, if any."
        },
        "requestedCancellation": {
          "type": "boolean",
          "description": "Output only. Identifies whether the user has requested cancellation of the operation. Operations that have successfully been cancelled have google.longrunning.Operation.error value with a google.rpc.Status.code of 1, corresponding to `Code.CANCELLED`.",
          "readOnly": true
        },
        "target": {
          "description": "Output only. Server-defined resource path for the target of the operation.",
          "type": "string",
          "readOnly": true
        },
        "endTime": {
          "description": "Output only. The time the operation finished running.",
          "type": "string",
          "format": "google-datetime",
          "readOnly": true
        },
        "verb": {
          "readOnly": true,
          "type": "string",
          "description": "Output only. Name of the verb executed by the operation."
        }
      },
      "id": "GoogleCloudBeyondcorpAppconnectionsV1alphaAppConnectionOperationMetadata",
      "description": "Represents the metadata of the long-running operation."
    }
  },
  "baseUrl": "https://beyondcorp.googleapis.com/",
  "parameters": {
    "quotaUser": {
      "description": "Available to use for quota purposes for server-side applications. Can be any arbitrary string assigned to a user, but should not exceed 40 characters.",
      "type": "string",
      "location": "query"
    },
    "upload_protocol": {
      "type": "string",
      "description": "Upload protocol for media (e.g. \"raw\", \"multipart\").",
      "location": "query"
    },
    "key": {
      "location": "query",
      "description": "API key. Your API key identifies your project and provides you with API access, quota, and reports. Required unless you provide an OAuth 2.0 token.",
      "type": "string"
    },
    "$.xgafv": {
      "type": "string",
      "enum": [
        "1",
        "2"
      ],
      "enumDescriptions": [
        "v1 error format",
        "v2 error format"
      ],
      "description": "V1 error format.",
      "location": "query"
    },
    "prettyPrint": {
      "type": "boolean",
      "description": "Returns response with indentations and line breaks.",
      "default": "true",
      "location": "query"
    },
    "callback": {
      "type": "string",
      "description": "JSONP",
      "location": "query"
    },
    "access_token": {
      "description": "OAuth access token.",
      "type": "string",
      "location": "query"
    },
    "fields": {
      "location": "query",
      "description": "Selector specifying which fields to include in a partial response.",
      "type": "string"
    },
    "oauth_token": {
      "description": "OAuth 2.0 token for the current user.",
      "type": "string",
      "location": "query"
    },
    "alt": {
      "location": "query",
      "default": "json",
      "enumDescriptions": [
        "Responses with Content-Type of application/json",
        "Media download with context-dependent Content-Type",
        "Responses with Content-Type of application/x-protobuf"
      ],
      "type": "string",
      "enum": [
        "json",
        "media",
        "proto"
      ],
      "description": "Data format for response."
    },
    "uploadType": {
      "description": "Legacy upload protocol for media (e.g. \"media\", \"multipart\").",
      "location": "query",
      "type": "string"
    }
  },
  "title": "BeyondCorp API",
  "documentationLink": "https://cloud.google.com/",
  "revision": "20260916",
  "servicePath": "",
  "version_module": true,
  "version": "v1alpha",
  "name": "beyondcorp",
  "icons": {
    "x32": "http://www.google.com/images/icons/product/search-32.gif",
    "x16": "http://www.google.com/images/icons/product/search-16.gif"
  },
  "ownerName": "Google",
  "discoveryVersion": "v1",
  "rootUrl": "https://beyondcorp.googleapis.com/",
  "ownerDomain": "google.com"
}
