Stores credentials that code libraries (Python, Node, Go SDKs) pick up automatically, separate from the gcloud CLI's own login. Use it when a local script needs to call Google APIs without embedding a service account key. The credentials land in ~/.config/gcloud/application_default_credentials.json and are removed with gcloud auth application-default revoke.
Looking for more? Search all 7,657 commands — works offline, in English or Spanish, and fixes typos.