About accessing regional endpoints through Private Service Connect endpoints
This page provides an overview of usingPrivate Service Connect endpoints to access regionalendpoints forsupported Google APIs in supported regions.
Consider using regional endpoints if you want to ensure that in-transit dataremains in a particular region.
For information about other Private Service Connect configurations,seePrivate Service Connect overview.
Features and compatibility
This table summarizes the features that are supported by endpoints that are usedto access regional endpoints for Google APIs.
| Configuration | Details |
|---|---|
| Consumer configuration (endpoint) | |
| Global reachability | If global access is enabled |
| Cloud Interconnect traffic | |
| Cloud VPN traffic | |
| Access through VPC Network Peering | |
| Connection propagation through NCC | |
| DNS configuration | Manual DNS configuration |
| IP version | IPv4 or IPv6 |
| Producer | |
| Supported services | Supported regional Google APIs |
Specifications
Public hostnames for regional endpoints have the following format:
Note: The private hostname format is also supported:SERVICE.REGION.rep.DOMAIN.We recommend using the public hostnames to specify the target service inyour Private Service Connect endpoint configuration.SERVICE.REGION.p.rep.DOMAIN.The subnet that you specify when you create an endpoint is aregularsubnet. The IP address assigned to the endpointis a regional internal IP address.
If you're using Shared VPC, you can create the endpoint in eitherthe host project or a service project.
By default, endpoints can be accessed only by clients that are in the sameregion and the same VPC network (or Shared VPCnetwork) as the endpoint. For information about making endpoints availablein other regions, seeGlobal access.
Architecture
Private Service Connect endpoints that have aregional endpoint target point to a service attachment that has been createdby Google to direct traffic to the regional service endpoint.
Clients in the same region as the endpoint can send traffic to the endpoint. Youcan also access the endpoint fromconnectednetworks in thesame region. If you want to access the endpoint from other regions, configureglobal access.
Figure 1. An endpoint lets service consumers send traffic from the consumer's VPC network to regional service endpoints for supported Google APIs through a service attachment that is managed by Google (click to enlarge).
Global access
When you create an endpoint, you can configure global access. Global access letsclients in other regions access the endpoint. The endpoint is also accessiblefromconnectednetworks.
Figure 2. An endpoint with global access enabled can be accessed by clients in another region, including by clients in connected networks (click to enlarge).
Supported regions and services
For a list of supported regions and services, seeRegional serviceendpoints.
Pricing
For pricing information, seeVirtual Private Cloud pricing.
Quotas
See theNumber of Regional Endpoints per project per region quota inQuotas and limits.
What's next
- Create a Private Service Connect endpoint toaccess regionalGoogle APIs.
- Learn more aboutPrivate Service Connect.
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-02-19 UTC.