This repository was archived by the owner on Mar 6, 2026. It is now read-only.
feat: experimental service account iam endpoint flow for id token#1258
Merged
arithmetic1728 merged 6 commits intomainfrom Mar 28, 2023
Merged
feat: experimental service account iam endpoint flow for id token#1258arithmetic1728 merged 6 commits intomainfrom
arithmetic1728 merged 6 commits intomainfrom
Conversation
4bbe7c6 to
4aad817
Compare
8211c66 to
1082922
Compare
clundin25
reviewed
Mar 28, 2023
clundin25
reviewed
Mar 28, 2023
clundin25
approved these changes
Mar 28, 2023
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
For service account credentials, implement a new ID token flow which uses iam.generateIdToken endpoint. This feature is currently experimental since iam endpoint doesn't support setAzpToEmail option yet. The ID token generated by this new flow will have a different azp claim (it uses id instead of email)
Design doc: go/googleapis-auth-id-token-iam-for-tpc
Example usage: