Meta tags:
description= Acquire a Google-signed OpenID Connect (OIDC) ID token.;
Headings (most frequently used words):
id, token, an, and, generate, get, with, for, service, cloud, run, stay, organized, collections, save, categorize, content, based, on, your, preferences, methods, getting, what, next, from, the, metadata, server, curl, powershell, java, go, node, js, python, ruby, use, connecting, to, by, impersonating, account, generic, development, functions, products, pricing, support, resources, engage,
Text of the page (most frequently used words):
the (134), token (71), #service (50), cloud (46), google (45), for (44), you (35), and (32), account (29), use (24), can (22), run (19), gcloud (18), credentials (18), audience (18), target (18), application (17), metadata (16), auth (16), get (16), that (16), url (16), cli (15), http (15), with (14), com (13), code (12), this (12), server (12), identity (12), example (12), request (12), import (12), generate (11), environment (11), using (11), authentication (10), principal (10), default (10), see (9), development (9), api (9), services (9), create (9), from (9), err (9), more (8), access (8), authenticate (8), when (8), call (8), client (8), overview (8), manage (7), thumb (7), information (7), tokens (7), your (7), www (7), make (7), googlecredentials (7), other (6), sample (6), java (6), methods (6), these (6), authorization (6), following (6), impersonation (6), include (6), authenticated (6), string (6), idtokencredentials (6), oauth2 (6), getidtokenfrommetadataserver (6), resources (5), engine (5), print (5), functions (5), replace (5), roles (5), running (5), attached (5), must (5), configure (5), generated (5), once (5), obtained (5), header (5), googleauth (5), install (5), library (5), fmt (5), option (5), sdk (5), management (5), português (4), español (4), down (4), need (4), content (4), compute (4), used (4), user (4), iam (4), uri (4), grant (4), role (4), invoker (4), another (4), security (4), workflow (4), tasks (4), scheduler (4), value (4), add (4), part (4), idtokenprovider (4), const (4), nil (4), return (4), tools (4), libraries (4), keys (4), about (3), samples (3), products (3), understand (3), page (3), are (3), generic (3), they (3), function (3), required (3), invoke (3), will (3), curl (3), service_account_email (3), true (3), privilege (3), bearing (3), adc (3), resource (3), identify (3), set (3), product (3), documentation (3), step (3), impersonating (3), before (3), have (3), configuration (3), either (3), requests (3), pub (3), sub (3), distributed (3), connecting (3), id_client (3), obtain (3), uses (3), console (3), targetaudience (3), failed (3), errorf (3), ctx (3), idtoken (3), golang (3), org (3), ioexception (3), public (3), based (3), ways (3), guides (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), sign (2), terms (2), site (2), youtube (2), getting (2), started (2), system (2), support (2), pricing (2), last (2), updated (2), 2026 (2), utc (2), licensed (2), under (2), license (2), send (2), feedback (2), commands (2), query (2), what (2), any (2), caller (2), permissions (2), not (2), https (2), openid (2), connect (2), usually (2), however (2), should (2), impersonate (2), enables (2), itself (2), might (2), provide (2), enable (2), lets (2), workflows (2), fully (2), managed (2), define (2), invokes (2), some (2), help (2), determine (2), claim (2), requires (2), aud (2), refresh (2), target_audience (2), new (2), gcecredentials (2), def (2), require (2), ruby (2), use_metadata_identity_endpoint (2), compute_engine (2), specific (2), setting (2), transport (2), args (2), kubernetes (2), python (2), await (2), variables (2), todo (2), developer (2), node (2), newtokensource (2), working (2), construct (2), object (2), which (2), obtains (2), context (2), build (2), arrays (2), throws (2), void (2), static (2), generalsecurityexception (2), main (2), flavor (2), computemetadata (2), instance (2), accounts (2), app (2), describes (2), proxy (2), signed (2), cases (2), languages (2), frameworks (2), infrastructure (2), costs (2), usage (2), storage (2), observability (2), monitoring (2), networking (2), migration (2), industry (2), solutions (2), hybrid (2), multicloud (2), databases (2), data (2), analytics (2), pipelines (2), hosting (2), managing (2), best (2), practices (2), apis (2), cross (2), reference (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, events, blog, engage, training, certification, architecture, center, github, status, release, notes, community, forums, contact, sales, marketplace, all, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, incorrectinformationorsamplecode, missing, missingtheinformationsamplesineed, otherdown, tell, except, otherwise, noted, details, registered, trademark, oracle, its, affiliates, developers, policies, apache, creative, commons, attribution, learn, shell, next, command, sure, keep, secure, never, them, production, meant, during, only, warning, has, work, post, iamcredentials, googleapis, projects, serviceaccounts, generateidtoken, includeemail, type, json, bearer, email, address, mdashfor, authorized, creator, serviceaccountopenidtokencreator, environments, provided, perform, cloudfunctions, instructions, general, process, always, involve, two, principals, represents, being, impersonated, called, seem, easier, simply, directly, known, self, creates, vulnerability, because, refreshed, perpetuity, allows, short, lived, trusted, then, orchestration, platform, executes, order, asynchronous, communication, between, message, push, subscription, execution, task, calls, enterprise, grade, cron, job, targets, gets, made, includes, calling, automatically, appropriate, initiate, end, puts, fetch_access_token, auth_cloud_idtoken_metadata_server, param, optionally, also, specify, mentioning, examples, appengine, etc, none, str, idtoken_from_metadata_server, log, fetchidtoken, getidtokenclient, async, uncomment, fprintf, receive, withcredentials, finddefaultcredentials, background, error, writer, func, println, out, gettokenvalue, refreshaccesstoken, licenses_true, format_full, aslist, setoptions, options, settargetaudience, setidtokenprovider, newbuilder, getapplicationdefault, below, idtokenfrommetadataserver, class, util, restmethod, headers, powershell, retrieve, endpoint, shown, flexible, standard, associated, generates, cannot, accepted, hosted, probably, claims, there, various, specified, their, document, term, refer, contents, lifetimes, making, deployed, gateway, endpoints, authenticating, secured, aware, iap, invoking, accessing, acquire, oidc, save, categorize, preferences, stay, organized, collections, home, uninstalling, components, packages, scripting, cheat, sheet, develop, accessibility, features, properties, configurations, behind, firewall, initialize, reauthentication, verification, requirement, types, troubleshoot, setup, how, works, premises, provider, containerized, local, rest, homebrew, installer, versioned, archives, snap, package, migrate, stable, image, docker, installation, explained, discover, start, free, skip,
Text of the page (random words):
nology areas more overview guides reference resources cross product tools more console discover google cloud sdk overview gcloud cli overview cloud client libraries overview client libraries and cloud apis explained get started install the gcloud cli other installation methods using docker overview migrate to the stable image using a snap package using versioned archives using the installer using homebrew authenticate to google cloud authentication methods at google ways to authenticate authenticate for using client libraries authenticate for using rest authenticate by using service account impersonation application default credentials set up application default credentials overview local development environment resource with an attached service account containerized environment on premises or another cloud provider cloud based development environment how application default credentials works troubleshoot your adc setup api keys use api keys to access apis manage api keys best practices for managing api keys get an id token tokens overview token types 2 step verification requirement reauthentication authentication use cases identity management products configure the gcloud cli initialize the gcloud cli authenticate for the gcloud cli configure the gcloud cli for use behind a proxy or firewall manage gcloud cli configurations manage gcloud cli properties enable accessibility features develop gcloud cli cheat sheet scripting gcloud cli commands client libraries best practices manage packages in gcloud cli managing gcloud cli components uninstalling the gcloud cli ai and ml application development application hosting compute data analytics and pipelines databases distributed hybrid and multicloud industry solutions migration networking observability and monitoring security storage access and resources management costs and usage management infrastructure as code sdk languages frameworks and tools home documentation application development google cloud sdk authentication guides send feedback get an id token stay organized with collections save and categorize content based on your preferences this page describes some ways to acquire a google signed openid connect oidc id token you need a google signed id token for the following authentication use cases accessing a cloud run service invoking a cloud run function authenticating a user to an application secured by identity aware proxy iap making a request to an api deployed with api gateway or cloud endpoints for information about id token contents and lifetimes see id tokens id tokens have a specific service or application that they can be used for specified by the value of their aud claim this document uses the term target service to refer to the service or application that the id token can be used to authenticate to when you get the id token you can include it in an authorization header in the request to the target service methods for getting an id token there are various ways to get an id token this page describes the following methods get an id token from the metadata server use a connecting service to generate an id token generate an id token by impersonating a service account generate a generic id token for development with cloud run and cloud run functions if you need an id token to be accepted by an application not hosted on google cloud you can probably use these methods however you should determine what id token claims the application requires get an id token from the metadata server when your code is running on a resource that can have a service account attached to it the metadata server for the associated service can usually provide an id token the metadata server generates id tokens for the attached service account you cannot get an id token based on user credentials from the metadata server you can get an id token from the metadata server when your code is running on the following google cloud services compute engine app engine standard environment app engine flexible environment cloud run functions cloud run google kubernetes engine cloud build to retrieve an id token from the metadata server you query the identity endpoint for the service account as shown in this example curl replace audience with the uri for the target service for example http www example com curl h metadata flavor google http metadata computemetadata v1 instance service accounts default identity audience audience powershell replace audience with the uri for the target service for example http www example com value invoke restmethod headers metadata flavor google uri http metadata computemetadata v1 instance service accounts default identity audience audience value java to run this code sample you must install the auth client library for java import com google auth oauth2 googlecredentials import com google auth oauth2 idtokencredentials import com google auth oauth2 idtokenprovider import com google auth oauth2 idtokenprovider option import java io ioexception import java security generalsecurityexception import java util arrays public class idtokenfrommetadataserver public static void main string args throws ioexception generalsecurityexception todo developer replace the below variables before running the code the url or target audience to obtain the id token for string url https example com getidtokenfrommetadataserver url use the google cloud metadata server to create an identity token and add it to the http request as part of an authorization header public static void getidtokenfrommetadataserver string url throws ioexception construct the googlecredentials object which obtains the default configuration from your working environment googlecredentials googlecredentials googlecredentials getapplicationdefault idtokencredentials idtokencredentials idtokencredentials newbuilder setidtokenprovider idtokenprovider googlecredentials settargetaudience url setting the id token options setoptions arrays aslist option format_full option licenses_true build get the id token once you ve obtained the id token you can use it to make an authenticated call to the target audience string idtoken idtokencredentials refreshaccesstoken gettokenvalue system out println generated id token go import context fmt io golang org x oauth2 google google golang org api idtoken google golang org api option getidtokenfrommetadataserver uses the google cloud metadata server environment to create an identity token and add it to the http request as part of an authorization header func getidtokenfrommetadataserver w io writer url string error url http www example com ctx context background construct the googlecredentials object which obtains the default configuration from your working environment credentials err google finddefaultcredentials ctx if err nil return fmt errorf failed to generate default credentials w err ts err idtoken newtokensource ctx url option withcredentials credentials if err nil return fmt errorf failed to create newtokensource w err get the id token once you ve obtained the id token you can use it to make an authenticated call to the target audience _ err ts token if err nil return fmt errorf failed to receive token w err fmt fprintf w generated id token n return nil node js to run this code sample you must install the google auth library for node js todo developer 1 uncomment and replace these variables before running the sample const targetaudience http www example com const googleauth require google auth library async function getidtokenfrommetadataserver const googleauth new googleauth const client await googleauth getidtokenclient targetaudience get the id token once you ve obtained the id token you can use it to make an authenticated call to the target audience await client idtokenprovider fetchidtoken targetaudience console log generated id token getidtokenfrommetadataserver python to run this code sample you must install the google auth python library import google from google auth import compute_engine import google auth transport requests import google oauth2 credentials def idtoken_from_metadata_server url str none use the google cloud metadata server in the cloud run or appengine or kubernetes etc environment to create an identity token and add it to the http request as part of an authorization header args url the url or target audience to obtain the id token for examples http www example com request google auth transport requests request set the target audience setting use_metadata_identity_endpoint to true will make the request use the default application credentials optionally you can also specify a specific service account to use by mentioning the service_account_email credentials compute_engine idtokencredentials request request target_audience url use_metadata_identity_endpoint true get the id token once you ve obtained the id token use it to make an authenticated call to the target audience credentials refresh request print credentials token print generated id token ruby to run this code sample you must install the google auth library for ruby require googleauth uses the google cloud metadata server environment to create an identity token and add it to the http request as part of an authorization header param url string the url or target audience to obtain the id token for e g http www example com def auth_cloud_idtoken_metadata_server url create the gcecredentials client id_client google auth gcecredentials new target_audience url get the id token once you ve obtained the id token you can use it to make an authenticated call to the target audience id_client fetch_access_token puts generated id token id_client refresh end use a connecting service to generate an id token some google cloud services help you call other services these connecting services might help determine when the call gets made or manage a workflow that includes calling the service the following services can automatically include an id token with the appropriate value for the aud claim when they initiate a call to a service that requires an id token cloud scheduler cloud scheduler is a fully managed enterprise grade cron job scheduler you can configure cloud scheduler to include either an id token or an access token when it invokes another service for more information see using authentication with http targets cloud tasks cloud tasks lets you manage the execution of distributed tasks you can configure a task to include either an id token or an access token when it calls a service for more information see using http target tasks with authentication tokens pub sub pub sub enables asynchronous communication between services you can configure pub sub to include an id token with a message for more information see authentication for push subscription workflows workflows is a fully managed orchestration platform that executes services in an order that you define a workflow you can define a workflow to include either an id token or an access token when it invokes another service for more information see make authenticated requests from a workflow generate an id token by impersonating a service account service account impersonation allows a principal to generate short lived credentials for a trusted service account the principal can then use these credentials to authenticate as the service account before a principal can impersonate a service account it must have an iam role on that service account that enables impersonation if the principal is itself another service account it might seem easier to simply provide the required permissions directly to that service account and enable it to impersonate itself this configuration known as self impersonation creates a security vulnerability because it lets the service account create an access token that can be refreshed in perpetuity service account impersonation should always involve two principals a principal that represents the caller and the service account that is being impersonated called the privilege bearing service account to generate an id token by impersonating a service account you use the following general process for step by step instructions see create an id token identify or create a service account to be the privilege bearing service account identify the required roles to invoke the target service grant these roles to the service account on the target service for cloud run services grant the cloud run invoker role roles run invoker for cloud run functions grant the cloud functions invoker role roles cloudfunctions invoker for other target services see the product documentation for the service identify the principal that will perform the impersonation and set up application default credentials adc to use the credentials for this principal for development environments the principal is usually the user account you provided to adc by using the gcloud cli however if you re running on a resource with a service account attached the attached service account is the principal grant the principal the service account openid connect identity token creator role roles iam serviceaccountopenidtokencreator use the iam credentials api to generate the id token for the authorized service account replace the following audience the uri for the target service mdashfor example http www example com service_account_email the email address of the privilege bearing service account curl x post h authorization bearer gcloud auth print access token h content type application json d audience audience includeemail true https iamcredentials googleapis com v1 projects serviceaccounts service_account_email generateidtoken generate a generic id token for development with cloud run and cloud run functions you can use the gcloud cli to get an id token for your user credentials that can be used with any cloud run service or cloud run function that the caller has the required iam permissions to invoke this token will not work for any other application warning be sure to keep these tokens secure and never use them in a production environment they are meant to be used during development only to generate a generic id token you use the gcloud auth print identity token command gcloud auth print identity token what s next understand id tokens use shell commands to query the compute engine metadata server learn more about authentication methods send feedback except as otherwise noted the content of this page is licensed under the creative commons attribution 4 0 license and code samples are licensed under the apache 2 0 license for details see the google developers site policies java is a registered trademark of oracle and or its affiliates last updated 2026 07 21 utc need to tell us more easy to understand easytounderstand thumb up solved my problem solvedmyproblem thumb up other otherup thumb up hard to understand hardtounderstand thumb down incorrect information or sample code incorrectinformationorsamplecode thumb down missing the information samples i need missingtheinformationsamplesineed thumb down o...
|