Skip to content

docs(auth): link ComputeEngineCredentials Javadoc to bound token section - #14627

Open
macastelaz wants to merge 6 commits into
googleapis:agentic-identities-bound-tokenfrom
macastelaz:docs-agent-bound-tokens-section-link
Open

macastelaz wants to merge 6 commits into
googleapis:agentic-identities-bound-tokenfrom
macastelaz:docs-agent-bound-tokens-section-link

Conversation

@macastelaz

@macastelaz macastelaz commented Oct 10, 2026 •

Copy link
Copy Markdown
Contributor

Important

Merge after cl/996749889 publishes on DevSite (or retarget to main if agentic-identities-bound-token merges first).

Summary

Follow-up to #14557 (comment): updates the ComputeEngineCredentials class Javadoc link to point directly to the new #certificate-bound-tokens-for-agent-identities section anchor introduced in cl/996749889:

https://cloud.google.com/java/getting-started/getting-started-with-google-auth-library#certificate-bound-tokens-for-agent-identities

Adds a README section and ComputeEngineCredentials class Javadoc covering:
- bound tokens are the default when an agent identity workload certificate
  is present, and require mTLS with the same certificate
- when a bound token is requested (cert discovery, agent SPIFFE trust domain)
- opt-out env vars and precedence: GOOGLE_API_ENABLE_RUNTIME_BOUND_TOKEN over
  the legacy GOOGLE_API_PREVENT_AGENT_TOKEN_SHARING_FOR_GCP_SERVICES, and
  GOOGLE_API_USE_CLIENT_CERTIFICATE=false also disabling binding
- the process-wide scope of the opt-out
- requesting unbound ID tokens for specific targets with
  IdTokenProvider.Option.BIND_ID_TOKEN_FALSE
- the ADK for Java known limitation and its workaround
@macastelaz
macastelaz requested review from a team as code owners October 10, 2026 02:33

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Javadoc for the ComputeEngineCredentials class to document that certificate-bound access tokens and ID tokens are requested by default when a workload certificate for an agent identity is available. It also adds references to IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN and the Google Auth Library guide. I have no feedback to provide.

@macastelaz
macastelaz requested a review from lqiu96 October 10, 2026 03:15

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant