{"record":{"id":"4460e3179dd2285d","repo":"grpc/grpc-go","slug":"required-field-subjecttokentype-is-not-specified","errorCode":null,"errorMessage":"required field SubjectTokenType is not specified","messagePattern":"required field SubjectTokenType is not specified","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/sts/sts.go","lineNumber":234,"sourceCode":"// - tokenExchangeServiceURI is a valid URI with a http(s) scheme\n// - subjectTokenPath and subjectTokenType are not empty.\nfunc validateOptions(opts Options) error {\n\tif opts.TokenExchangeServiceURI == \"\" {\n\t\treturn errors.New(\"empty token_exchange_service_uri in options\")\n\t}\n\tu, err := url.Parse(opts.TokenExchangeServiceURI)\n\tif err != nil {\n\t\treturn err\n\t}\n\tif u.Scheme != \"http\" && u.Scheme != \"https\" {\n\t\treturn fmt.Errorf(\"scheme is not supported: %q. Only http(s) is supported\", u.Scheme)\n\t}\n\n\tif opts.SubjectTokenPath == \"\" {\n\t\treturn errors.New(\"required field SubjectTokenPath is not specified\")\n\t}\n\tif opts.SubjectTokenType == \"\" {\n\t\treturn errors.New(\"required field SubjectTokenType is not specified\")\n\t}\n\treturn nil\n}\n\n// cachedMetadata returns the cached metadata provided it is not going to\n// expire anytime soon.\n//\n// Caller must hold c.mu.\nfunc (c *callCreds) cachedMetadata() map[string]string {\n\tnow := time.Now()\n\t// If the cached token has not expired and the lifetime remaining on that\n\t// token is greater than the minimum value we are willing to accept, go\n\t// ahead and use it.\n\tif c.tokenExpiry.After(now) && c.tokenExpiry.Sub(now) > minCachedTokenLifetime {\n\t\treturn c.tokenMetadata\n\t}\n\treturn nil\n}","sourceCodeStart":216,"sourceCodeEnd":252,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/sts/sts.go#L216-L252","documentation":"Returned by sts.validateOptions when Options.SubjectTokenType is empty. SubjectTokenType is an RFC 8693 identifier (e.g., urn:ietf:params:oauth:token-type:jwt) that tells the STS server what kind of token the subject_token is. Without it the token exchange server cannot interpret the subject token.","triggerScenarios":"Calling sts.NewCredentials with an Options struct where SubjectTokenType is not set. This is the last of the three required-field checks in validateOptions (after URI and SubjectTokenPath).","commonSituations":"Copy-paste from examples that omit the token type, or config that relies on a default value (there is no default). Developers unfamiliar with RFC 8693 URN identifiers may leave it blank thinking it is optional.","solutions":["Set Options.SubjectTokenType to the correct URN for your subject token type.","For JWT subject tokens (e.g., Kubernetes SA tokens), use urn:ietf:params:oauth:token-type:jwt.","For opaque or SAML tokens, use the corresponding URN from RFC 8693 section 3."],"exampleFix":"// before\nopts := sts.Options{\n    TokenExchangeServiceURI: \"https://sts.googleapis.com/v1/token\",\n    SubjectTokenPath:        \"/var/run/secrets/tokens/sa-token\",\n    // SubjectTokenType missing\n}\n// after\nopts := sts.Options{\n    TokenExchangeServiceURI: \"https://sts.googleapis.com/v1/token\",\n    SubjectTokenPath:        \"/var/run/secrets/tokens/sa-token\",\n    SubjectTokenType:        \"urn:ietf:params:oauth:token-type:jwt\",\n}","handlingStrategy":"validation","validationCode":"if opts.SubjectTokenType == \"\" {\n    return fmt.Errorf(\"SubjectTokenType must be set (e.g., urn:ietf:params:oauth:token-type:jwt)\")\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Set SubjectTokenType to the RFC 8693 URN matching your subject token format.","Common value for JWT tokens: urn:ietf:params:oauth:token-type:jwt.","Document the expected URN in your config templates."],"tags":["go","grpc","sts","credentials","validation"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}