{"record":{"id":"7245ad24ea7f51b7","repo":"grpc/grpc-go","slug":"credentials-audience-cannot-be-empty","errorCode":null,"errorMessage":"credentials: audience cannot be empty","messagePattern":"credentials: audience cannot be empty","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/google/gcp_service_account_identity_credentials.go","lineNumber":103,"sourceCode":"// parameters cannot be empty.\n//\n// The credentials object starts asynchronous background token fetches to\n// refresh expired tokens. The provided context propagates cancellation to\n// these background tasks. Users should not pass an RPC-scoped context here,\n// but rather a context that is valid for the entire lifetime of the\n// credentials and should cancel the context when they are done.\n//\n// # Experimental\n//\n// Notice: This API is EXPERIMENTAL and may be changed or removed in a\n// later release.\nfunc NewServiceAccountIdentityCredentials(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {\n\tif ctx == nil {\n\t\treturn nil, fmt.Errorf(\"credentials: ctx cannot be nil\")\n\t}\n\n\tif audience == \"\" {\n\t\treturn nil, fmt.Errorf(\"credentials: audience cannot be empty\")\n\t}\n\n\tcreds, err := internal.NewIDTokenCredentials(&idtoken.Options{Audience: audience})\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"credentials: failed to create ID token credentials: %v\", err)\n\t}\n\n\treturn &gcpServiceAccountIdentityCallCreds{\n\t\tctx:      ctx,\n\t\taudience: audience,\n\t\tcreds:    creds,\n\t\tbackoff:  internal.BackoffStrategy,\n\t}, nil\n}\n\n// GetRequestMetadata gets the current request metadata, refreshing tokens if\n// required. This implementation follows the PerRPCCredentials interface.\n//","sourceCodeStart":85,"sourceCodeEnd":121,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/google/gcp_service_account_identity_credentials.go#L85-L121","documentation":"Returned by google.NewServiceAccountIdentityCredentials when the audience argument is an empty string. The audience is the intended recipient of the ID-token JWT; without it the token has no valid target and the metadata-server fetch would be meaningless, so the constructor rejects it upfront.","triggerScenarios":"Calling google.NewServiceAccountIdentityCredentials(ctx, \"\") or with a variable that resolved to empty. The check at gcp_service_account_identity_credentials.go:102-104 returns immediately.","commonSituations":"Audience sourced from an unset config flag/env var/secret; a typo or empty default; refactoring that dropped the audience plumbing; misreading the API and assuming a default audience would be inferred (it is not).","solutions":["Provide a non-empty audience string (typically the URL/identifier of the receiving service, e.g. \"https://my-service.example.com\").","Source the audience from configuration and validate it is non-empty before calling the constructor.","Add a startup check: if audience == \"\" { log.Fatal(\"audience required\") }."],"exampleFix":"// before\ncreds, err := google.NewServiceAccountIdentityCredentials(ctx, os.Getenv(\"AUD\")) // empty -> error\n\n// after\nif aud := os.Getenv(\"AUD\"); aud == \"\" {\n    log.Fatal(\"AUD env var (token audience) must be set\")\n}\ncreds, err := google.NewServiceAccountIdentityCredentials(ctx, os.Getenv(\"AUD\"))","handlingStrategy":"validation","validationCode":"func newCredsValidated(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {\n    if strings.TrimSpace(audience) == \"\" {\n        return nil, errors.New(\"audience must be a non-empty string (the target service identifier)\")\n    }\n    return google.NewServiceAccountIdentityCredentials(ctx, audience)\n}","typeGuard":"func isAudienceValid(a string) bool { return strings.TrimSpace(a) != \"\" }","tryCatchPattern":null,"preventionTips":["Source audience from config and validate non-empty at startup.","Document the expected audience format (typically the receiving service URL/identifier).","Fail fast with a clear message if the audience env var/flag is unset."],"tags":["grpc","credentials","gcp","validation","jwt","audience"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}