{"record":{"id":"8b517638ee211c95","repo":"grpc/grpc-go","slug":"credentials-failed-to-create-id-token-credentials","errorCode":null,"errorMessage":"credentials: failed to create ID token credentials: %v","messagePattern":"credentials: failed to create ID token credentials: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/google/gcp_service_account_identity_credentials.go","lineNumber":108,"sourceCode":"// but rather a context that is valid for the entire lifetime of the\n// credentials and should cancel the context when they are done.\n//\n// # Experimental\n//\n// Notice: This API is EXPERIMENTAL and may be changed or removed in a\n// later release.\nfunc NewServiceAccountIdentityCredentials(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {\n\tif ctx == nil {\n\t\treturn nil, fmt.Errorf(\"credentials: ctx cannot be nil\")\n\t}\n\n\tif audience == \"\" {\n\t\treturn nil, fmt.Errorf(\"credentials: audience cannot be empty\")\n\t}\n\n\tcreds, err := internal.NewIDTokenCredentials(&idtoken.Options{Audience: audience})\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"credentials: failed to create ID token credentials: %v\", err)\n\t}\n\n\treturn &gcpServiceAccountIdentityCallCreds{\n\t\tctx:      ctx,\n\t\taudience: audience,\n\t\tcreds:    creds,\n\t\tbackoff:  internal.BackoffStrategy,\n\t}, nil\n}\n\n// GetRequestMetadata gets the current request metadata, refreshing tokens if\n// required. This implementation follows the PerRPCCredentials interface.\n//\n// It guarantees that only one underlying token fetch will be executed\n// concurrently. If a valid token is cached, it is returned immediately. If\n// a fetch recently failed, the cached error is returned until the backoff\n// interval expires. Otherwise, it initiates a new token fetch or blocks\n// waiting for an already-in-progress fetch to complete.","sourceCodeStart":90,"sourceCodeEnd":126,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/google/gcp_service_account_identity_credentials.go#L90-L126","documentation":"Returned by NewServiceAccountIdentityCredentials when the underlying cloud.google.com/go/auth/credentials/idtoken.NewCredentials call fails to build an ID-token credential from the supplied audience. The wrapper preserves the root cause (e.g. malformed audience, missing/unreachable metadata server, invalid ADC) in the trailing %v. This credential type is only valid inside GCP, so the failure often reflects an environment mismatch rather than a programming error.","triggerScenarios":"Calling google.NewServiceAccountIdentityCredentials(ctx, audience) outside of a GCP environment (no metadata server reachable at 169.254.169.254), passing a malformed audience string, or running with a broken/old google-auth library whose idtoken.NewCredentials returns a non-nil error at line 106-108.","commonSituations":"Running the binary locally or in a non-GCP CI worker where the GCE metadata server is unavailable; using an audience URL that does not match the target service's allowed audiences; pinning an incompatible cloud.google.com/go/auth version that changed the idtoken.Options contract.","solutions":["Verify the process runs on a GCE/GKE/Cloud Run/Flex App Engine instance where the metadata server is reachable (curl http://169.254.169.254).","Confirm the audience string matches the intended target service's configured audience exactly (URL form, no trailing slash differences).","Upgrade cloud.google.com/go/auth and google.golang.org/grpc to compatible versions and run go mod tidy.","Inspect the wrapped error after the colon for the idtoken-specific root cause and address that directly."],"exampleFix":"// before\ncreds, err := google.NewServiceAccountIdentityCredentials(context.Background(), \"\")\n// after\ncreds, err := google.NewServiceAccountIdentityCredentials(ctx, \"https://my-service-1234-uc.a.run.app\")\nif err != nil {\n    return fmt.Errorf(\"build id-token creds: %w\", err)\n}","handlingStrategy":"validation","validationCode":"// Before calling NewServiceAccountIdentityCredentials, confirm the\n// environment is GCP and the audience is well-formed.\nfunc isOnGCP() bool {\n    ctx, cancel := context.WithTimeout(context.Background(), 2*time.Second)\n    defer cancel()\n    _, err := metadata.GetWithContext(ctx, \"instance/service-accounts/default/email\")\n    return err == nil\n}\n\nfunc validAudience(a string) bool {\n    u, err := url.Parse(a)\n    return err == nil && u.Scheme == \"https\" && u.Host != \"\"\n}\n\nif !isOnGCP() {\n    log.Fatal(\"NewServiceAccountIdentityCredentials requires a GCP environment\")\n}\nif !validAudience(audience) {\n    log.Fatalf(\"invalid audience %q\", audience)\n}","typeGuard":null,"tryCatchPattern":"creds, err := google.NewServiceAccountIdentityCredentials(ctx, audience)\nif err != nil {\n    return fmt.Errorf(\"id-token credential setup failed (are you on GCP? audience=%q): %w\", audience, err)\n}","preventionTips":["Gate construction behind a GCP-environment check (metadata server probe).","Validate the audience URL format before passing it in.","Keep cloud.google.com/go/auth and grpc versions aligned via go mod tidy."],"tags":["grpc","gcp","authentication","id-token","credentials"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}