{"record":{"id":"a9dfbcb8b6989341","repo":"grpc/grpc-go","slug":"credentials-ctx-cannot-be-nil","errorCode":null,"errorMessage":"credentials: ctx cannot be nil","messagePattern":"credentials: ctx cannot be nil","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"credentials/google/gcp_service_account_identity_credentials.go","lineNumber":99,"sourceCode":"// audience.\n//\n// This credential fetches the ID token from the GCE metadata server and is\n// only valid for use in environments running on GCP. The ctx and audience\n// parameters cannot be empty.\n//\n// The credentials object starts asynchronous background token fetches to\n// refresh expired tokens. The provided context propagates cancellation to\n// these background tasks. Users should not pass an RPC-scoped context here,\n// but rather a context that is valid for the entire lifetime of the\n// credentials and should cancel the context when they are done.\n//\n// # Experimental\n//\n// Notice: This API is EXPERIMENTAL and may be changed or removed in a\n// later release.\nfunc NewServiceAccountIdentityCredentials(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {\n\tif ctx == nil {\n\t\treturn nil, fmt.Errorf(\"credentials: ctx cannot be nil\")\n\t}\n\n\tif audience == \"\" {\n\t\treturn nil, fmt.Errorf(\"credentials: audience cannot be empty\")\n\t}\n\n\tcreds, err := internal.NewIDTokenCredentials(&idtoken.Options{Audience: audience})\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"credentials: failed to create ID token credentials: %v\", err)\n\t}\n\n\treturn &gcpServiceAccountIdentityCallCreds{\n\t\tctx:      ctx,\n\t\taudience: audience,\n\t\tcreds:    creds,\n\t\tbackoff:  internal.BackoffStrategy,\n\t}, nil\n}","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/credentials/google/gcp_service_account_identity_credentials.go#L81-L117","documentation":"Returned by google.NewServiceAccountIdentityCredentials when the ctx argument is nil. The constructor stores ctx to drive background token fetches for the credential's lifetime, so a nil context would panic later; the function validates upfront and returns this error instead.","triggerScenarios":"Calling google.NewServiceAccountIdentityCredentials(nil, \"audience\"). The check at gcp_service_account_identity_credentials.go:98-100 returns the error immediately before any GCP/metadata interaction.","commonSituations":"Passing nil by mistake (e.g. a variable that was never initialized); refactoring that removed the context parameter sourcing; tests that construct credentials without setting up a context; code that assumed a default background context would be used (it is not — you must pass context.Background() explicitly).","solutions":["Pass a non-cancellation context scoped to the credential's lifetime, e.g. context.Background() or a context you cancel on shutdown.","Do not pass an RPC-scoped context (the doc explicitly warns against it); use a long-lived context.","Add a unit test asserting ctx != nil before calling the constructor."],"exampleFix":"// before\ncreds, err := google.NewServiceAccountIdentityCredentials(nil, aud) // error\n\n// after\nctx, cancel := context.WithCancel(context.Background())\ndefer cancel()\ncreds, err := google.NewServiceAccountIdentityCredentials(ctx, aud)","handlingStrategy":"validation","validationCode":"func newCredsSafe(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {\n    if ctx == nil {\n        ctx = context.Background() // or return an explicit error\n    }\n    return google.NewServiceAccountIdentityCredentials(ctx, audience)\n}","typeGuard":"func isContextValid(ctx context.Context) bool { return ctx != nil }","tryCatchPattern":null,"preventionTips":["Always pass a long-lived, non-nil context (e.g. context.Background() with cancel).","Do not pass RPC-scoped contexts; the credential outlives any single RPC.","Add a startup assertion that the context variable is initialized before constructing credentials."],"tags":["grpc","credentials","gcp","validation","nil-context","api-misuse"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}