grpc/grpc-go · error
credentials: audience cannot be empty
Error message
credentials: audience cannot be empty
What it means
Returned by google.NewServiceAccountIdentityCredentials when the audience argument is an empty string. The audience is the intended recipient of the ID-token JWT; without it the token has no valid target and the metadata-server fetch would be meaningless, so the constructor rejects it upfront.
Solutions
- Provide a non-empty audience string (typically the URL/identifier of the receiving service, e.g. "https://my-service.example.com").
- Source the audience from configuration and validate it is non-empty before calling the constructor.
- Add a startup check: if audience == "" { log.Fatal("audience required") }.
Example fix
// before
creds, err := google.NewServiceAccountIdentityCredentials(ctx, os.Getenv("AUD")) // empty -> error
// after
if aud := os.Getenv("AUD"); aud == "" {
log.Fatal("AUD env var (token audience) must be set")
}
creds, err := google.NewServiceAccountIdentityCredentials(ctx, os.Getenv("AUD")) Defensive patterns
Strategy: validation
Validate before calling
func newCredsValidated(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {
if strings.TrimSpace(audience) == "" {
return nil, errors.New("audience must be a non-empty string (the target service identifier)")
}
return google.NewServiceAccountIdentityCredentials(ctx, audience)
} Type guard
func isAudienceValid(a string) bool { return strings.TrimSpace(a) != "" } Prevention
- Source audience from config and validate non-empty at startup.
- Document the expected audience format (typically the receiving service URL/identifier).
- Fail fast with a clear message if the audience env var/flag is unset.
When it happens
Trigger: Calling google.NewServiceAccountIdentityCredentials(ctx, "") or with a variable that resolved to empty. The check at gcp_service_account_identity_credentials.go:102-104 returns immediately.
Common situations: Audience sourced from an unset config flag/env var/secret; a typo or empty default; refactoring that dropped the audience plumbing; misreading the API and assuming a default audience would be inferred (it is not).
Related errors
- credentials: ctx cannot be nil
- no expiration claims
- token file
- cannot send secure credentials on an insecure connection
- credentials: failed to create ID token credentials
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/7245ad24ea7f51b7.
Report an issue: GitHub.
Appendix: source
Thrown at credentials/google/gcp_service_account_identity_credentials.go:103
// parameters cannot be empty.
//
// The credentials object starts asynchronous background token fetches to
// refresh expired tokens. The provided context propagates cancellation to
// these background tasks. Users should not pass an RPC-scoped context here,
// but rather a context that is valid for the entire lifetime of the
// credentials and should cancel the context when they are done.
//
// # Experimental
//
// Notice: This API is EXPERIMENTAL and may be changed or removed in a
// later release.
func NewServiceAccountIdentityCredentials(ctx context.Context, audience string) (credentials.PerRPCCredentials, error) {
if ctx == nil {
return nil, fmt.Errorf("credentials: ctx cannot be nil")
}
if audience == "" {
return nil, fmt.Errorf("credentials: audience cannot be empty")
}
creds, err := internal.NewIDTokenCredentials(&idtoken.Options{Audience: audience})
if err != nil {
return nil, fmt.Errorf("credentials: failed to create ID token credentials: %v", err)
}
return &gcpServiceAccountIdentityCallCreds{
ctx: ctx,
audience: audience,
creds: creds,
backoff: internal.BackoffStrategy,
}, nil
}
// GetRequestMetadata gets the current request metadata, refreshing tokens if
// required. This implementation follows the PerRPCCredentials interface.
//View on GitHub (pinned to 0c51461d27)