{"repo":"astral-sh/ambient-id","free":true,"listed":false,"github":"https://github.com/astral-sh/ambient-id","clone":"git clone https://github.com/astral-sh/ambient-id.git","description":"A library for accessing ambient OpenID Connect tokens","language":"Rust","stars":11,"topics":["authentication","github-actions","gitlab-ci","oidc"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"ambient-id A library for accessing ambient OIDC credentials in a variety of environments. This crate serves the same purpose as Python's [id] library. Supported environments ambient-id currently supports ambient OIDC credential detection in the following environments: GitHub Actions - GitHub Actions requires the id-token: write permission to be set at the job or workflow level. In general, users should set this at the job level to limit the scope of the permission. For additional information on OpenID Connect in GitHub Actions, see the [GitHub documentation]. GitLab CI - On GitLab, this crate looks for an ID TOKEN environment variable, where is the audience string with non-alphanumeric characters replaced by underscores and converted to uppercase. For example, if the audience is sigstore , the crate will look for a SIGSTORE ID TOKEN environment variable. For additional information on OpenID Connect and ID TOKEN environment variables, see the [GitLab documentation]. Buildkite - On Buildkite, this crate invokes buildkite-agent oidc request-token --audience to obtain the token. If you're using Buildkite's [Docker plugin], you'll need to propagate the environment and mount the Buildkite agent binary into the container for this to work correctly. Specifically, you'll need propagate-environment: true and mount-buildkite-agent: true set in your plugin configuration. For additional information on OpenID Connect in Buildkite, see the [Buildkite documentation]. CircleCI - On CircleCI, ","default_branch":null,"files":null,"tree":[],"storefront":"/r/astral-sh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/astral-sh/ambient-id/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}