{"repo":"riptideslabs/tokenex","free":true,"listed":false,"github":"https://github.com/riptideslabs/tokenex","clone":"git clone https://github.com/riptideslabs/tokenex.git","description":"Tokenex is a Go library that securely exchanges identity tokens for temporary cloud credentials, with built-in support for AWS, GCP, Azure, OCI, Kubernetes, and OAuth2.","language":"Go","stars":84,"topics":["aws","azure","gcp","oauth2","oci"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Tokenex - Cloud Credentials Provider Library This library provides a unified interface for obtaining and refreshing credentials from various cloud providers and authentication systems. It is designed to facilitate secure access to cloud resources by exchanging identity tokens for temporary credentials. Related Blog Posts Introducing tokenex: an open source Go library for fetching and refreshing credentials tokenex adds Vault & OpenBao support: Exchanging ID tokens (JWTs) for secrets without static credentials Supplying short-lived OpenAI API keys to AI agents with Riptides Secretless Azure access with tokenex: Federated Identity via User-Assigned Managed Identity --- Table of Contents Features Installation Usage Common Setup AWS Provider GCP Provider Azure Provider OCI Provider Generic Provider K8sSecret Provider OAuth2 Authorization Code OAuth2 Client Credentials Vault Provider GitHub App Provider Channel Behavior License Contributing --- Features - AWS: Exchanges ID tokens for AWS temporary session credentials using AWS's Workload Identity Federation - GCP: Exchanges ID tokens for GCP access tokens using GCP's Workload Identity Federation - Azure: Exchanges ID tokens for Azure access tokens using Microsoft Entra ID's Workload Identity Federation - OCI: Exchanges ID tokens for OCI User Principal Session Tokens (UPST) using OCI's Workload Identity Federation - Generic: Simply returns the token provided by the identity token provider and refreshes it before expiration - K8sSec","default_branch":null,"files":null,"tree":[],"storefront":"/r/riptideslabs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/riptideslabs/tokenex/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}