Workload Identity Federation
Workload identity federation lets a workload authenticate to a cloud provider by presenting a short-lived token from an identity provider it already has, such as a CI/CD system or a Kubernetes cluster, instead of storing a long-lived secret or access key.
The workload obtains a signed OIDC token from its own platform (for example, the token GitHub Actions issues to each job), and the cloud validates the token's issuer, subject and audience against a trust configuration before exchanging it for temporary credentials. AWS supports this through IAM OIDC identity providers, Google Cloud through Workload Identity Federation, and Microsoft Entra through federated identity credentials on app registrations and managed identities. It removes the stored secret that leaks into repositories and tickets, which is the most common way cloud workloads are compromised. The main mistake is a trust condition that is too broad, such as accepting any branch or any repository in an organization, which lets an attacker who can run a job anywhere in scope assume the role.
See also: workload identity, token exchange, SPIFFE, secrets in repositories and CI
Related on Start with Identity
- GlossaryAgentic Identity
Identity for autonomous AI agents that act on a user's behalf, call APIs, and chain tools. Requires scoped, delegated, auditable, and revocable credentials rath
- GlossaryNon-Human Identity (NHI)
Any identity that is not a person: service accounts, API keys, OAuth tokens, certificates, workloads, and AI agents. NHIs now outnumber human identities in most
- GlossaryService Principal
A service principal is the identity an application or automated workload uses to sign in to Microsoft Entra ID and access Azure or Microsoft Graph resources: th
- RankingBest Machine Identity for Startups: Top 5 Secrets & Workload Tools
The best machine identity tools for startups in 2026: Infisical, Doppler, HashiCorp Vault, Akeyless, and SPIFFE/SPIRE. Ranked for developer experience, pricing,
- TechniqueFederation trust abuse and SAML forgery
A service provider that accepts a SAML assertion it should have rejected treats a forged identity as authenticated, because the failure sits in signature valida
- GuideIdentity Federation Implementation Guide: Protocols, Trust, and Cross-Domain SSO
A step-by-step guide to implementing identity federation covering SAML, OIDC, and WS-Federation protocols, trust relationship configuration, attribute mapping,