Google Cloud
Google Cloud services that accept OAuth 2.0 bearer tokens, plus V4 signed URLs for Cloud Storage.
Bearer tokens sign headers; expires_in selects V4 signed URLs for Cloud Storage.
Get started
cargo add reqsign --features google
use reqsign::google;
// Service account files, workload identity federation, VM metadata —
// resolved by the default chain.
let signer = google::default_signer("storage.googleapis.com");
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://storage.googleapis.com/my-bucket/my-object")
.body(())?
.into_parts()
.0;
// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;
Credentials
Default credential chain
The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:
- Application Default Credentials from GOOGLE_APPLICATION_CREDENTIALS
- Well-known gcloud ADC file
- VM metadata server
Credential providers
Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:
EnvCredentialProvider— Application Default Credentials from GOOGLE_APPLICATION_CREDENTIALSWellKnownCredentialProvider— Well-known gcloud ADC fileVmMetadataCredentialProvider— VM metadata serverStaticCredentialProvider— Static service account JSONFileCredentialProvider— Credential file at a fixed pathTokenCredentialProvider— Pre-issued OAuth2 tokenAuthorizedUserCredentialProvider— Authorized user (gcloud) credentialsExternalAccountCredentialProvider— External account (workload identity federation)ImpersonatedServiceAccountCredentialProvider— Service account impersonationServiceAccountTokenCredentialProvider— OAuth2 token from a service account key or impersonation
Credential granting
This provider can exchange credentials for downscoped ones before any request is signed — see Granting scoped access:
- Credential Access Boundary (server-side) — Exchanges a token through the STS API for one downscoped by an access boundary.
- Credential Access Boundary (client-side) — Derives a downscoped token locally without a round-trip to the STS API. Requires the google-credential-access-boundary-client-side facade feature.