Skip to main content

Google Cloud

Google Cloud services that accept OAuth 2.0 bearer tokens, plus V4 signed URLs for Cloud Storage.

OAuth 2.0 bearer tokenV4 signed URLs✓ header signing✓ query / presign— WASMdocs.rs/reqsign-google ↗

Bearer tokens sign headers; expires_in selects V4 signed URLs for Cloud Storage.

Get started​

cargo add reqsign --features google
use reqsign::google;

// Service account files, workload identity federation, VM metadata —
// resolved by the default chain.
let signer = google::default_signer("storage.googleapis.com");

let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://storage.googleapis.com/my-bucket/my-object")
.body(())?
.into_parts()
.0;

// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;

Credentials

Default credential chain

The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:

  1. Application Default Credentials from GOOGLE_APPLICATION_CREDENTIALS
  2. Well-known gcloud ADC file
  3. VM metadata server

Credential providers

Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:

Credential granting

This provider can exchange credentials for downscoped ones before any request is signed — see Granting scoped access:

  • Credential Access Boundary (server-side) — Exchanges a token through the STS API for one downscoped by an access boundary.
  • Credential Access Boundary (client-side) — Derives a downscoped token locally without a round-trip to the STS API. Requires the google-credential-access-boundary-client-side facade feature.