Skip to content

The GCP Identity Token Trust Provider verifies the identities of workloads running within Google Cloud Platform (GCP) by validating identity tokens issued by GCP. These tokens carry metadata, such as the email associated with the service account or user executing the operation, ensuring secure and authenticated access to GCP resources.

To validate the user identity that Google Cloud Identity-Aware Proxy (IAP) asserts for workloads behind IAP, see GCP IAP JWT Trust Provider.

The following match rule is available for this Trust Provider type:

DataDescriptionExample
emailThe email associated with the GCP service account or useruser@example.com

For additional information about GCP Identity Tokens, see Google Cloud Identity.