Skip to content

Credentials & Identity Federation

Guides for authenticating pipelines to external services using Concourse-issued JWTs (the idtoken var source) instead of storing long-lived secrets. For general credential management — Vault, AWS Secrets Manager, and other cluster-wide credential managers — see Credential Management in the Docs.

  • Authenticating to Vault via IDToken


    Let a pipeline log in to Vault directly, beyond what Concourse's native Vault integration offers.

    View guide

  • Authenticating to AWS via IDToken


    Assume an IAM role from a pipeline without managing IAM users or long-lived access keys.

    View guide

  • Authenticating to Azure via IDToken


    Log in to Azure from a pipeline using a federated credential.

    View guide

  • Authenticating to GCP via IDToken


    Impersonate a GCP service account from a pipeline using workload identity federation.

    View guide

For details on JWT claims, key rotation, and the subject_scope setting, see the IDToken credential manager reference page.