pub struct Credential {
pub service_account: Option<ServiceAccount>,
pub token: Option<Token>,
pub signer_email: Option<String>,
}Expand description
Credential represents Google credentials that may contain a service account, token, and provider-discovered signer identity.
IMPORTANT: This is a specially designed structure that can hold both ServiceAccount and Token simultaneously. This design is intentional and critical for Google’s authentication:
- Service account only: Used for signed URL generation and JWT-based authentication
- Token only: Used for Bearer authentication (e.g., from metadata server, OAuth2)
- Token with signer email: Also supports query signing through IAMCredentials
signBlob - Both: The RequestSigner is responsible for exchanging service account for tokens when needed, and can use cached tokens when available to avoid unnecessary exchanges
The RequestSigner implementation handles the logic of when to use which credential type and when to perform token exchanges. Discovery providers should return credentials as they receive them without trying to perform exchanges themselves. Explicit conversion providers may return a new variant, such as a token-only credential produced from a service account.
Fields§
§service_account: Option<ServiceAccount>Service account information, if available.
token: Option<Token>OAuth2 access token, if available.
signer_email: Option<String>Service account email authorized to sign with the token, if known by the provider.
This identity is used only for query signing and does not affect Bearer authentication.
Implementations§
Source§impl Credential
impl Credential
Sourcepub fn with_service_account(service_account: ServiceAccount) -> Self
pub fn with_service_account(service_account: ServiceAccount) -> Self
Create a credential with only a service account.
Sourcepub fn with_token(token: Token) -> Self
pub fn with_token(token: Token) -> Self
Create a credential with a token.
Sourcepub fn with_signer_email(self, signer_email: impl Into<String>) -> Self
pub fn with_signer_email(self, signer_email: impl Into<String>) -> Self
Set the service account email authorized to sign with this credential’s token.
This identity is used only for query signing and does not affect Bearer authentication.
Sourcepub fn has_service_account(&self) -> bool
pub fn has_service_account(&self) -> bool
Check if the credential has a service account.
Sourcepub fn has_valid_token(&self) -> bool
pub fn has_valid_token(&self) -> bool
Check if the credential has a valid token.