Skip to content

DEVSDK-3242: Workload Identity Federation - GCP pilot, private preview - #1991

Open
mark-kogan-stripe wants to merge 8 commits into
private-previewfrom
Oauth-GCP-Separate-Packages
Open

mark-kogan-stripe wants to merge 8 commits into
private-previewfrom
Oauth-GCP-Separate-Packages

Conversation

@mark-kogan-stripe

@mark-kogan-stripe mark-kogan-stripe commented Oct 5, 2026 •

Copy link
Copy Markdown

Why?

This PR introduces an alternate way to create a top-level Stripe client, authenticated via GCP instead of a long-lived API key. Rather than relying on a semi-permanent secret that can be leaked or mismanaged, the SDK fetches a short-lived token backed by a public key and the guarantee that the code is running on genuine cloud provider hardware.

The change adds a separate adapter package within this repo that uses the GCECredentials SDK to build an assertion function capable of retrieving web identity tokens. The core stripe package then uses that assertion function to mint an ephemeral key, refreshing it proactively and also on a single 401 as a fallback, for the lifetime of the session. Once constructed, the resulting Stripe client behaves identically to a standard one.

What?

  • Creates an independent package under gcp-workload-identity
  • Adds gcp-workload-identity/lib/stripe/gcp_workload_identity.rb, which uses the GCECredentials SDK to export GcpWorkloadIdentity()
  • Adds necessary package-related files to expose an independent package (Gemfile, LICENSE, .gemspec)
  • Updates api_requestor.rb to support authenticating via a function instead of an API key, and enables a single 401 retry (independent of normal network retries) for Workload Identity authenticators
  • Introduces a new error type for failures arising from the Workload Identity process
  • Updates StripeClient by introducing an alternate constructor, for_workload_identity, which passes the Workload Identity authenticator into the Stripe initializer
  • Adds lib/stripe/workload_identity.rb containing core logic for validating assertion inputs to the core Stripe package, performing proactive refreshes, caching ephemeral tokens in a thread-safe manner, and sanitizing error outputs to avoid exposing assertions
  • Adds unit tests in the core package for Workload Identity processes

See Also

Original Project Context

Configuration

  • skip-changefile: This PR is not a user-facing change, so there's no changefile.

@mark-kogan-stripe
mark-kogan-stripe marked this pull request as ready for review October 7, 2026 15:31
@mark-kogan-stripe
mark-kogan-stripe requested a review from a team as a code owner October 7, 2026 15:32
@mark-kogan-stripe
mark-kogan-stripe requested review from jar-stripe and removed request for a team October 7, 2026 15:32
@mark-kogan-stripe
mark-kogan-stripe force-pushed the Oauth-GCP-Separate-Packages branch from cbc9b4a to 73cc08f Compare October 7, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant