Anthropic::GoogleAuth
Google Cloud authentication for the Vertex and Google Cloud clients.
Resolves a GCP access token from, in priority order:
- an explicit
access_token, - a
token_providerproc (called whenever a fresh token is needed), - Application Default Credentials:
GOOGLE_APPLICATION_CREDENTIALS(authorized_userrefresh flow), then the GCE metadata server.
Service-account (service_account) key files are not supported: the
OAuth2 JWT-bearer grant needs RS256 signing and Crystal's standard
library has no RSA signer. Pass access_token:/token_provider:, use
gcloud auth application-default login (which writes authorized_user
credentials), or run on GCP so the metadata server can mint tokens.
Constants
SCOPE = "https://www.googleapis.com/auth/cloud-platform"
TOKEN_URL = "https://oauth2.googleapis.com/token"