module

Anthropic::GoogleAuth

Google Cloud authentication for the Vertex and Google Cloud clients.

Resolves a GCP access token from, in priority order:

  1. an explicit access_token,
  2. a token_provider proc (called whenever a fresh token is needed),
  3. Application Default Credentials: GOOGLE_APPLICATION_CREDENTIALS (authorized_user refresh flow), then the GCE metadata server.

Service-account (service_account) key files are not supported: the OAuth2 JWT-bearer grant needs RS256 signing and Crystal's standard library has no RSA signer. Pass access_token:/token_provider:, use gcloud auth application-default login (which writes authorized_user credentials), or run on GCP so the metadata server can mint tokens.

Constants

SCOPE = "https://www.googleapis.com/auth/cloud-platform"
TOKEN_URL = "https://oauth2.googleapis.com/token"

Nested types