Skip to content
Latchkey

GitHub Actions google-github-actions/auth workload identity audience error

google-github-actions/auth federates the GitHub OIDC token into Google Cloud via Workload Identity Federation. The provider must accept the token audience and the attribute condition must match the repository, or the exchange is denied.

What this error means

An auth step using workload_identity_provider fails acquiring credentials, citing audience, attribute condition, or the id-token permission.

github-actions
Error: google-github-actions/auth failed with: failed to generate Google Cloud
federated token for //iam.googleapis.com/projects/.../providers/github:
the audience in the ID token does not match

Diagnose it: what token do you actually have?

Permission failures in Actions are almost never about your repository settings alone. Three things combine: the default GITHUB_TOKEN permission set for the repo or organization, the permissions: block in the workflow, and whether the event is a fork pull request, which downgrades the token to read-only regardless of everything else.

.github/workflows/ci.yml
- name: Show the token scopes actually granted
  run: |
    curl -sI -H "Authorization: Bearer $GITHUB_TOKEN" \
      https://api.github.com/ | grep -i "^x-oauth-scopes\|^x-accepted"
    echo "event: ${{ github.event_name }}"
    echo "fork PR: ${{ github.event.pull_request.head.repo.fork }}"
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

Common causes

Audience mismatch or missing id-token permission

The provider expects a specific audience and the job needs id-token: write to mint a token with it.

Attribute condition rejects the repo

The WIF provider attribute-condition (e.g. assertion.repository) does not match the calling repository.

How to fix it

Align audience, permission, and attribute condition

  1. Add permissions: id-token: write.
  2. Set workload_identity_provider and service_account to the configured WIF resources.
  3. Make the provider attribute-condition match your repository/owner.
.github/workflows/ci.yml
permissions:
  id-token: write
steps:
  - uses: google-github-actions/auth@v2
    with:
      workload_identity_provider: projects/123/locations/global/workloadIdentityPools/gh/providers/github
      service_account: ci@project.iam.gserviceaccount.com

Grant the narrowest permission that works

Declaring a permissions: block switches the job from the repository default to exactly what you list, so an incomplete block is a common cause of a new failure right after someone tightened security. List every scope the job needs, not just the one that failed.

.github/workflows/ci.yml
permissions:
  contents: read        # checkout
  packages: write       # push to GHCR
  id-token: write       # OIDC to a cloud provider
  pull-requests: write  # comment on or label a PR
  checks: write         # publish check runs

How to prevent it

  • Set id-token: write for every GCP OIDC job.
  • Keep the WIF attribute condition scoped to your repo/owner.

Frequently asked questions

What causes GitHub Actions google-github-actions/auth workload identity audience error?
There are 2 common causes: audience mismatch or missing id-token permission and attribute condition rejects the repo. The provider expects a specific audience and the job needs id-token: write to mint a token with it.
How do I fix GitHub Actions google-github-actions/auth workload identity audience error?
Align audience, permission, and attribute condition. Add permissions: id-token: write.
What does GitHub Actions google-github-actions/auth workload identity audience error actually mean?
An auth step using workload_identity_provider fails acquiring credentials, citing audience, attribute condition, or the id-token permission.
How do I stop GitHub Actions google-github-actions/auth workload identity audience error happening again?
Set id-token: write for every GCP OIDC job. The prevention section lists 2 changes that keep it from recurring.

Related guides

References

Not every red build is your code. Latchkey repairs the ones that are not, on the runner. Start free → 30-day trial · No credit card