# GitHub Actions google-github-actions/auth workload identity audience error

> Fix google-github-actions/auth workload identity failures - the OIDC token audience, provider, or subject does not match the Workload Identity Federation configuration.

Source: https://latchkey.dev/learn/github-actions/google-auth-workload-identity-audience  
Updated: 2026-06-26

google-github-actions/auth federates the GitHub OIDC token into Google Cloud via Workload Identity Federation. The provider must accept the token audience and the attribute condition must match the repository, or the exchange is denied.

## Diagnose it: what token do you actually have?

Permission failures in Actions are almost never about your repository settings alone. Three things combine: the default `GITHUB_TOKEN` permission set for the repo or organization, the `permissions:` block in the workflow, and whether the event is a fork pull request, which downgrades the token to read-only regardless of everything else.

```.github/workflows/ci.yml
- name: Show the token scopes actually granted
  run: |
    curl -sI -H "Authorization: Bearer $GITHUB_TOKEN" \
      https://api.github.com/ | grep -i "^x-oauth-scopes\|^x-accepted"
    echo "event: ${{ github.event_name }}"
    echo "fork PR: ${{ github.event.pull_request.head.repo.fork }}"
  env:
    GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
```

> If `fork PR` prints `true`, stop looking at `permissions:`. A fork pull request gets a read-only token by design, and no workflow-level grant can raise it.

## Grant the narrowest permission that works

Declaring a `permissions:` block switches the job from the repository default to exactly what you list, so an incomplete block is a common cause of a new failure right after someone tightened security. List every scope the job needs, not just the one that failed.

```.github/workflows/ci.yml
permissions:
  contents: read        # checkout
  packages: write       # push to GHCR
  id-token: write       # OIDC to a cloud provider
  pull-requests: write  # comment on or label a PR
  checks: write         # publish check runs
```

> Set `permissions` at the job level rather than the workflow level where you can. A workflow-level grant applies to every job, including ones that only run tests.

## FAQ

### What causes GitHub Actions google-github-actions/auth workload identity audience error?

There are 2 common causes: audience mismatch or missing id-token permission and attribute condition rejects the repo. The provider expects a specific audience and the job needs id-token: write to mint a token with it.

### How do I fix GitHub Actions google-github-actions/auth workload identity audience error?

Align audience, permission, and attribute condition. Add permissions: id-token: write.

### What does GitHub Actions google-github-actions/auth workload identity audience error actually mean?

An auth step using workload_identity_provider fails acquiring credentials, citing audience, attribute condition, or the id-token permission.

### How do I stop GitHub Actions google-github-actions/auth workload identity audience error happening again?

Set id-token: write for every GCP OIDC job. The prevention section lists 2 changes that keep it from recurring.

---

Latchkey runs CI/CD that repairs its own failures. Agent entry points: https://latchkey.dev/agent.txt, https://latchkey.dev/openapi.json, https://latchkey.dev/llms.txt
