// the find
salrashid123/google_id_token
Authenticating using Google OpenID Connect Tokens
A reference repo explaining how Google-issued OpenID Connect id_tokens work and how to obtain/verify them, with minimal sample snippets in Python, Java, Go, Node.js, .NET, and C. It's aimed at developers securing Cloud Run, Cloud Functions, or IAP-protected services who need to understand the id_token vs access_token distinction rather than pull in a library.
The explanation of id_token vs access_token and the aud/target_audience mechanics is clearer than Google's own docs, including the service-account-JSON-exchange flow and the metadata-server shortcut. It covers the less-obvious paths too: IAMCredentials generateIdToken(), Workload Identity Federation, and the OIDC tokens embedded in Cloud Scheduler/Tasks/Pub-Sub webhooks. It consolidates JWK and x509 endpoints for Google, Firebase/Identity Platform, and IAP in one place, which otherwise takes digging through separate docs pages.
This isn't a library — each language folder is a single throwaway script, so you're copy-pasting and adapting rather than importing something maintained; the README even disclaims support. Last commit is October 2023, so two years stale against a space (GCP auth libraries, IAM APIs) that shifts fairly often, and nothing indicates the samples still match current library APIs. No tests or CI across any of the six language samples, so there's no signal whether they even still run. The 'Language: C' classification and the cc sample pointing to an open GitHub issue rather than documented usage suggest that path is the least maintained of the bunch.