diff --git a/google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/ComputeEngineCredentials.java b/google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/ComputeEngineCredentials.java index 686c5389d5e3..4d6fa3de136a 100644 --- a/google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/ComputeEngineCredentials.java +++ b/google-auth-library-java/oauth2_http/java/com/google/auth/oauth2/ComputeEngineCredentials.java @@ -81,7 +81,11 @@ /** * OAuth2 credentials representing the built-in service account for a Google Compute Engine VM. * - *
Fetches access tokens from the Google Compute Engine metadata server. + *
Fetches access tokens from the Google Compute Engine metadata server. When a workload + * certificate for an agent identity is available, requests certificate-bound access tokens and ID + * tokens by default (see {@code IdTokenProvider.Option.DISABLE_BOUND_ID_TOKEN} and the Google + * Auth Library guide). * *
These credentials use the IAM API to sign data. See {@link #sign(byte[])} for more details. */