Skip to content

docs(auth): clarify quota project behavior on ImpersonatedCredentials - #14597

Open
lqiu96 wants to merge 2 commits into
mainfrom
docs-auth-impersonated-quota-project-12604
Open

lqiu96 wants to merge 2 commits into
mainfrom
docs-auth-impersonated-quota-project-12604

Conversation

@lqiu96

@lqiu96 lqiu96 commented Oct 7, 2026

Copy link
Copy Markdown
Member

Fixes #12604

Summary

Clarifies the Javadoc on ImpersonatedCredentials (Builder.setQuotaProjectId, idTokenWithAudience, and create overloads) regarding how quotaProjectId is applied:

  • The quotaProjectId configured on ImpersonatedCredentials is sent via the x-goog-user-project header on downstream API requests authenticated with the impersonated credentials.
  • Requests to the IAM Credentials API (generateAccessToken and generateIdToken) used to mint tokens are authenticated using sourceCredentials. To specify a quota project (x-goog-user-project header) for those IAM Credentials API calls, the quota project ID should be configured on sourceCredentials.

@lqiu96
lqiu96 requested review from a team as code owners October 7, 2026 19:49

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the Javadoc documentation in ImpersonatedCredentials.java to clarify the behavior of the quotaProjectId parameter and builder method. Specifically, it explains that the quota project ID is applied to downstream requests made with the impersonated credentials, but not to the IAM Credentials API requests (such as generateAccessToken or generateIdToken) used to mint tokens. To set a quota project for those token-minting calls, users must configure it on the sourceCredentials instead. Additionally, a minor typo in the documentation was corrected. There are no review comments, and I have no further feedback to provide.

@lqiu96
lqiu96 enabled auto-merge (squash) October 7, 2026 23:50

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[google-auth-library-java] Generating ID token with ImpersonatedCredentials does not support overriding quota project

2 participants