Menu

Post image 1
Post image 2
Post image 3
1 / 3
0

Trusted Sources for Deployment Protection - Vercel

Vercel News·Kit Foster·4 days ago
#mvm8SCsK
#vercel#token#oidc#trusted#project#photo
Reading 0:00
15s threshold

Trusted Sources lets protected deployments accept short-lived identity tokens (OIDC) from Vercel projects and external services you authorize, so you no longer have to share a long-lived Protection Bypass for Automation secret. Trusted Sources is the recommended approach, but Protection Bypass for Automation continues to work Callers attach an OIDC token in the x-vercel-trusted-oidc-idp-token header. Vercel then verifies the signature, checks the claims you configured, and confirms the environment matches the rule. Link to heading Authorize Vercel projects By default, the Vercel OIDC token for a project can call its own deployments. To authorize another project in the same team, add it to Trusted Sources. Self-access and cross-project rules are both customizable with from / to environment pairs.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More