← Files VercelARCHIVED FILE

skills/deployments-cicd/references/oidc-federation.md

938 Bytes · Oct 6, 2026 · 18:03 UTC

↓ Download file

See the change to this file →

# OIDC Federation (Secure Backend Access)

Vercel OIDC federation is for **secure backend access** — letting your deployed Vercel functions authenticate with third-party services (AWS, GCP, HashiCorp Vault) without storing long-lived secrets. It does **not** replace `VERCEL_TOKEN` for CLI deployments.

**What OIDC does:** Your Vercel function requests a short-lived OIDC token from Vercel at runtime, then exchanges it with an external provider's STS/token endpoint for scoped credentials.

**What OIDC does not do:** Authenticate `vercel pull`/`build`/`deploy` in CI; those need a Vercel access token. Only `vcr` and Remote Cache offer CI-side OIDC exchanges.

**When to use OIDC:**
- Serverless functions that need to call AWS APIs (S3, DynamoDB, SQS)
- Functions authenticating to GCP services via Workload Identity Federation
- Any runtime service-to-service auth where you want to avoid storing static secrets in Vercel env vars

SHA-256: 8be13e948df3af0e2e53c31a39924affe52e3e7765dba18d48c4b9fc6bb87e18