Skip to main content
OIDC trust policies add identity verification to service accounts. When configured, a service account only works when the request includes a valid OIDC token from a trusted CI/CD provider. Even if the service token leaks, it’s useless outside the trusted environment.

How It Works

  1. You create a service account with an OIDC policy (or add one later via the dashboard)
  2. The policy specifies which CI provider and identity can use this service account
  3. At runtime, the CLI auto-detects the OIDC token from the CI environment
  4. The server validates both the service token AND the OIDC token before returning secrets
Neither credential is sufficient alone — the service token handles decryption, the OIDC token proves identity.

Setup

GitHub Actions

1

Create a service account with OIDC

Omit --branch to allow all branches. Store the service token in your repository’s secrets as RELIC_SERVICE_TOKEN.
2

Add permissions to your workflow

Your GitHub Actions workflow needs id-token: write permission:
3

Run with secrets

The OIDC token is auto-detected and sent with the request.

GitLab CI

1

Create a service account with OIDC

2

Add id_tokens to your CI config

Other Providers

For CI providers that support OIDC but aren’t auto-detected, set the RELIC_OIDC_TOKEN environment variable manually:

Managing OIDC Policies

Add via CLI (at creation time)

Or for GitLab:

Add or update via dashboard

OIDC policies can be configured from the web dashboard without re-creating the service account. Navigate to your project’s service accounts, click “Add OIDC” or “Edit OIDC”, select the provider, and enter your organization, repository, and branch.

Remove OIDC policy

To remove an OIDC policy and fall back to token-only authentication, click “Remove” in the OIDC dialog on the dashboard.

Subject Patterns

Subject patterns control which CI identities can use the service account.

Auto-Detection

The CLI automatically detects OIDC tokens in supported environments:

Security Model

  • Service token alone: authenticates + decrypts (works without OIDC)
  • Service token + OIDC: authenticates via both, decrypts with token. If OIDC is configured, both are required.
  • OIDC token alone: not sufficient — the token is for identity only, not decryption
This preserves Relic’s end-to-end encryption while adding CI identity verification. The server never sees your secrets in plaintext.
OIDC doesn’t eliminate the need for RELIC_SERVICE_TOKEN. The token is still required for client-side decryption. OIDC adds a second authentication factor that proves the request comes from a trusted CI environment.

Comparison

Last modified on May 2, 2026