How It Works
- You create a service account with an OIDC policy (or add one later via the dashboard)
- The policy specifies which CI provider and identity can use this service account
- At runtime, the CLI auto-detects the OIDC token from the CI environment
- The server validates both the service token AND the OIDC token before returning secrets
Setup
GitHub Actions
1
Create a service account with OIDC
--branch to allow all branches. Store the service token in your repository’s secrets as RELIC_SERVICE_TOKEN.2
Add permissions to your workflow
Your GitHub Actions workflow needs
id-token: write permission:3
Run with secrets
GitLab CI
1
Create a service account with OIDC
2
Add id_tokens to your CI config
Other Providers
For CI providers that support OIDC but aren’t auto-detected, set theRELIC_OIDC_TOKEN environment variable manually:
Managing OIDC Policies
Add via CLI (at creation time)
Add or update via dashboard
OIDC policies can be configured from the web dashboard without re-creating the service account. Navigate to your project’s service accounts, click “Add OIDC” or “Edit OIDC”, select the provider, and enter your organization, repository, and branch.Remove OIDC policy
To remove an OIDC policy and fall back to token-only authentication, click “Remove” in the OIDC dialog on the dashboard.Subject Patterns
Subject patterns control which CI identities can use the service account.Auto-Detection
The CLI automatically detects OIDC tokens in supported environments:Security Model
- Service token alone: authenticates + decrypts (works without OIDC)
- Service token + OIDC: authenticates via both, decrypts with token. If OIDC is configured, both are required.
- OIDC token alone: not sufficient — the token is for identity only, not decryption