Two Paths to the Same Destination: Agent Identity Federation

Both paths end with a short-lived, cloud-native credential and no long-lived secret in sight — the divergence is in the middle.
Agent needs to call a service GOOGLE WORKSPACE / GCP MICROSOFT 365 / AZURE Presents external identity token (e.g. K8s / OIDC token) Workload Identity Federation exchanges token, no stored secret Impersonates service account scoped permissions apply Presents workload credential (e.g. K8s service acct token) Entra ID federated credential exchanges token, no stored secret Managed Identity assumed scoped RBAC role applies Short-lived credential, zero secrets stored