Two Paths to the Same Destination: Agent Identity Federation
Both paths end with a short-lived, cloud-native credential and no long-lived secret in sight — the divergence is in the middle.
Agent needs to call a service
GOOGLE WORKSPACE / GCP
MICROSOFT 365 / AZURE
Presents external identity token
(e.g. K8s / OIDC token)
Workload Identity Federation
exchanges token, no stored secret
Impersonates service account
scoped permissions apply
Presents workload credential
(e.g. K8s service acct token)
Entra ID federated credential
exchanges token, no stored secret
Managed Identity assumed
scoped RBAC role applies
Short-lived credential, zero secrets stored