OIDC token request failed or token invalid
April 30, 2026 ยท View on GitHub
Playbook ID: oidc-token-failure
Category: auth
Severity: high
Tags: oidc, jwt, token, federated, aws, gcp, azure, github-actions
What this failure means
An OIDC token request failed or the issued token was rejected by the cloud provider. Federated authentication to AWS, GCP, or Azure cannot proceed.
Common log signals
OIDC token
Unable to get OIDC token
invalid_token
JWT validation
Invalid JWT
JWT verification failed
JWT expired
JWT signature
Diagnosis
An OIDC token request failed or the issued token was rejected by the cloud provider. Federated authentication to AWS, GCP, or Azure cannot proceed.
Fix steps
- In GitHub Actions, ensure the job has
permissions: id-token: write. - Decode the OIDC token and inspect
iss,sub,aud, and repository claims to confirm they match the cloud-side trust policy. - For AWS, verify the IAM role trust policy
StringLikecondition matches the actualsubclaim. - For GCP, check the Workload Identity Pool provider attribute mapping and condition logic.
- For Azure, confirm the federated credential issuer, subject, and audience are correct.
- For token audience mismatch errors, set the expected audience explicitly in the workflow step or provider configuration.
Validation
- Re-run the failing workflow step with debug logging enabled.
- Confirm
ACTIONS_ID_TOKEN_REQUEST_URLis present when the workflow expects GitHub-issued OIDC.
Likely files to inspect
.github/workflows/.gitlab-ci.yml
Run Faultline
faultline analyze build.log
faultline explain oidc-token-failure
faultline workflow build.log --json --mode agent
Search phrases this page answers
- OIDC token request failed or token invalid
- Auth: oidc token request failed or token invalid
- Error getting token from GitHub's OIDC provider
- GitHub Actions oidc token request failed or token invalid
- faultline explain oidc-token-failure
Generated from playbooks/bundled/log/auth/oidc-token-failure.yaml. Do not edit directly โ run make docs-generate.