Dev Tools · 17h ago
Vercel Adds Custom OIDC Token Audiences for Secure Service Auth
Vercel's OIDC issuer now supports custom audiences, allowing deployments to request tokens with a specific audience claim for secure service-to-service authentication. The exchange service mints provider-specific tokens without additional infrastructure, preserving original claims and adding an auditable delegation chain. This prevents token replay attacks if a provider is compromised, as mismatched audience claims cause verification to fail.
Meridian48 take
A practical security upgrade for Vercel users, but its value depends on adoption of OIDC-based workflows; for most, the fixed audience may suffice.
verceloidc-authentication