megachangelog
Feature

Custom OIDC Token Audiences

Vercel's OIDC issuer now supports custom audience claims, allowing deployments to request tokens with specific audiences for secure service-to-service authentication. This enables security best practices by minting provider-specific tokens without managing additional infrastructure.

Vercel's OIDC issuer () now supports custom audiences. Deployments can request OIDC tokens with a specific audience claim, enabling secure service-to-service authentication with third-party providers.oidc.vercel.com

Vercel OIDC tokens are issued with a fixed audience (). While most cloud providers don't require a specific audience value, using a unique audience per provider is a security best practice. If a provider is compromised, an attacker cannot replay the token against a different provider - the mismatched claim will cause verification to fail. This new service makes it easy to mint provider-specific tokens without managing additional infrastructure.https://vercel.com/{owner}aud

When a Vercel deployment runs, it receives an OIDC token signed by Vercel. The new exchange service accepts this token and returns a new one signed with the same key, but with an updated audience () claim targeting your downstream service.aud

The exchanged token:

You can optionally pass a (JWT ID) to assign a unique identifier to the exchanged token. This is useful for auditing and tracing token usage across services - for example, correlating a specific token exchange with downstream API calls in your logs.jti

Downstream services verify the exchanged token using the public key available at .https://oidc.vercel.com/{owner}/.well-known/jwks

Both the signing key and the token exchange endpoint are replicated across all , ensuring low-latency token exchange regardless of where the deployment is running.Vercel regions

Read more

Why custom audiences?

How it works

  • Preserves all original claims (project, environment, owner, expiration)

  • Sets the (issuer) to , scoped to the team that owns the deploymentisshttps://oidc.vercel.com/{owner}

  • Includes an (actor) claim with the original token's audience and issued-at time, providing an auditable delegation chainact

  • Updates the to the requested downstream audienceaud

  • Updates the (issued-at) to the current timestamp, reflecting when the new token was creatediat

oidcsecurityauthdeploymentapi

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →