Log In with OIDC
Use OIDC when the Formal Endpoint should authenticate as a machine identity. This flow avoids long-lived Formal credentials on the host. The Endpoint exchanges source OIDC tokens for short-lived Formal credentials. It refreshes those credentials while the source can provide valid tokens.1
Create an OIDC integration
Create an OIDC integration for the workload. Map the integration to a Formal machine user.Configure a claim condition that restricts access to the intended workload. You can also configure an end-user email expression.Copy the integration ID after creating the integration.
2
Configure a token source
Add one token source to
~/.formal/config.toml.- AWS
- Azure
- GCP
- Environment variable
- File
Use AWS on hosts with credentials from the standard AWS credential chain.The Endpoint uses the standard AWS credential chain. Supported sources include environment variables, shared configuration, IRSA, EKS Pod Identity, and EC2 instance profiles.If no region is set in the environment or shared config, the Endpoint uses EC2 instance metadata.
3
Start the Formal Endpoint
Unset
FORMAL_API_KEY because API key authentication takes precedence.Restart the desktop app, or start a headless agent:4
Verify
Run these commands from another terminal:
formal auth whoami should show the integration’s machine user. formal ls should show resources available to that identity.Log In with an API Key
Use an API key when the Formal Endpoint should skip the browser login flow. This works for human users and machine users.1
Create an API key
Go to API Keys and click Create API Key.To authenticate as a machine user, assign the key to that machine user.
2
Start the Formal Endpoint
--headless:3
Verify