# OIDC support for generating ephemeral Doppler tokens

**URL:** <https://community.doppler.com/t/oidc-support-for-generating-ephemeral-doppler-tokens/1503>\
**Category:** Feature Requests\
**Created:** [April 5, 2024, 3:28pm UTC](https://community.doppler.com/t/oidc-support-for-generating-ephemeral-doppler-tokens/1503 "2024-04-05T15:28:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RobGodfrey](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/robgodfrey/32/1040_2.png) [@RobGodfrey](https://community.doppler.com/u/RobGodfrey)\
**Post date:** [April 5, 2024, 3:28pm UTC](https://community.doppler.com/t/oidc-support-for-generating-ephemeral-doppler-tokens/1503/1 "2024-04-05T15:28:27Z")

</div>

Within CD pipelines, we often need to pull secrets from Doppler using a long lived DOPPLER\_TOKEN. This token is long lived and gets stored in a pipeline environment variable. CI/CD vendors are being increasingly targeted with breaches leaking secrets like these. Last year CircleCI had an incident where they advised all their customers to rotate secrets stored in pipeline environment variables. To mitigate breaches of this nature it would be great if Doppler could provide support for generating an ephemeral Doppler token using OIDC. This would mean we would no longer need long long lived credentials in CD pipelines and could generate short lived tokens to retrieve secrets from Doppler where needed.

---

<div class="post-metadata">

**Author:** ![watsonian](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/watsonian/32/267_2.png) [@watsonian](https://community.doppler.com/u/watsonian)\
**Post date:** [January 21, 2025, 7:52pm UTC](https://community.doppler.com/t/oidc-support-for-generating-ephemeral-doppler-tokens/1503/2 "2025-01-21T19:52:40Z")

</div>

@RobGodfrey Just wanted to chime back in to let you know that we just shipped OIDC support! You can get more information about this here:

> **[Service Account Identities (OIDC)](https://docs.doppler.com/docs/service-account-identities)**
>
> Identities allow a service account to authenticate to Doppler via OIDC without using a static API token. Any tool that can generate OIDC tokens (e.g., CI tools like GitHub or GitLab) is compatible with Doppler. Use the service account detail page to...

It’s available on the Team and Enterprise plans.

---

<div class="post-metadata">

**Author:** ![RobGodfrey](https://sea2.discourse-cdn.com/flex016/user_avatar/community.doppler.com/robgodfrey/32/1040_2.png) [@RobGodfrey](https://community.doppler.com/u/RobGodfrey)\
**Post date:** [January 21, 2025, 8:16pm UTC](https://community.doppler.com/t/oidc-support-for-generating-ephemeral-doppler-tokens/1503/3 "2025-01-21T20:16:12Z")

</div>

Excellent, thank you for the update. We will take a look.
