Authentication
An overview of gRPC authentication, including built-in auth mechanisms, and how to plug in your own authentication systems.
Authentication
Overview
gRPC is designed to work with a variety of authentication mechanisms, making it easy to safely use gRPC to talk to other systems. You can use our supported mechanisms - SSL/TLS with or without Google token-based authentication - or you can plug in your own authentication system by extending our provided code.
gRPC also provides a simple authentication API that lets you provide all the
necessary authentication information as Credentials when creating a channel or
making a call.
Supported auth mechanisms
The following authentication mechanisms are built-in to gRPC:
- SSL/TLS: gRPC has SSL/TLS integration and promotes the use of SSL/TLS to authenticate the server, and to encrypt all the data exchanged between the client and the server. Optional mechanisms are available for clients to provide certificates for mutual authentication.
- ALTS: gRPC supports ALTS as a transport security mechanism, if the application is running on Compute Engine or Google Kubernetes Engine (GKE). For details, see one of the following language-specific pages: ALTS in C++, ALTS in Go, ALTS in Java, ALTS in Python.
- Token-based authentication with Google: gRPC provides a generic mechanism (described below) to attach metadata based credentials to requests and responses. Additional support for acquiring access tokens (typically OAuth2 tokens) while accessing Google APIs through gRPC is provided for certain auth flows: you can see how this works in our code examples below. In general this mechanism must be used as well as SSL/TLS on the channel - Google will not allow connections without SSL/TLS, and most gRPC language implementations will not let you send credentials on an unencrypted channel.
Warning
Google credentials should only be used to connect to Google services. Sending a Google issued OAuth2 token to a non-Google service could result in this token being stolen and used to impersonate the client to Google services.Authentication API
gRPC provides a simple authentication API based around the unified concept of Credentials objects, which can be used when creating an entire gRPC channel or an individual call.
Credential types
Credentials can be of two types:
- Channel credentials, which are attached to a
Channel, such as SSL credentials. - Call credentials, which are attached to a call (or
ClientContextin C++).
You can also combine these in a CompositeChannelCredentials, allowing you to
specify, for example, SSL details for the channel along with call credentials
for each call made on the channel. A CompositeChannelCredentials associates a
ChannelCredentials and a CallCredentials to create a new
ChannelCredentials. The result will send the authentication data associated
with the composed CallCredentials with every call made on the channel.
For example, you could create a ChannelCredentials from an SslCredentials
and an AccessTokenCredentials. The result when applied to a Channel would
send the appropriate access token for each call on this channel.
Individual CallCredentials can also be composed using
CompositeCallCredentials. The resulting CallCredentials when used in a call
will trigger the sending of the authentication data associated with the two
CallCredentials.
Using client-side SSL/TLS
Now let’s look at how Credentials work with one of our supported auth
mechanisms. This is the simplest authentication scenario, where a client just
wants to authenticate the server and encrypt all data. The example is in C++,
but the API is similar for all languages: you can see how to enable SSL/TLS in
more languages in our Examples section below.
// Create a default SSL ChannelCredentials object.
auto channel_creds = grpc::SslCredentials(grpc::SslCredentialsOptions());
// Create a channel using the credentials created in the previous step.
auto channel = grpc