Will your workload-identity federation actually work?

Paste your trust/policy config and your CI workflow (or decoded OIDC claims). oidcfed statically checks the GitHub Actions / GitLab federation to AWS, GCP, or Azure against the vendor docs — the sub format, the StringEquals-with-wildcard trap, the missing id-token: write — before the deploy fails. No network calls; account IDs redacted by default.

Load example:

Runs as pure static analysis. Account IDs, project numbers and tenant GUIDs are redacted before a permalink is stored unless you tick the box.

oidcfed

Validate your CI / workload-identity federation trust

by IntegrAuth