Skip to content

Go quickstart documents API key auth only, with no Application Default Credentials path #2188

Description

@karolpiotrowicz

The Go quickstart at https://adk.dev/get-started/go/ covers a single authentication method. Its auth section is titled "Set your API key", the sample uses APIKey: os.Getenv("GOOGLE_API_KEY"), and readers are sent to AI Studio for a key. Application Default Credentials are not mentioned, and there is no link from that section to the Google Cloud page.

ADK Go supports Application Default Credentials as a first-class option. auth.ADC() is an exported credential provider alongside auth.APIKey() and auth.ServiceAccount() in auth/providers.go, defaulting to the cloud-platform scope. Passing Backend: genai.BackendVertexAI to gemini.NewModel authenticates through Application Default Credentials with no key at all, which several examples in the repository already do. Application Default Credentials are also used for telemetry export, the agent registry, and the GCP auth client.

The "Connect to Google Cloud and Agent Platform" page at https://adk.dev/get-started/google-cloud/ covers this well, leading with Application Default Credentials and placing the API key path last. A reader who follows the Go quickstart start to finish never reaches it.

This matters most for organizations that will not distribute API keys, who currently have to discover the supported path by reading the source. Adding a short alternative-auth subsection to the Go quickstart, or a pointer to the Google Cloud page from the auth section, would close the gap.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions