Setting metadata on machine identities
- Manually Configure Metadata
1
Navigate to the Access Control page on the organization sidebar and select a machine identity.

2
On the machine identity page, click the pencil icon to edit the selected identity.

3
Add metadata via key-value pairs and update the machine identity.

Accessing attributes from machine identity login
When machine identities authenticate, they may receive additional payloads/attributes from the service provider. For methods like OIDC, these come as claims in the token and can be made available in your policies.- OIDC Login Attributes
- Kubernetes Login Attributes
- AWS Attributes
- Other Authentication Method Attributes
- Navigate to the Identity Authentication settings and select the OIDC Auth Method.
- In the Advanced section, locate the Claim Mapping configuration.
- Map the OIDC claims to permission attributes by specifying:
- Attribute Name: The identifier to be used in your policies (e.g., department).
- Claim Path: The dot notation path to the claim in the OIDC token (e.g., user.department).
- department: to
user.department - role: to
user.role

Template helper functions
In addition to referencing attributes directly, you can use helper functions to transform attribute values within your policy templates. stripPrefix Removes a prefix from the beginning of a string. If the string does not start with the given prefix, it is returned unchanged. Examples: Givenidentity.auth.kubernetes.namespace = production-us-east:
identity.auth.aws.arn = arn:aws:iam::123456789012:user/example-user:
myapp-pr-1 and myapp-pr-42. Trimming the generated segment lets every one
of those namespaces resolve to the same secret path as the base namespace, without writing a
condition for each pull request.
A pattern can contain at most five * or ? wildcards. A pattern with more than that trims
nothing, and the string is returned unchanged.
Examples:
Given identity.auth.kubernetes.namespace = myapp-pr-42:
identity.auth.kubernetes.namespace = myapp (nothing matches the pattern):

