adk_google_adc (erlang_adk v0.9.0)
View SourceBounded OAuth bearer acquisition for the Vertex request adapter.
A direct api_key is treated as an already-minted OAuth access token. The google_adc source invokes either a trusted injected provider (for managed integrations/tests) or the fixed gcloud Application Default Credentials command. No shell, caller-supplied executable, arguments, or output-derived error term crosses this boundary.