This document describes the items that are present in Confidential VM
attestation tokens, as defined in the
well-known endpoint
for Confidential VM. The tokens are JSON web tokens (JWT).
Example token
The following is an example of an encoded attestation token. You can use https://jwt.io/ to decode it:
eyJhbGciOiJSUzI1NiIsImtpZCI6IjFjNjdmYWVhYjRhYzE1ZDJmNmZmODMwY2E2ZmM1N2YyYmVhM2Y0YmIiLCJ0eXAiOiJKV1QifQ.eyJhdWQiOiJcdTAwM2NZT1VSQVVESUVOQ0VcdTAwM2UiLCJleHAiOjE3MTU5NzE2OTcsImlhdCI6MTcxNTk2ODA5NywiaXNzIjoiaHR0cHM6Ly9jb25maWRlbnRpYWxjb21wdXRpbmcuZ29vZ2xlYXBpcy5jb20iLCJuYmYiOjE3MTU5NjgwOTcsInN1YiI6Imh0dHBzOi8vd3d3Lmdvb2dsZWFwaXMuY29tL2NvbXB1dGUvdjEvcHJvamVjdHMvcnVpZGV6aGFuZy0yL3pvbmVzL3VzLWNlbnRyYWwxLWMvaW5zdGFuY2VzL2N2bS10b2tlbi1jbGFpbXMiLCJlYXRfbm9uY2UiOlsidGhpc0lzQWN1c3RvbU5vbmNlIiwidGhpc0lzQU11Y2hMb25nZXJDdXN0b21Ob25jZVdpdGhQYWRkaW5nRm9yNzRCeXRlczAwMDAwMDAwMDAwMDAwMDAwMDAwMDAwMDAiXSwic2VjYm9vdCI6ZmFsc2UsIm9lbWlkIjoxMTEyOSwiaHdtb2RlbCI6IkdDUF9BTURfU0VWIiwic3duYW1lIjoiR0NFIiwiZGJnc3RhdCI6ImVuYWJsZWQiLCJzdWJtb2RzIjp7ImdjZSI6eyJ6b25lIjoidXMtY2VudHJhbDEtYyIsInByb2plY3RfaWQiOiJydWlkZXpoYW5nLTIiLCJwcm9qZWN0X251bWJlciI6IjQ3MDY1MjQyNjMwNSIsImluc3RhbmNlX25hbWUiOiJjdm0tdG9rZW4tY2xhaW1zIiwiaW5zdGFuY2VfaWQiOiI3MzMzMjUxNTQ2ODE2NDQ2MDY5In19LCJnb29nbGVfc2VydmljZV9hY2NvdW50cyI6WyI0NzA2NTI0MjYzMDUtY29tcHV0ZUBkZXZlbG9wZXIuZ3NlcnZpY2VhY2NvdW50LmNvbSJdfQ.Z8CIreuWj8vQKe9L5f5Ol80LcWBI_pFWwfT8qsky8hjtH3OMmqfUCJJRx-dX5Rqm5n4qe4dHacLgSWQlT9MDYyrtWDuocA2WtfPZLvM0DNc4HuoNPZtVrgMMcZ93Xyl5-tJuI5PbPshiDBT06_QaRm5l37RRL2CsxXZGCkKsxV1vs0gF5xZgSNmhDqg3q1fONhA3VglZ-H0SHAvMNr1qwXDKrQxdYxyFfEMLkcsRxSXlR5mLCbMIFptGTPXt-k83xJzCipuKSiKJrwaRdZTmlapn7UtaTRLvG3YCmXPg6oOvNKtE8T4KeBY36EdzR0Fdmz_pXSbWL-q8-y90VxDxwQ
AMD SEV token
The following is an example of a decoded AMD SEV attestation token:
{
"alg": "RS256",
"kid": "6e66f1aededf736581df2599ee20387718978dcd",
"typ": "JWT"
}.
{
"aud": "<YOURAUDIENCE>",
"exp": 1715359550,
"iat": 1715355950,
"iss": "https://confidentialcomputing.googleapis.com",
"nbf": 1698861565,
"sub": "https://www.googleapis.com/compute/v1/projects/<YOURPROJECT>/zones/us-central1-c/instances/cvm-token-claims",
"eat_nonce": [
"thisIsAcustomNonce",
"thisIsAMuchLongerCustomNonceWithPaddingFor74Bytes0000000000000000000000000"
],
"secboot": true,
"oemid": 11129,
"hwmodel": "GCP_AMD_SEV",
"swname": "GCE",
"dbgstat": "disabled-since-boot",
"eat_profile": "https://cloud.google.com/confidential-computing/confidential-vm/docs/token-claims",
"submods": {
"gce": {
"zone": "us-central1-c",
"project_id": "<YOURPROJECT>",
"project_number": "470652426305",
"instance_name": "cvm-token-claims",
"instance_id": "7333251546816446069"
}
},
"google_service_accounts": [
"470652426305-compute@developer.gserviceaccount.com"
]
}
Intel TDX token
The following is an example of a decoded Intel TDX attestation token:
{
"alg": "RS256",
"kid": "6e66f1aededf736581df2599ee20387718978dcd",
"typ": "JWT"
}.
{
"aud": "<YOURAUDIENCE>",
"exp": 1715359550,
"iat": 1715355950,
"iss": "https://confidentialcomputing.googleapis.com",
"nbf": 1698861565,
"sub": "//compute.googleapis.com/projects/470652426305/zones/us-central1-c/instances/7333251546816446069",
"eat_nonce": [
"thisIsAcustomNonce"
],
"secboot": true,
"oemid": 11129,
"hwmodel": "GCP_INTEL_TDX",
"swname": "GCE",
"dbgstat": "disabled-since-boot",
"eat_profile": "https://cloud.google.com/confidential-computing/confidential-vm/docs/token-claims",
"submods": {
"gce": {
"zone": "us-central1-c",
"project_number": "470652426305",
"instance_id": "7333251546816446069"
}
},
"tdx": {
"gcp_attester_tcb_date": "2026-06-01T00:00:00Z",
"tcb_evaluation_data_number": 17,
"fmspc": "00806F000000",
"tee_tcb_svn": "06010300000000000000000000000000",
"pcesvn": 11,
"sgx_tcb_comp_svn": "08080202040100060000000000000000",
"xfam": "e702060000000000",
"tdattributes": "0000000000000000",
"mrtd": "c68518a0ebb42136c12b2275164f8c72f25fa9a343922286a41b52bc7e4c2787e35b7782b132454191a27e366bc33e8a",
"rtmr0": "a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1a1",
"rtmr1": "b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2b2",
"rtmr2": "c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3",
"rtmr3": "000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"
},
"google_service_accounts": [
"470652426305-compute@developer.gserviceaccount.com"
]
}
The items within the token are further explained in the following sections.
Token items
The following table describes the high-level items in an attestation token. These items are compliant with the OpenID Connect 1.0 specification.
well-known endpoint values |
Description |
|---|---|
claims_supported |
See Top-level claims. |
id_token_signing_alg_values_supported |
The signing algorithms (alg values) supported by the
token. Confidential VM supports the RS256
algorithm. |
issuer |
The HTTPS scheme that Confidential VM uses as its issuer identifier. The value is
|
jwks_uri |
The path to the public keys used to verify the token signature. You can publish these keys in a Cloud Storage bucket. You can find the An example value is
|
response_types_supported |
The list of supported Confidential VM response
types. Confidential VM supports id_token.
|
scopes_supported |
The
OAuth 2.0
scope values that the Confidential VM instance supports.
Confidential VM supports openid only. |
subject_types_supported |
The subject identifier types that Confidential VM
supports. Confidential VM supports
public. |
Top-level claims
The following table describes the top-level supported claims in the attestation token.
| Claim | Type | Description |
|---|---|---|
aud |
String |
The audience. For the default token used with a workload identity
pool, the audience is For tokens with custom audiences, the audience is echoed from the audience in the token request. The maximum length is 512 bytes. |
dbgstat |
String | The debug status for the hardware. Not available for AMD SEV. |
eat_nonce |
String or string array | One or more nonces for the attestation token. The values are echoed from the token options sent in the custom token request. Each nonce must be between 10 to 74 bytes inclusive. A maximum of six nonces are allowed. |
eat_profile |
String |
The URI of the Entity Attestation Token (EAT) profile defining the
token schema. The value is
https://cloud.google.com/confidential-computing/confidential-vm/docs/token-claims.
|
exp |
Int, Unix timestamp |
The expiration time on or after which the token must not be accepted for
processing. The value is a JSON number that represents the number of
seconds from
1970-01-01T0:0:0Z as measured
in UTC until the expiry time.
|
google_service_accounts |
String array | The validated service accounts that are running the Confidential VM workload. |
hwmodel |
String |
The unique identifier for the hardware token. The identifier must be one of the following values:
|
iat |
Int, Unix timestamp |
The time when the JWT was issued. The value is a JSON number that
represents the number of seconds from
1970-01-01T0:0:0Z as measured
in UTC until the issue time.
|
iss |
String |
The issuer of the token, which is set to
https://confidentialcomputing.googleapis.com.
|
nbf |
Int, Unix timestamp |
The time after which the JWT is allowed to be processed. The value is a
JSON number that represents the number of seconds from
1970-01-01T0:0:0Z as measured
in UTC.
|
oemid |
Uint64 |
The Google
Private Enterprise Number (PEN), which is 11129.
|
secboot |
Boolean | Whether Secure Boot is enabled, which makes sure that the firmware and operating system are authenticated during the VM boot process. |
sub |
String |
The subject identifying the virtual machine instance:
|
submods |
Array | An array of various claims. See Submod claims. |
swname |
String |
The name of the approved operating system for the VM. The value is always |
tdx |
Object | An object containing claims for Intel TDX instances. See Intel TDX claims. |
Intel TDX claims
The following table describes the tdx claims in the attestation token for
Intel TDX instances.
| Claim | Type | Description |
|---|---|---|
tcb_evaluation_data_number |
Uint32 | Monotonically increasing Intel TCB Evaluation Data Number associated with the platform's FMSPC from Intel TCB Info. |
gcp_attester_tcb_date |
String | Timestamp (UTC) of the Intel TCB evaluation baseline. |
mrtd |
String (hex) | Measurement of the initial Trust Domain contents and virtual firmware (OVMF). |
rtmr0 |
String (hex) | Runtime measurement register 0 (virtual firmware configuration and system parameters). |
rtmr1 |
String (hex) | Runtime measurement register 1 (guest OS bootloader and kernel measurements). |
rtmr2 |
String (hex) | Runtime measurement register 2 (initial RAM disk (initramfs) and kernel command-line). |
rtmr3 |
String (hex) | Runtime measurement register 3 (customer runtime extensions and applications). |
fmspc |
String (hex) | 6-byte Family-Model-Stepping SKU for Intel Provisioning Certification Service (PCS) lookup. |
tee_tcb_svn |
String (hex) | 16-byte array of TDX TCB component security version numbers when the Trust Domain was launched. |
pcesvn |
Uint16 | SVN of the Provisioning Certification Enclave (PCE). |
sgx_tcb_comp_svn |
String (hex) | 16-byte array of Intel SGX TCB component security version numbers. |
xfam |
String (hex) | 8-byte mask of enabled CPU extended features. |
tdattributes |
String (hex) | 8-byte bitmap of TD execution attributes. |
Submods claims
The following table describes the submods claims in the attestation token.
| Claim | Type | Description |
|---|---|---|
gce |
Object | See Compute Engine claims. |
Compute Engine claims
The following table describes the gce claims in the attestation token.
| Claim | Type | Description |
|---|---|---|
instance_id |
String | The VM instance ID. |
instance_name |
String | The VM instance name. |
project_id |
String | The project ID for the project that the VM is running in. |
project_number |
String | The project number for the project that the VM is running in. |
zone |
String | The Compute Engine zone where the Confidential VM instance is running. |
What's next
See the IETF draft for The Entity Attestation Token (EAT) for more information on attestation claims.
See the OpenID Connect Core 1.0 for more information on OpenID token claims.
For more information about tokens and retrieving them, see vTPM Attestation Codelab.