Vercel Security & compliance

OIDC issuer in global mode (tokens honored beyond this team)

Part of the Deployment posture check · fix arrives as a guide

What it is

The project's OIDC issuer is configured in global mode rather than team mode.

Why it matters

Tokens issued for your deployments are honoured beyond your team, so a cloud provider trust policy matching the issuer may accept tokens minted by another Vercel customer.

How to fix it

Switch the OIDC issuer to team mode, then verify your cloud provider trust policies match on the specific team-scoped subject rather than the issuer alone.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.