Vercel
Security & compliance
OIDC issuer in global mode (tokens honored beyond this team)
Part of the Deployment posture check · fix arrives as a guide
What it is
The project's OIDC issuer is configured in global mode rather than team mode.
Why it matters
Tokens issued for your deployments are honoured beyond your team, so a cloud provider trust policy matching the issuer may accept tokens minted by another Vercel customer.
How to fix it
Switch the OIDC issuer to team mode, then verify your cloud provider trust policies match on the specific team-scoped subject rather than the issuer alone.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.