- Playground
- Chat (
pollyin Helm) - Insights
Keyless authentication for Chat and Insights requires Helm chart version 0.17.0 or later and LangSmith application version 0.17.29 or later.
- Enable GKE Workload Identity Federation. Enable it on the cluster and the node pools that run LangSmith. See Workload Identity Federation for GKE.
-
Grant the GSA Vertex AI access. Create or select a GSA for these model calls. Grant it only
roles/aiplatform.userin the project that hosts the models: -
Allow each KSA to impersonate the GSA. Grant each calling KSA
roles/iam.workloadIdentityUseron the GSA. Replace the five KSA placeholders with the names rendered by your Helm release:Bind only these specific KSA subjects. If the workloads use different namespaces, run the command separately with each KSA’s namespace. -
Annotate every KSA. Add the GSA annotation through your Helm values. The Chat and Insights API and queue identities are separate callers. Every API and queue identity needs an annotation and IAM binding:
Helm
-
Use ADC instead of explicit credentials. In each Vertex AI or Gemini provider configuration, leave Service Account JSON empty. Keep
GOOGLE_VERTEX_AI_WEB_CREDENTIALSandGOOGLE_APPLICATION_CREDENTIALSunset. LangSmith uses explicit JSON credentials instead of ADC when both are present.
Connect these docs to your agent of choice via MCP for real-time answers.

