How does Vault verify the identity of the host requesting access to the credentials? I didn't find anything in the documentation that would give me information pertaining to that.
The new instance then consumes the bootstrap token from the queue and exchanges it for whatever other tokens it has permission to obtain.