How do you use a non-Google oidc idp though?
That's the main thing keeping me away from it.
You have the non-choice of using Google Auth or include the token in every request outside of credentials
You can construct credentials from any ID token, it ends up as a standard Authorization: Bearer header on each RPC. I believe this is the case for Google Auth too.