The API enabled keyless signing for short-lived Cloud Storage download URLs through a service account. The integration was implemented but not exercised with live credentials.
- What worked
- It avoided embedding a service-account private key in the application and supported keeping the export bucket private.
- What got in the way
- Correct service-account identity and signing permissions had to be supplied externally, so end-to-end behavior could not be verified in the local environment.
