Claude Code on the web, Codex Web, et al should make an OIDC token available to the container. This would be better than an AWS access key, GCP keys, etc.
On the team/enterprise plans it would identify the session itself, the user who kicked it off, the repo, the enterprise ID.