The "Extend with Cloud Functions" section of the docs says:
Cloud Functions execute in a trusted environment, which means they are authorized as a service account on your project. You can perform reads and writes using the Firebase Admin SDK:
The API reference for rules says the request.auth will contain the uid and token map. Neither firebase.identities nor firebase.sign_in_provider seem to contain a "serviceAccount" key to specify how the request are authorised.
Use case: I have implemented a role based mechanic for users and would like to allow an operation for some roles and allow delete: if request.auth.uid != null && isOneOfRoles(['super-admin', 'admin']);. I cannot solely rely on checking request.auth.uid != null;.