gh secret set
Add a secret for GitHub Actions
What it does
Secrets are tokens and passwords that workflows need but that must not sit in the code. gh secret set DEPLOY_TOKEN asks for the value without showing it and stores it in the repository; in a workflow it is available as ${{ secrets.DEPLOY_TOKEN }}.
The value can come from a file: gh secret set DEPLOY_TOKEN < key.pem. A secret cannot be read back, only overwritten. gh secret list shows the names, and --env stores a secret for a specific environment.
Careful. Do not pass the value with --body right in the command: it stays in your shell history. Let gh ask for it.
Syntax
gh secret set <NAME>
gh secret set <NAME> < <file>
gh secret listExamples
Add the secret DEPLOY_TOKEN to the repository for Actions
gh secret set DEPLOY_TOKENsecret set— create or update a secretDEPLOY_TOKEN— the name; the value is asked for without echo
Related commands
- gh workflow run — Start a GitHub Actions workflow by hand
- gh run — Follow GitHub Actions runs and read their logs
- gh auth — Sign in to GitHub from the terminal and check who you are signed in as