gh secret set

Add a secret for GitHub Actions

What it does

Secrets are tokens and passwords that workflows need but that must not sit in the code. gh secret set DEPLOY_TOKEN asks for the value without showing it and stores it in the repository; in a workflow it is available as ${{ secrets.DEPLOY_TOKEN }}.

The value can come from a file: gh secret set DEPLOY_TOKEN < key.pem. A secret cannot be read back, only overwritten. gh secret list shows the names, and --env stores a secret for a specific environment.

Careful. Do not pass the value with --body right in the command: it stays in your shell history. Let gh ask for it.

Syntax

gh secret set <NAME>
gh secret set <NAME> < <file>
gh secret list

Examples

Related commands

Practise · All commands