GitHub Actions OIDC Token Validator
Validates GitHub Actions OIDC tokens for secure, secretless deployments. Uses the GitHub Actions id-token API and the jose JWT library to verify audience, issuer, and subject claims. Integrates with AWS STS AssumeRoleWithWebIdentity and GCP Workload Identity Federation for cloud access.
Prerequisites
GitHub repository with Actions enabled
Installation
Use the upstream install or setup path that matches your environment:
- Docker to Azure App Service
- Use Docker service containers
- Make a contribution Learn how to contribute
Requirements and caveats from upstream:
- Deploy to third-party platforms Node.js to Azure App Service
- Python to Azure App Service
- Node.js
Basic usage or getting-started notes:
Billing and usage
Choose when workflows run Trigger a workflow
Choose where workflows run Choose the runner for a job