# GitHub Actions OIDC Token Validator

> Validates GitHub Actions OIDC tokens for secure, secretless deployments. Uses the GitHub Actions id-token API and the jose JWT library to verify audience, issuer, and subject claims. Integrates with AWS STS AssumeRoleWithWebIdentity and GCP Workload Identity Federation for cloud access.

- Skill: `agentskillexchange/github-actions-oidc-token-validator` (Agent Skill)
- Install (CLI): `npx skillmds@latest add agentskillexchange/github-actions-oidc-token-validator`
- Raw SKILL.md: https://api.skillmd.com/api/skills/agentskillexchange/github-actions-oidc-token-validator/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: agentskillexchange (https://skillmd.com/u/agentskillexchange)
- Updated: 2026-09-08
- Page: https://skillmd.com/skills/agentskillexchange/github-actions-oidc-token-validator

---


# GitHub Actions OIDC Token Validator

Validates GitHub Actions OIDC tokens for secure, secretless deployments. Uses the GitHub Actions id-token API and the jose JWT library to verify audience, issuer, and subject claims. Integrates with AWS STS AssumeRoleWithWebIdentity and GCP Workload Identity Federation for cloud access.

## Prerequisites

GitHub repository with Actions enabled

## Installation

Use the upstream install or setup path that matches your environment:
- Docker to Azure App Service
- Use Docker service containers
- Make a contribution Learn how to contribute

Requirements and caveats from upstream:
- Deploy to third-party platforms Node.js to Azure App Service
- Python to Azure App Service
- Node.js

Basic usage or getting-started notes:
- Billing and usage
- Choose when workflows run Trigger a workflow
- Choose where workflows run Choose the runner for a job

- Source: https://docs.github.com/en/actions

## Documentation

- https://docs.github.com/en/actions

## Source

- [Agent Skill Exchange](https://agentskillexchange.com/skills/github-actions-oidc-token-validator/)

