iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
There are two documented deployment paths, and they use different credentials. Cloudways’ webhook guide uses a Cloudways API Access Token so a webhook script can ask Cloudways to pull a Git branch. Its GitHub Actions zero-downtime guide instead connects from the Actions runner to the server over SSH. The available documentation does not establish a current, copy-ready GitHub Actions workflow that calls Cloudways API v2 directly with an access token, so this guide separates the verified options rather than guessing at an endpoint or payload.
Choose the deployment architecture first
| Path | Trigger and deployment actor | Credential in the documented path | Release approach | Main trade-off |
|---|---|---|---|---|
| Cloudways webhook with API Access Token | Your Git provider sends a webhook to an application endpoint; the webhook script calls Cloudways, which pulls the selected branch. | Cloudways API Access Token, plus a separate webhook secret. | Cloudways Git deployment pulls into the configured path. | Fewer runner-side release steps, but requires a securely configured, reachable webhook and protected server-side configuration. |
| GitHub Actions with SSH | GitHub Actions runs on configured branch events; the runner connects to the Cloudways server. | A dedicated SSH private key stored as an Actions secret; its public key is trusted by the server. | Timestamped release directories, shared persistent files, and a symlink switch. | More control over build and release steps, but requires SSH-key management and server-side release setup. |
These are documented architectures, not performance comparisons. Cloudways describes its SSH release pattern as zero-downtime, but the available material does not provide an independently measured downtime result.
What Cloudways documents about API Access Tokens
Cloudways says new integrations should use API Access Tokens rather than the legacy API Key. In its webhook design, a push leads the Git provider to send a request to a webhook script. The script validates that request, authenticates to the Cloudways API, and triggers a Git pull of the selected branch.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
The Cloudways Help Center says, “The complete Access Token is displayed only once.” Copy it when creating it and keep it in protected storage. Cloudways’ guide is for applications on Cloudways Flexible and assumes Git deployment is configured and the application’s SSH public key can access the Git-over-SSH repository.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Set up the documented webhook path
- Prepare Git deployment. In Cloudways Flexible, configure Git deployment for the application and selected repository and branch. Add the application’s SSH public key at the Git provider so the server can fetch the repository. Cloudways’ setup guide is How to Deploy Code to Your Application Using Git on Cloudways Flexible.
- Create a dedicated API Access Token. In Cloudways API Integration, create a token and choose an expiration. Select Limited Access if the selector includes the required Git operation; use Full Access only if Limited Access does not support it. The guide does not establish the current permission label for that operation.
- Copy and protect the token. Cloudways displays the complete token only once. Keep it out of public repositories, client-side code, public files, support tickets, chats, screenshots, and webhook URLs. Cloudways’ own webhook implementation describes a configuration file outside
public_html; that server-side pattern should not be transplanted into a GitHub Actions workflow without a reason. - Configure and secure the webhook. Cloudways’ implementation uses the server ID, application ID, SSH repository URL, branch, and optional deployment path. If the path is empty, the default is
public_html. Validate incoming webhook requests with a separate secret and keep the token in protected server-side configuration. - Validate the result. Confirm that the webhook is accepted, Cloudways pulls the intended branch to the intended path, and the running application works. If the token expires or is revoked, authentication stops until a replacement token is configured.
For Cloudways’ full webhook instructions, see How to Automatically Deploy From Git to Cloudways Using Webhooks.
What the GitHub Actions SSH path does
Cloudways’ separate guide describes an Actions workflow that monitors main and staging, connects to the server over SSH, prepares a timestamped release directory, reuses shared configuration and uploads, then switches a symlink to activate the release. The setup uses a dedicated SSH key pair: the public key is placed on the Cloudways server, and the private key is stored in GitHub Actions secrets. The article also includes API calls for follow-on server operations, but it does not establish that those calls use the newer API Access Token scheme.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Read the documented pattern in Implementing Zero Downtime Deployments on Cloudways. Treat it as evidence for an SSH-driven release architecture, not as a verified direct Actions-to-API-token workflow.
Why not paste a direct API-token workflow here?
A safe copy-and-paste API workflow needs the current Cloudways API v2 authentication method, exact Git deployment endpoint, request fields, and token permission scope. Those details are not established by the documentation reviewed for this guide. Cloudways API v1 reached end of life on March 31, 2026; its documentation is a migration warning, not a reliable basis for a new implementation. Do not infer a v2 endpoint or payload from v1. Check current v2 documentation before writing a workflow that calls the API directly.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Likewise, do not assume the third-party Cloudways API Git Action supports current Access Tokens: its Marketplace listing asks for an account email and legacy API Key. Cloudways says not to create new integrations using that old key. Only use an action after its maintainer documents current token support and you have verified its behavior and required permissions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Harden the GitHub Actions workflow
GitHub Actions provides controls for deployment triggers, build and test steps, environments, branch restrictions, approvals, secret access, and concurrency. Use them to reduce the chance that an unintended change or overlapping run reaches production. GitHub’s guidance is in Continuous deployment.
Quick Recap
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Create a dedicated deployment credential and grant only the permissions required for the chosen architecture.
- Keep API tokens and SSH private keys in GitHub Actions secrets or an appropriate protected secret store; never commit them, expose them in public application files, or print them in logs.
- Restrict production secrets to the intended branch and environment. Add an approval gate when production changes require review.
- Use concurrency controls to prevent overlapping production deployments when concurrent releases could conflict.
- Set an expiration and rotation plan for tokens, replace credentials before expiry, and revoke any credential that is exposed or no longer needed.
- After deployment, verify the expected commit and application behavior. A successful workflow run alone does not prove the live site is healthy.
Which path fits your setup?
- Choose the webhook path if you want Cloudways to perform its documented Git pull after a validated Git-provider webhook and can maintain the protected server-side configuration it requires.
- Choose the SSH Actions path if the runner should control build and release sequencing and you are prepared to manage SSH access and the server-side release layout.
- Do not claim a direct Actions-to-Cloudways API-token deployment is ready to copy until you have verified the current API v2 endpoint, payload, authentication, and limited-access permission in Cloudways’ current documentation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

