iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Cloudways says its legacy API key is scheduled to reach end of life on October 15, 2026, so GitHub Actions workflows that still rely on it need a migration plan. The key detail: an Access Token is not automatically interchangeable with an API key in every GitHub Action. Inventory your workflow, create a dedicated token with the permissions it needs, store it as a GitHub Actions secret, confirm your integration supports token authentication, then test deployment before removing the old key.
What changes, and when?
Cloudways’ Access Token guidance sets October 15, 2026 as the scheduled end-of-life date for the legacy API key. An integration that still depends on that key may stop authenticating after retirement. Check the Cloudways token guide for the current policy and status before scheduling a production change, since retirement timelines can change.
Access Tokens can be created for individual integrations, assigned scopes and expiry periods, and revoked independently. Cloudways recommends Limited Access for most integrations, but currently labels it Beta; the available endpoints may change. Select only the permissions the deployment actually needs, and do not assume a required Git operation is covered until you check the current permission options.
First, confirm how your workflow authenticates
Search the repository’s workflow and deployment configuration for CLOUDWAYS_API_KEY, api-key, and Cloudways API request code. Check every repository and environment that deploys through Cloudways, then identify whether each workflow uses a Marketplace action or calls the API itself. Credential names and authentication methods can differ between integrations.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
This compatibility check matters because the Cloudways API Git Pull Marketplace listing reviewed here documents the legacy CLOUDWAYS_API_KEY secret and an api-key input. That listing does not establish that the action accepts a new Access Token. Check the exact action version and its source or documentation for explicit Access Token support before changing the credential value. See the Cloudways API Git Pull Marketplace listing. Cloudways’ API v2 overview provides background, but request syntax and supported authentication should come from current Cloudways API documentation.
Create and store a dedicated Access Token
- Open Cloudways API Integration. Cloudways says this interface is available to the primary account owner. Create a token named for the GitHub Actions workflow so its purpose is clear.
- Choose expiry and permissions. Set an expiry consistent with your credential-rotation policy. Prefer Limited Access and select the required Git deployment operation if it is currently available. Limited Access is Beta; if the needed operation is missing, verify the current API and action behavior instead of granting broad access by default.
- Copy the token immediately. Cloudways displays the complete value only once. It cannot later be viewed, retrieved, or regenerated. If you lose it, create a replacement and update the integration.
- Add it to GitHub Actions secrets. Store the value as a repository, environment, or organization secret, depending on which workflows need it and your access-control model. GitHub documents these secret types in its Actions secrets guidance.
Reference the secret from the workflow only through the input or authentication mechanism the action or API integration explicitly supports. Do not hard-code the token in YAML, commit it, print it to logs, or place it in a public URL.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Update the integration and test a deployment
Use the path that matches your workflow’s authentication implementation:
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Keep a third-party action only if the maintained version explicitly supports Cloudways Access Tokens. Confirm the expected input or request authentication method, whether it can apply the needed limited scope, and how it handles secrets and errors.
- Change or customize the workflow if the action supports only the legacy key. Make API requests only through a documented Cloudways authentication method, and account for secret handling, least-privilege permissions, and useful failure diagnostics.
After updating the integration, run it against a safe branch or staging target when available. Confirm both that authentication succeeds and that the expected deployment completes. The Cloudways API Playground can test operations, but Cloudways warns that its actions affect the authenticated account; use care and a test server where possible.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Remove the old key after the new path works
Once the controlled deployment succeeds, remove the legacy key from GitHub secrets and any other stored configuration used by the workflow. Review other consumers before deleting or revoking shared credentials. Revoke Access Tokens that are unused or exposed; Cloudways says revocation disables a token immediately, so confirm that no active integration still depends on it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot common migration failures
HTTP 401: authentication failed
Check that the token was copied correctly and remains valid, unexpired, and unrevoked. An expired or revoked token cannot authenticate. If the token was lost, create a replacement, update the GitHub secret, and rerun the workflow. Cloudways describes these causes in its Git auto-deployment guide.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
HTTP 403: permission or webhook issue
Check the token’s permission for the Git pull operation and, where the deployment uses a webhook, verify the webhook secret independently. Cloudways identifies an incorrect webhook secret or insufficient Git permission as possible causes.
The action still asks for an API key
Do not assume the token will work merely because you put it in the old secret slot. The Marketplace listing documents legacy credential names; verify the specific action version’s current documentation and source for Access Token support. If it does not support tokens, use a supported integration path rather than relabeling the secret.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
The token expired or was lost
An expired token stops authenticating, and a lost token cannot be retrieved. Create a new token, replace the GitHub secret, test deployment, then revoke the old token when it is no longer needed.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

