The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To remove long-lived AWS access keys from GitHub Actions, configure AWS to trust GitHub’s OIDC identity provider, create a narrowly scoped IAM role, and have the workflow request temporary credentials for that role. The workflow needs id-token: write and the AWS credentials action, but that permission alone does not grant access to AWS resources. The IAM role’s trust policy controls which GitHub workflow can assume it; the role’s permissions control what it can do after that.
How GitHub Actions OIDC access to AWS works
Instead of storing an AWS access key and secret in GitHub, a workflow requests a GitHub-issued OpenID Connect (OIDC) JSON Web Token. The AWS credentials action presents the token to AWS Security Token Service (STS) through web identity federation. AWS checks the token against its configured GitHub OIDC provider and the IAM role’s trust policy. If those checks pass, STS returns temporary credentials for the role.
Those temporary credentials are not permissionless: AWS permissions attached to the assumed role determine which actions the workflow can perform. GitHub summarizes the change as access “without needing to store the AWS credentials as long-lived GitHub secrets.” GitHub Docs, “Configuring OpenID Connect in Amazon Web Services” explains the integration.
How do I use GitHub Actions OIDC with AWS?
For GitHub.com, the integration uses the issuer URL https://token.actions.githubusercontent.com. With the official AWS credentials action, the audience is sts.amazonaws.com. Set up the provider and role in AWS, then configure the workflow to request a token and assume that role.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
1. Create or confirm the IAM OIDC provider
In the AWS account that owns the target role, configure an IAM OIDC identity provider for https://token.actions.githubusercontent.com. Use sts.amazonaws.com as the audience for the official credentials action. If the provider already exists in the account, confirm its issuer and audience rather than creating a duplicate.
2. Create a dedicated IAM role and constrain its trust policy
Create a role for the deployment or workflow purpose, and configure its trust policy to name the GitHub OIDC provider as the federated principal and allow sts:AssumeRoleWithWebIdentity. Add conditions for both the audience and the subject. The audience should match the token intended for AWS; the subject (sub) should identify the repository and deployment identity that is allowed to assume the role.
A branch-scoped subject can look like repo:ORG/REPO:ref:refs/heads/BRANCH. Replace the uppercase parts with the actual organization, repository, and branch. This limits role assumption to that branch identity. AWS specifically advises including a sub condition that restricts which GitHub entities can assume the role; a broad wildcard can admit repositories beyond the intended control. See AWS IAM’s GitHub-specific trust-policy guidance.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
3. Choose branch or environment scope intentionally
For workflows that deploy through a GitHub environment, the subject uses the environment name, for example repo:ORG/REPO:environment:prod, instead of the branch-ref form. An environment subject identifies the environment, so configure GitHub environment protection rules—such as eligible deployment branches or tags—to control which workflow runs can reach it. A branch-specific subject can be more direct when only one ref should assume the role; an environment is useful when deployment approvals or environment-level restrictions are part of the process.
A repository-wide wildcard is less restrictive than an exact branch or environment identity. Use it only when the deployment design genuinely requires multiple identities, and understand that each workflow matching the wildcard may be eligible to assume the role. Keep the IAM subject aligned with the intended deployment boundary.
4. Check the subject format AWS must match
Do not assume every repository emits the same sub format. GitHub’s AWS guide says repositories created after July 15, 2026, and repositories that opted in to immutable subject claims include immutable owner and repository IDs in the subject. The IAM trust condition must match the format actually issued for the repository. GitHub documents this behavior in its OpenID Connect reference and notes that the immutable format is not available on GitHub Enterprise Server.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How do I remove AWS access keys from the workflow?
Grant token-request permission to the job that needs AWS access, configure the AWS credentials action with the role ARN and region, and then run the AWS CLI or SDK commands. The following is a structural example; replace the role ARN and region with your values, and pin actions according to your repository’s supply-chain policy.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallname: Deploy
on:
push:
branches: [main]
permissions:
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
permissions:
contents: read
id-token: write
steps:
- uses: actions/checkout@<approved-commit-sha>
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@<approved-commit-sha>
with:
role-to-assume: arn:aws:iam::123456789012:role/YourGitHubActionsRole
aws-region: us-east-1
- name: Deploy
run: aws sts get-caller-identity
The id-token: write permission lets the workflow request and use an OIDC token; it does not itself grant permission to modify AWS resources. As GitHub puts it, “Setting id-token: write in the workflow’s permissions does not give the workflow permission to modify or write to any resources.” AWS access comes only after the role trust succeeds, and the role’s AWS permissions still apply.
Grant id-token: write at job level when only one job needs AWS federation. A workflow-level setting can be appropriate when several jobs need tokens, but job-level scope avoids granting that capability to unrelated jobs. Keep other GitHub permissions, such as contents, as narrow as the workflow allows.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Pin the checkout and credentials actions using the repository’s established action-pinning policy. The official example uses a commit SHA, but any specific SHA should be verified against the action release and your security policy rather than copied as a current recommendation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should the GitHub OIDC trust policy sub be?
Set sub to the narrowest GitHub identity that matches how deployment is supposed to work, and make sure its exact syntax matches the token GitHub issues. For a single deployment branch, use a branch-ref identity. For a protected environment, use the environment identity and enforce eligible branches or tags through GitHub’s environment protection rules. Avoid relying on custom OIDC claims: AWS does not support custom claims for this integration.
GitHub also notes a Dependabot-specific detail: OIDC tokens requested for Dependabot update jobs have an event_name claim of dynamic. If your trust strategy uses an event_name condition, account for that behavior only after confirming the precise claim and the relevant AWS condition support. Do not add a condition copied from a different token format without validating that it matches the workflow’s identity.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
How to verify the cutover safely
- Run the intended workflow from an identity allowed by the role’s trust policy. Confirm that the credentials action assumes the expected role and that the AWS command succeeds only for actions granted to that role.
- Try a workflow run from a branch, repository, or environment that should not qualify. Confirm that it cannot assume the role. If it can, tighten the trust policy subject or environment protections before relying on the setup.
- Once the OIDC path works and the access boundaries are verified, remove the obsolete AWS access-key secrets from GitHub and any workflow references to them.
These checks are part of validating your own configuration; a successful permitted run alone does not prove that unintended workflows are excluded.
GitHub Enterprise Server is a different issuer setup
This guide covers GitHub.com. GitHub Enterprise Server uses an issuer based on the instance hostname and path rather than GitHub.com’s issuer, and GitHub’s documentation calls for self-hosted runners in that setup. Do not reuse the GitHub.com provider URL and trust assumptions without checking the configuration for your GHES instance.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

