Skip to main content
If an administrator has connected your GitHub organization to your 1Password Business account, you can use 1Password to broker access to secrets from your 1Password Environments in your organization’s GitHub Actions workflows at runtime.

Step 1: Set up an Environment

To configure the variables you need to use in a GitHub Actions workflow, make sure you have the latest version of the 1Password desktop app, then create a new 1Password Environment with your variables or add your variables to an existing Environment.

Step 2: Connect your Environment to your GitHub Actions workflow

After you’ve set up an Environment and added your secrets, you can connect the Environment to your GitHub Actions workflow:
  1. Open your Environment, then select Connect in the GitHub Actions section.
    If you’ve already connected your Environment to a workflow, select Connect instead, then select Connect in the GitHub Actions section.
  2. Select the integration field, then choose the integration for the GitHub organization you need.
  3. Enter the name of the repository where your workflow needs to run.
  4. (Optional) Specify if you want to restrict access to a specific GitHub Actions workflow, environment, or branch in your repository.
  5. Select Add workflow.

Step 3: Modify your GitHub Actions workflow

After you’ve connected your Environment to GitHub Actions, copy the snippet from the 1Password desktop app and include it in a GitHub Actions workflow in order to reference any secrets in your Environment. You can choose from two methods to reference variables in your workflow:
  • If you include export-env: "true" as an import parameter to the step you copied into your workflow, you can reference the variables with the following structure: ${{ env.<variable-name> }}
  • If you add a unique identifier to the step you copied into your workflow, you can reference the variables with the following structure: ${{ steps.<id>.outputs.<variable-name> }}
The specific steps you’ll need to follow will vary depending on your workflow setup. Refer to the GitHub Actions documentation for more information on how to use workflows.

Usage example

The following example shows how to use 1Password Credential Broker to load a username and token variable from an Environment, then use them to sign in to Docker Hub.
config.yml

Get help

If you don’t see GitHub Actions as a destination in the 1Password desktop app, make sure your administrator has connected your GitHub organization to your 1Password account. If you see an OIDC-related error in your workflow log in GitHub, make sure you have id-token: write set in the permissions within your workflow. . This permission allows GitHub to generate a short-lived token that 1Password uses to identify your workflow before supplying your secrets at runtime.

Learn more