Skip to content

OIDC custom properties as claims #1230

@glider-bot

Description

@glider-bot

Value Prop

GitHub Actions OIDC now supports custom repository properties as claims, enabling platform and security teams to embed rich metadata directly into every token issued from a repository. This structured identity context allows cloud providers, artifact registries, and secrets brokers to enforce attribute-based access control (ABAC) without any workflow-level configuration changes.

Expected Outcome

Teams can expect to eliminate hard-coded allow lists and manual policy exceptions. Replacing them with version controlled repository attributes that automatically propagate into cloud IAM trust policies at scale. Organizations will achieve least-privilege access across hundreds or thousands of repositories with a one-time policy investment, reducing operational burden and improving auditability across every workflow run.

Metadata

Metadata

Assignees

No one assigned

    Labels

    EnterpriseProduct SKU: GitHub EnterpriseFreeProduct SKU: GitHub FreePublic PreviewTeamProduct SKU: GitHub Team

    Type

    No type

    Projects

    Status

    Q1 2026 – Jan-Mar

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions