Skip to content

Instantly share code, notes, and snippets.

@tofran
Created August 2, 2026 11:43
Show Gist options
  • Select an option

  • Save tofran/9c861c3253cd3649e4ea1e218c46846f to your computer and use it in GitHub Desktop.

Select an option

Save tofran/9c861c3253cd3649e4ea1e218c46846f to your computer and use it in GitHub Desktop.
Helper script to generate the correct GitHub Actions OIDC sub claim for use in AWS IAM trust policies (and other cloud providers). Required for repositories created after July 15, 2026, which use an immutable format including numeric owner/repo IDs.
#!/usr/bin/env bash
# GitHub Actions OIDC subject claim helper
#
# Repositories created after July 15, 2026 use an immutable subject (sub) claim
# format that includes numeric owner and repo IDs instead of just names:
#
# New: repo:owner@OWNER_ID/repo@REPO_ID:ref:refs/heads/main
# Old: repo:owner/repo:ref:refs/heads/main
#
# This prevents subject claim reuse if a GitHub username or repo name is recycled
# by a different owner — which is a security risk for cloud trust policies (AWS IAM,
# GCP Workload Identity, etc.) that rely on the sub claim for access control.
#
# Repos created before July 15, 2026 keep the old format unless you opt in via
# the GitHub OIDC settings UI or REST API.
#
# More info: https://docs.github.com/en/actions/reference/security/oidc#immutable-subject-claims
#
set -euo pipefail
read -rp "GitHub owner (user or org): " OWNER
read -rp "Repository name: " REPO
OWNER_ID=$(curl -sf "https://api.github.com/users/$OWNER" | jq -r .id)
REPO_ID=$(curl -sf "https://api.github.com/repos/$OWNER/$REPO" | jq -r .id)
PREFIX="repo:$OWNER@$OWNER_ID/$REPO@$REPO_ID"
echo ""
echo "OIDC subject claim prefix: $PREFIX"
echo ""
echo "Examples:"
echo " Branch (main): $PREFIX:ref:refs/heads/main"
echo " Any branch: $PREFIX:ref:refs/heads/*"
echo " Pull request: $PREFIX:pull_request"
echo " Any: $PREFIX:*"
echo ""
echo "IAM trust policy condition (StringLike):"
echo " \"token.actions.githubusercontent.com:sub\": \"$PREFIX:*\""
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment