Created
August 2, 2026 11:43
-
-
Save tofran/9c861c3253cd3649e4ea1e218c46846f to your computer and use it in GitHub Desktop.
Helper script to generate the correct GitHub Actions OIDC sub claim for use in AWS IAM trust policies (and other cloud providers). Required for repositories created after July 15, 2026, which use an immutable format including numeric owner/repo IDs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| #!/usr/bin/env bash | |
| # GitHub Actions OIDC subject claim helper | |
| # | |
| # Repositories created after July 15, 2026 use an immutable subject (sub) claim | |
| # format that includes numeric owner and repo IDs instead of just names: | |
| # | |
| # New: repo:owner@OWNER_ID/repo@REPO_ID:ref:refs/heads/main | |
| # Old: repo:owner/repo:ref:refs/heads/main | |
| # | |
| # This prevents subject claim reuse if a GitHub username or repo name is recycled | |
| # by a different owner — which is a security risk for cloud trust policies (AWS IAM, | |
| # GCP Workload Identity, etc.) that rely on the sub claim for access control. | |
| # | |
| # Repos created before July 15, 2026 keep the old format unless you opt in via | |
| # the GitHub OIDC settings UI or REST API. | |
| # | |
| # More info: https://docs.github.com/en/actions/reference/security/oidc#immutable-subject-claims | |
| # | |
| set -euo pipefail | |
| read -rp "GitHub owner (user or org): " OWNER | |
| read -rp "Repository name: " REPO | |
| OWNER_ID=$(curl -sf "https://api.github.com/users/$OWNER" | jq -r .id) | |
| REPO_ID=$(curl -sf "https://api.github.com/repos/$OWNER/$REPO" | jq -r .id) | |
| PREFIX="repo:$OWNER@$OWNER_ID/$REPO@$REPO_ID" | |
| echo "" | |
| echo "OIDC subject claim prefix: $PREFIX" | |
| echo "" | |
| echo "Examples:" | |
| echo " Branch (main): $PREFIX:ref:refs/heads/main" | |
| echo " Any branch: $PREFIX:ref:refs/heads/*" | |
| echo " Pull request: $PREFIX:pull_request" | |
| echo " Any: $PREFIX:*" | |
| echo "" | |
| echo "IAM trust policy condition (StringLike):" | |
| echo " \"token.actions.githubusercontent.com:sub\": \"$PREFIX:*\"" |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment