Trust a GitHub repository to exchange OIDC tokens for keys (dashboard session only)
POST
/auth/github-oidc/trusts
const url = 'https://api.krakenkey.io/auth/github-oidc/trusts';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"name":"pfe renewal","repository":"krakenkey/website","repositoryId":"123456789","allowedRefs":["example"],"environment":"example","scopes":["certs:read"],"allowedDomainIds":["example"],"allowedCertIds":[1]}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.krakenkey.io/auth/github-oidc/trusts \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "name": "pfe renewal", "repository": "krakenkey/website", "repositoryId": "123456789", "allowedRefs": [ "example" ], "environment": "example", "scopes": [ "certs:read" ], "allowedDomainIds": [ "example" ], "allowedCertIds": [ 1 ] }'Authorizations
Section titled “Authorizations”Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
name
required
string
Example
pfe renewalrepository
required
string
Example
krakenkey/websiterepositoryId
GitHub’s numeric repository id, to pin the policy before its first run. Find it with gh api repos/OWNER/NAME --jq .id. Public repositories are looked up automatically when omitted.
string
Example
123456789allowedRefs
Refs allowed to exchange tokens, e.g. refs/heads/main or refs/tags/v*. Omit for any ref.
Array<string>
environment
Only jobs in this GitHub environment match
string
scopes
Array<string>
allowedDomainIds
Array<string>
allowedCertIds
Array<number>
Responses
Section titled “Responses”Trust policy created