Skip to content

Trust a GitHub repository to exchange OIDC tokens for keys (dashboard session only)

POST
/auth/github-oidc/trusts
curl --request POST \
--url https://api.krakenkey.io/auth/github-oidc/trusts \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{ "name": "pfe renewal", "repository": "krakenkey/website", "repositoryId": "123456789", "allowedRefs": [ "example" ], "environment": "example", "scopes": [ "certs:read" ], "allowedDomainIds": [ "example" ], "allowedCertIds": [ 1 ] }'
Media typeapplication/json
object
name
required
string
Example
pfe renewal
repository
required
string
Example
krakenkey/website
repositoryId

GitHub’s numeric repository id, to pin the policy before its first run. Find it with gh api repos/OWNER/NAME --jq .id. Public repositories are looked up automatically when omitted.

string
Example
123456789
allowedRefs

Refs allowed to exchange tokens, e.g. refs/heads/main or refs/tags/v*. Omit for any ref.

Array<string>
environment

Only jobs in this GitHub environment match

string
scopes
Array<string>
Allowed values: certs:read certs:issue certs:renew certs:revoke domains:read domains:write endpoints:read endpoints:write probes:report account:read account:write
allowedDomainIds
Array<string>
allowedCertIds
Array<number>

Trust policy created