[metadata]
description: You can authenticate to the REST API to access more endpoints and have a higher rate limit.
google-site-verification: c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY
og:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
og:site_name: GitHub Docs
og:title: Authenticating to the REST API - GitHub Docs
og:type: article
og:url: https://docs-internal.github.com/en/rest/authentication/authenticating-to-the-rest-api?apiVersion=2026-03-10
page-document-type: article
path-article: rest/authentication/authenticating-to-the-rest-api
path-language: en
path-product: rest
path-version: free-pro-team@latest
status: 200
twitter:card: summary
twitter:description: You can authenticate to the REST API to access more endpoints and have a higher rate limit.
twitter:domain: docs-internal.github.com
twitter:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
twitter:title: Authenticating to the REST API - GitHub Docs
twitter:url: https://docs-internal.github.com/en/rest/authentication/authenticating-to-the-rest-api?apiVersion=2026-03-10
viewport: width=device-width, initial-scale=1

[document-links]
API Insights: /en/rest/orgs/api-insights
API Versions: /en/rest/about-the-rest-api/api-versions
About authentication with a GitHub App: /en/apps/creating-github-apps/authenticating-with-a-github-app/about-authentication-with-a-github-app
About the REST API: /en/rest/about-the-rest-api/about-the-rest-api
Actions concurrency groups: /en/rest/actions/concurrency-groups
Agent tasks: /en/rest/agent-tasks/agent-tasks
Alerts: /en/rest/dependabot/alerts
Artifact attestations: /en/rest/orgs/attestations
Artifact metadata: /en/rest/orgs/artifact-metadata
Artifacts: /en/rest/actions/artifacts
Ask the GitHub community: https://github.com/orgs/community/discussions
Assignees: /en/rest/issues/assignees
Attestations: /en/rest/repos/attestations
Attestations: /en/rest/users/attestations
Authenticating: /en/rest/authentication/authenticating-to-the-rest-api
Authentication: /en/rest/authentication
Authorizing a personal access token for use with single sign-on: /en/authentication/authenticating-with-single-sign-on/authorizing-a-personal-access-token-for-use-with-single-sign-on
Autolinks: /en/rest/repos/autolinks
Best practices: /en/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Billing usage: /en/rest/billing/usage
Blobs: /en/rest/git/blobs
Blocking users: /en/rest/orgs/blocking
Blocking users: /en/rest/users/blocking
Blog: https://github.blog
Branches: /en/rest/branches/branches
Breaking changes: /en/rest/about-the-rest-api/breaking-changes
Budgets: /en/rest/billing/budgets
Building a CI server: /en/rest/guides/building-a-ci-server
CORS and JSONP: /en/rest/using-the-rest-api/using-cors-and-jsonp-to-make-cross-origin-requests
Cache: /en/rest/actions/cache
Check runs: /en/rest/checks/runs
Check suites: /en/rest/checks/suites
Classroom: /en/rest/classroom/classroom
Cloud agent repository management: /en/rest/copilot/copilot-cloud-agent-management
Code quality: /en/rest/code-quality/code-quality
Code scanning: /en/rest/code-scanning/code-scanning
Codes of conduct: /en/rest/codes-of-conduct/codes-of-conduct
Codespaces: /en/rest/codespaces/codespaces
Collaborators: /en/rest/collaborators/collaborators
Collaborators: /en/rest/copilot-spaces/collaborators
Comments: /en/rest/gists/comments
Comments: /en/rest/issues/comments
Commit comments: /en/rest/commits/comments
Commit statuses: /en/rest/commits/statuses
Commits: /en/rest/commits/commits
Commits: /en/rest/git/commits
Community: /en/rest/metrics/community
Comparing GitHub's APIs: /en/rest/about-the-rest-api/comparing-githubs-rest-api-and-graphql-api
Configurations: /en/rest/code-security/configurations
Contact support: https://support.github.com
Contents: /en/rest/repos/contents
Copilot Spaces: /en/rest/copilot-spaces/copilot-spaces
Copilot cloud agent management: /en/rest/copilot/copilot-coding-agent-management
Copilot content exclusion management: /en/rest/copilot/copilot-content-exclusion-management
Copilot usage metrics: /en/rest/copilot/copilot-usage-metrics
Copilot user management: /en/rest/copilot/copilot-user-management
Custom patterns: /en/rest/secret-scanning/custom-patterns
Custom properties: /en/rest/orgs/custom-properties
Custom properties: /en/rest/repos/custom-properties
Delivering deployments: /en/rest/guides/delivering-deployments
Dependency review: /en/rest/dependency-graph/dependency-review
Dependency submission: /en/rest/dependency-graph/dependency-submission
Deploy keys: /en/rest/deploy-keys/deploy-keys
Deployment branch policies: /en/rest/deployments/branch-policies
Deployment statuses: /en/rest/deployments/statuses
Deployments: /en/rest/deployments/deployments
Discover resources for a user: /en/rest/guides/discovering-resources-for-a-user
Draft Project items: /en/rest/projects/drafts
Emails: /en/rest/users/emails
Emojis: /en/rest/emojis/emojis
Encrypt secrets: /en/rest/guides/encrypting-secrets-for-the-rest-api
Endpoints for GitHub App installation tokens: /en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens
Endpoints for GitHub App user tokens: /en/rest/authentication/endpoints-available-for-github-app-user-access-tokens
Endpoints for fine-grained PATs: /en/rest/authentication/endpoints-available-for-fine-grained-personal-access-tokens
Enterprise team members: /en/rest/enterprise-teams/enterprise-team-members
Enterprise team organizations: /en/rest/enterprise-teams/enterprise-team-organizations
Enterprise teams: /en/rest/enterprise-teams/enterprise-teams
Environments: /en/rest/deployments/environments
Events: /en/rest/activity/events
Events: /en/rest/issues/events
Expert services: https://services.github.com
Feeds: /en/rest/activity/feeds
Followers: /en/rest/users/followers
Forks: /en/rest/repos/forks
GPG keys: /en/rest/users/gpg-keys
Get started - Checks: /en/rest/guides/using-the-rest-api-to-interact-with-checks
Get started - Git database: /en/rest/guides/using-the-rest-api-to-interact-with-your-git-database
Getting started with the REST API: /en/rest/using-the-rest-api/getting-started-with-the-rest-api#authentication
Getting started with the REST API: /en/rest/using-the-rest-api/getting-started-with-the-rest-api?tool=cli#path
Getting started: /en/rest/using-the-rest-api/getting-started-with-the-rest-api
Gists: /en/rest/gists/gists
Git SSH keys: /en/rest/users/keys
GitHub Apps: /en/rest/apps/apps
GitHub Docs: /en
GitHub event types: /en/rest/using-the-rest-api/github-event-types
GitHub-hosted runners: /en/rest/actions/hosted-runners
Gitignore: /en/rest/gitignore/gitignore
Global security advisories: /en/rest/security-advisories/global-advisories
Home: /en
Installations: /en/rest/apps/installations
Invitations: /en/rest/collaborators/invitations
Issue dependencies: /en/rest/issues/issue-dependencies
Issue event types: /en/rest/using-the-rest-api/issue-event-types
Issue field values: /en/rest/issues/issue-field-values
Issue fields: /en/rest/orgs/issue-fields
Issue types: /en/rest/orgs/issue-types
Issue types: /en/rest/repos/issue-types
Issues: /en/rest/issues/issues
Keeping API credentials secure: /en/rest/authentication/keeping-your-api-credentials-secure
Keeping your API credentials secure: /en/rest/authentication/keeping-your-api-credentials-secure
Keeping your API credentials secure: /en/rest/authentication/keeping-your-api-credentials-secure?apiVersion=2022-11-28
Labels: /en/rest/issues/labels
Learn how to contribute: /contributing
Libraries: /en/rest/using-the-rest-api/libraries-for-the-rest-api
Licenses: /en/rest/licenses/licenses
Machines: /en/rest/codespaces/machines
Make a contribution: https://github.com/github/docs/blob/main/content/rest/authentication/authenticating-to-the-rest-api.md
Managing your personal access tokens: /en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens
Markdown: /en/rest/markdown/markdown
Marketplace: /en/rest/apps/marketplace
Members: /en/rest/orgs/members
Members: /en/rest/teams/members
Meta: /en/rest/meta/meta
Milestones: /en/rest/issues/milestones
Network configurations: /en/rest/orgs/network-configurations
Notifications: /en/rest/activity/notifications
OAuth authorizations: /en/rest/apps/oauth-applications
OIDC: /en/rest/actions/oidc
OpenAPI description: /en/rest/about-the-rest-api/about-the-openapi-description-for-the-rest-api
Organization configurations: /en/rest/private-registries/organization-configurations
Organization roles: /en/rest/orgs/organization-roles
Organization secrets: /en/rest/codespaces/organization-secrets
Organization: /en/rest/interactions/orgs
Organizations: /en/rest/codespaces/organizations
Organizations: /en/rest/migrations/orgs
Organizations: /en/rest/orgs/orgs
Outside collaborators: /en/rest/orgs/outside-collaborators
Packages: /en/rest/packages/packages
Pages: /en/rest/pages/pages
Pagination: /en/rest/using-the-rest-api/using-pagination-in-the-rest-api
Permissions for GitHub Apps: /en/rest/authentication/permissions-required-for-github-apps
Permissions for fine-grained PATs: /en/rest/authentication/permissions-required-for-fine-grained-personal-access-tokens
Permissions required for GitHub Apps: /en/rest/authentication/permissions-required-for-github-apps
Permissions required for fine-grained personal access tokens: /en/rest/authentication/permissions-required-for-fine-grained-personal-access-tokens
Permissions: /en/rest/actions/permissions
Personal access tokens: /en/rest/orgs/personal-access-tokens
Pricing: https://github.com/pricing
Privacy policy: /en/site-policy/privacy-policies/github-privacy-statement
Privacy: /en/site-policy/privacy-policies/github-privacy-statement
Project fields: /en/rest/projects/fields
Project items: /en/rest/projects/items
Project views: /en/rest/projects/views
Projects: /en/rest/projects/projects
Protected branches: /en/rest/branches/branch-protection
Protection rules: /en/rest/deployments/protection-rules
Pull requests: /en/rest/pulls/pulls
Push protection: /en/rest/secret-scanning/push-protection
Quickstart: /en/rest/quickstart
REST API: /en/rest
Rate limit: /en/rest/rate-limit/rate-limit
Rate limits for the REST API: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Rate limits: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Reactions: /en/rest/reactions/reactions
References: /en/rest/git/refs
Release assets: /en/rest/releases/assets
Releases: /en/rest/releases/releases
Rendering data as graphs: /en/rest/guides/rendering-data-as-graphs
Repositories: /en/rest/repos/repos
Repository access: /en/rest/dependabot/repository-access
Repository secrets: /en/rest/codespaces/repository-secrets
Repository security advisories: /en/rest/security-advisories/repository-advisories
Repository: /en/rest/interactions/repos
Resources: /en/rest/copilot-spaces/resources
Review comments: /en/rest/pulls/comments
Review requests: /en/rest/pulls/review-requests
Reviews: /en/rest/pulls/reviews
Revocation: /en/rest/credentials/revoke
Rule suites: /en/rest/orgs/rule-suites
Rule suites: /en/rest/repos/rule-suites
Rules: /en/rest/orgs/rules
Rules: /en/rest/repos/rules
SSH signing keys: /en/rest/users/ssh-signing-keys
Scopes for OAuth apps: /en/apps/oauth-apps/building-oauth-apps/scopes-for-oauth-apps#available-scopes
Script with JavaScript: /en/rest/guides/scripting-with-the-rest-api-and-javascript
Script with Ruby: /en/rest/guides/scripting-with-the-rest-api-and-ruby
Scripting with the REST API and JavaScript: /en/rest/guides/scripting-with-the-rest-api-and-javascript#authenticating-in-github-actions
Search: /en/rest/search/search
Secret scanning: /en/rest/secret-scanning/secret-scanning
Secrets: /en/rest/actions/secrets
Secrets: /en/rest/agents/secrets
Secrets: /en/rest/dependabot/secrets
Security campaigns: /en/rest/campaigns/campaigns
Security managers: /en/rest/orgs/security-managers
Self-hosted runner groups: /en/rest/actions/self-hosted-runner-groups
Self-hosted runners: /en/rest/actions/self-hosted-runners
Sign up: https://github.com/signup?ref_cta=Sign+up&ref_loc=docs+header&ref_page=docs
Social accounts: /en/rest/users/social-accounts
Software bill of materials (SBOM): /en/rest/dependency-graph/sboms
Source endpoints: /en/rest/migrations/source-imports
Stacked pull requests: /en/rest/pulls/stacks
Starring: /en/rest/activity/starring
Statistics: /en/rest/metrics/statistics
Status: https://www.githubstatus.com/
Sub-issues: /en/rest/issues/sub-issues
Tags: /en/rest/git/tags
Teams: /en/rest/teams/teams
Terms: /en/site-policy/github-terms/github-terms-of-service
Timeline: /en/rest/issues/timeline
Timezones: /en/rest/using-the-rest-api/timezones-and-the-rest-api
Traffic: /en/rest/metrics/traffic
Trees: /en/rest/git/trees
Troubleshooting: /en/rest/using-the-rest-api/troubleshooting-the-rest-api
Use GITHUB_TOKEN for authentication in workflows: /en/actions/tutorials/authenticate-with-github_token#modifying-the-permissions-for-the-github_token
User secrets: /en/rest/codespaces/secrets
User: /en/rest/interactions/user
Users: /en/rest/migrations/users
Users: /en/rest/users/users
Using secrets in GitHub Actions: /en/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets
Variables: /en/rest/actions/variables
Variables: /en/rest/agents/variables
Watching: /en/rest/activity/watching
Webhooks: /en/rest/apps/webhooks
Webhooks: /en/rest/orgs/webhooks
Webhooks: /en/rest/repos/webhooks
Workflow jobs: /en/rest/actions/workflow-jobs
Workflow runs: /en/rest/actions/workflow-runs
Workflow syntax for GitHub Actions: /en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idstepsrun
Workflows: /en/rest/actions/workflows
Working with comments: /en/rest/guides/working-with-comments

[content]
Authenticating to the REST API - GitHub Docs
Skip to main content
GitHub Docs
Version:
Free, Pro, & Team
Search or ask Copilot
Search or ask
Copilot
Select language: current language is English
Sign up
Search or ask Copilot
Search or ask
Copilot
Open menu
Collapse sidebar
Expand sidebar
Scroll breadcrumbs left
Home
REST API
Authentication
Authenticating
Scroll breadcrumbs right
REST API
API Version:
2026-03-10 (latest)
Quickstart
About the REST API
About the REST API
Comparing GitHub's APIs
API Versions
Breaking changes
OpenAPI description
Using the REST API
Getting started
Rate limits
Pagination
Libraries
Best practices
Troubleshooting
Timezones
CORS and JSONP
Issue event types
GitHub event types
Authentication
Authenticating
Keeping API credentials secure
Endpoints for GitHub App installation tokens
Endpoints for GitHub App user tokens
Endpoints for fine-grained PATs
Permissions for GitHub Apps
Permissions for fine-grained PATs
Guides
Script with JavaScript
Script with Ruby
Discover resources for a user
Delivering deployments
Rendering data as graphs
Working with comments
Building a CI server
Get started - Git database
Get started - Checks
Encrypt secrets
Actions
Artifacts
Cache
Actions concurrency groups
GitHub-hosted runners
OIDC
Permissions
Secrets
Self-hosted runner groups
Self-hosted runners
Variables
Workflow jobs
Workflow runs
Workflows
Activity
Events
Feeds
Notifications
Starring
Watching
Agent tasks
Agent tasks
Agents
Secrets
Variables
Apps
GitHub Apps
Installations
Marketplace
OAuth authorizations
Webhooks
Billing
Budgets
Billing usage
Branches
Branches
Protected branches
Campaigns
Security campaigns
Checks
Check runs
Check suites
Classroom
Classroom
Code quality
Code quality
Code scanning
Code scanning
Code security settings
Configurations
Codes of conduct
Codes of conduct
Codespaces
Codespaces
Organizations
Organization secrets
Machines
Repository secrets
User secrets
Collaborators
Collaborators
Invitations
Commits
Commits
Commit comments
Commit statuses
Copilot
Cloud agent repository management
Copilot cloud agent management
Copilot content exclusion management
Copilot usage metrics
Copilot user management
Copilot Spaces
Collaborators
Copilot Spaces
Resources
Credentials
Revocation
Dependabot
Alerts
Repository access
Secrets
Dependency graph
Dependency review
Dependency submission
Software bill of materials (SBOM)
Deploy keys
Deploy keys
Deployments
Deployment branch policies
Deployments
Environments
Protection rules
Deployment statuses
Emojis
Emojis
Enterprise teams
Enterprise team members
Enterprise team organizations
Enterprise teams
Gists
Gists
Comments
Git database
Blobs
Commits
References
Tags
Trees
Gitignore
Gitignore
Interactions
Organization
Repository
User
Issues
Assignees
Comments
Events
Issue dependencies
Issue field values
Issues
Labels
Milestones
Sub-issues
Timeline
Licenses
Licenses
Markdown
Markdown
Meta
Meta
Metrics
Community
Statistics
Traffic
Migrations
Organizations
Source endpoints
Users
Organizations
API Insights
Artifact metadata
Artifact attestations
Blocking users
Custom properties
Issue fields
Issue types
Members
Network configurations
Organization roles
Organizations
Outside collaborators
Personal access tokens
Rule suites
Rules
Security managers
Webhooks
Packages
Packages
Pages
Pages
Private registries
Organization configurations
Projects
Draft Project items
Project fields
Project items
Projects
Project views
Pull requests
Review comments
Pull requests
Review requests
Reviews
Stacked pull requests
Rate limit
Rate limit
Reactions
Reactions
Releases
Releases
Release assets
Repositories
Attestations
Autolinks
Contents
Custom properties
Forks
Issue types
Repositories
Rule suites
Rules
Webhooks
Search
Search
Secret scanning
Custom patterns
Push protection
Secret scanning
Security advisories
Global security advisories
Repository security advisories
Teams
Members
Teams
Users
Attestations
Blocking users
Emails
Followers
GPG keys
Git SSH keys
Social accounts
SSH signing keys
Users
Authenticating to the REST API
You can authenticate to the REST API to access more endpoints and have a higher rate limit.
Copy as Markdown
In this article
About authentication
Authenticating with a personal access token
Authenticating with a token generated by an app
Authenticating in a GitHub Actions workflow
Authenticating with username and password
Further reading
About authentication
Many REST API endpoints require authentication or return additional information if you are authenticated. Additionally, you can make more requests per hour when you are authenticated.
To authenticate your request, you will need to provide an authentication token with the required scopes or permissions. There a few different ways to get a token: You can create a personal access token, generate a token with a GitHub App, or use the built-in
GITHUB_TOKEN
in a GitHub Actions workflow.
After creating a token, you can authenticate your request by sending the token in the
Authorization
header of your request. For example, in the following request, replace
YOUR-TOKEN
with a reference to your token:
curl --request GET \ --url "https://api.github.com/octocat" \ --header "Authorization: Bearer YOUR-TOKEN" \ --header "X-GitHub-Api-Version: 2026-03-10"
Note
In most cases, you can use
Authorization: Bearer
or
Authorization: token
to pass a token. However, if you are passing a JSON web token (JWT), you must use
Authorization: Bearer
.
Failed login limit
If you try to use a REST API endpoint without a token or with a token that has insufficient permissions, you will receive a
404 Not Found
or
403 Forbidden
response. Authenticating with invalid credentials will initially return a
401 Unauthorized
response.
After detecting several requests with invalid credentials within a short period, the API will temporarily reject all authentication attempts for that user (including ones with valid credentials) with a
403 Forbidden
response. For more information, see
Rate limits for the REST API
.
Authenticating with a personal access token
If you want to use the GitHub REST API for personal use, you can create a personal access token. If possible, GitHub recommends that you use a fine-grained personal access token instead of a personal access token (classic). For more information about creating a personal access token, see
Managing your personal access tokens
.
If you are using a fine-grained personal access token, your fine-grained personal access token requires specific permissions in order to access each REST API endpoint. The REST API reference document for each endpoint states whether the endpoint works with fine-grained personal access tokens and states what permissions are required in order for the token to use the endpoint. Some endpoints may require multiple permissions, and some endpoints may require one of multiple permissions. For an overview of which REST API endpoints a fine-grained personal access token can access with each permission, see
Permissions required for fine-grained personal access tokens
.
If you are using a personal access token (classic), it requires specific scopes in order to access each REST API endpoint. For general guidance about what scopes to choose, see
Scopes for OAuth apps
.
Personal access tokens act as your identity (limited by the scopes or permissions you selected) when you make requests to the REST API. As such, it is important to keep your personal access tokens secure. For more information about keeping your personal access tokens secure, see
Keeping your API credentials secure
.
Personal access tokens and SAML SSO
If you use a personal access token (classic) to access an organization that enforces SAML single sign-on (SSO) for authentication, you will need to authorize your token after creation. Fine-grained personal access tokens are authorized during token creation, before access to the organization is granted. For more information, see
Authorizing a personal access token for use with single sign-on
.
If you do not authorize your personal access token (classic) for SAML SSO before you try to use it to access a single organization that enforces SAML SSO, you may receive a
404 Not Found
or a
403 Forbidden
error. If you receive a
403 Forbidden
error, the
X-GitHub-SSO
header will include a URL that you can follow to authorize your token. The URL expires after one hour.
If you do not authorize your personal access token (classic) for SAML SSO before you try to use it to access multiple organizations, the API will not return results from the organizations that require SAML SSO and the
X-GitHub-SSO
header will indicate the ID of the organizations that require SAML SSO authorization of your personal access token (classic). For example:
X-GitHub-SSO: partial-results; organizations=21955855,20582480
.
Authenticating with a token generated by an app
If you want to use the API for an organization or on behalf of another user, GitHub recommends that you use a GitHub App. For more information, see
About authentication with a GitHub App
.
The REST API reference documentation for each endpoint states whether the endpoint works with GitHub Apps and states what permissions are required in order for the app to use the endpoint. Some endpoints may require multiple permissions, and some endpoints may require one of multiple permissions. For an overview of which REST API endpoints a GitHub App can access with each permission, see
Permissions required for GitHub Apps
.
You can also create an OAuth token with an OAuth app to access the REST API. However, GitHub recommends that you use a GitHub App instead. GitHub Apps allow more control over the access and permission that the app has.
Access tokens created by apps are automatically authorized for SAML SSO.
Using basic authentication
Some REST API endpoints for GitHub Apps and OAuth apps require you to use basic authentication to access the endpoint. You will use the app's client ID as the username and the app's client secret as the password.
For example:
curl --request POST \ --url "https://api.github.com/applications/YOUR_CLIENT_ID/token" \ --user "YOUR_CLIENT_ID:YOUR_CLIENT_SECRET" \ --header "Accept: application/vnd.github+json" \ --header "X-GitHub-Api-Version: 2026-03-10" \ --data '{ "access_token": "ACCESS_TOKEN_TO_CHECK" }'
The client ID and client secret are associated with the app, not with the owner of the app or a user who authorized the app. They are used to perform operations on behalf of the app, such as creating access tokens.
If you are the owner of a GitHub App or OAuth app, or if you are an app manager for a GitHub App, you can find the client ID and generate a client secret on the settings page for your app. To navigate to your app's settings page:
In the upper-right corner of any page on GitHub, click your profile picture.
Navigate to your account settings.
For an app owned by a personal account, click
Settings
.
For an app owned by an organization:
Click
Your organizations
.
To the right of the organization, click
Settings
.
In the left sidebar, click
Developer settings
.
In the left sidebar, click
GitHub Apps
or
OAuth apps
.
For GitHub Apps, to the right of the GitHub App you want to access, click
Edit
. For OAuth apps, click the app that you want to access.
Next to
Client ID
, you will see the client ID for your app.
Next to
Client secrets
, click
Generate a new client secret
to generate a client secret for your app.
Authenticating in a GitHub Actions workflow
If you want to use the API in a GitHub Actions workflow, GitHub recommends that you authenticate with the built-in
GITHUB_TOKEN
instead of creating a token. You can grant permissions to the
GITHUB_TOKEN
with the
permissions
key. For more information, see
Use GITHUB_TOKEN for authentication in workflows
.
If this is not possible, you can store your token as a secret and use the name of your secret in your GitHub Actions workflow. For more information about secrets, see
Using secrets in GitHub Actions
.
Authenticating in a GitHub Actions workflow using GitHub CLI
To make an authenticated request to the API in a GitHub Actions workflow using GitHub CLI, you can store the value of
GITHUB_TOKEN
as an environment variable, and use the
run
keyword to execute the GitHub CLI
api
subcommand. For more information about the
run
keyword, see
Workflow syntax for GitHub Actions
.
In the following example workflow, replace
PATH
with the path of the endpoint. For more information about the path, see
Getting started with the REST API
.
jobs:
use_api:
runs-on:
ubuntu-latest
permissions:
{}
steps:
-
env:
GH_TOKEN:
${{
secrets.GITHUB_TOKEN
}}
run:
| gh api /PATH
Authenticating in a GitHub Actions workflow using
curl
To make an authenticated request to the API in a GitHub Actions workflow using
curl
, you can store the value of
GITHUB_TOKEN
as an environment variable, and use the
run
keyword to execute a
curl
request to the API. For more information about the
run
keyword, see
Workflow syntax for GitHub Actions
.
In the following example workflow, replace
PATH
with the path of the endpoint. For more information about the path, see
Getting started with the REST API
.
YAML
jobs: use_api: runs-on: ubuntu-latest permissions: {} steps: - env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | curl --request GET \ --url "https://api.github.com/PATH" \ --header "Authorization: Bearer $GH_TOKEN"
jobs:
use_api:
runs-on:
ubuntu-latest
permissions:
{}
steps:
-
env:
GH_TOKEN:
${{
secrets.GITHUB_TOKEN
}}
run:
| curl --request GET \ --url "https://api.github.com/PATH" \ --header "Authorization: Bearer $GH_TOKEN"
Authenticating in a GitHub Actions workflow using JavaScript
For an example of how to authenticate in a GitHub Actions workflow using JavaScript, see
Scripting with the REST API and JavaScript
.
Authenticating with username and password
Authentication with username and password is not supported. If you try to authenticate with user name and password, you will receive a 4xx error.
Further reading
Keeping your API credentials secure
Getting started with the REST API
Help and support
Did you find what you needed?
Yes
No
Privacy policy
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
Learn how to contribute
Still need help?
Ask the GitHub community
Contact support
Legal
©
2026
GitHub, Inc.
Terms
Privacy
Status
Pricing
Expert services
Blog
