Skip to main content

Authenticating GitHub Actions to AWS Without Access Keys

Learn how to use OpenID Connect (OIDC) for GitHub Actions to obtain short-lived AWS credentials securely without key rotation.

AI-written
Inewgen
04 Oct 2026Source: Dev.to2 min read (0 views)
Share
Authenticating GitHub Actions to AWS Without Access Keys

Stock photo for illustration only, not from the actual event

Font size
  • Authenticate GitHub Actions to AWS using OIDC without static access keys
  • Configure the Identity Provider once per AWS account
  • Control access using Trust Policies specifying allowed repositories and branches
  • Workflows receive temporary credentials that expire automatically after the run

While working with GitHub Actions, developers can utilize OpenID Connect (OIDC) to authenticate directly to AWS. This approach allows workflows to acquire short-lived AWS credentials dynamically for each individual run, completely eliminating the need to store long-lived static access keys.

This method significantly improves security by removing the burden of rotating or managing persistent credentials that carry long-term risks. To get started in the AWS Console, navigate to IAM, select Identity providers, and add a new provider.

  • This setup needs to be performed only once per AWS account
  • Every role utilized by your workflows can share this single provider
  • Navigate to IAM, select Roles, and click Create role
  • Choose Web identity and select the newly created provider with the sts.amazonaws.com audience
AWS IAM console settings dashboard interface

Stock photo for illustration only, not from the actual event

Next, the trust policy controls precisely which GitHub repository and branch are permitted to assume this role. The policy structure must explicitly define these boundaries, accompanied by an attached permission policy limited strictly to the required actions, such as listing and uploading files to a single S3 bucket.

Adopting OIDC for cloud authentication represents a modern security best practice that eliminates hardcoded secrets in source control. By issuing ultra-short-lived tokens, organizations drastically minimize the attack surface, ensuring that even if credentials are intercepted, they quickly become invalid.

Source: Dev.to

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article