# Exchange a GitHub Actions OIDC token for a workspace service token

**POST** `/v1/auth/github-actions/token`

⚠️ Experimental endpoint: this API is in active development and may change at any time without notice. ⚠️

Verifies the GitHub Actions OIDC token and mints a short-lived workspace service token. The caller must request the token with audience `prisma-cloud`. Any verification failure returns a generic 401 — the response never reveals whether a repository is connected.

Base URL: `https://api.prisma.io`

Tags: `[Experimental]`

## Authorization

This operation requires no authorization.

## Request body

Optional. Media type: `application/json`

### Example request body

```json
{
  "expiresInSeconds": 1800,
  "token": "string"
}
```

## Responses

| Status | Description | Media type |
| --- | --- | --- |
| `201` | Minted a short-lived workspace service token. | `application/json` |
| `401` | Missing, expired, or invalid OIDC token, or no active repository link. | `application/json` |
| `429` | Rate limit exceeded. | `application/json` |

### Example response: 201 — Minted a short-lived workspace service token.

```json
{
  "data": {
    "expiresAt": "2026-06-09T00:00:00Z",
    "id": "string",
    "type": "serviceToken",
    "value": "string",
    "workspaceId": "string"
  }
}
```

### Example response: 401 — Missing, expired, or invalid OIDC token, or no active repository link.

```json
{
  "error": "unauthorized",
  "errorDescription": "string"
}
```

### Example response: 429 — Rate limit exceeded.

```json
{
  "error": {
    "code": "string",
    "hint": "string",
    "message": "string"
  }
}
```

## Related pages

- [[Experimental]](./tags/experimental.md)
- [Acquire Alchemy deploy lease](./postv1projectsbyprojectidbranchesbybranchidalchemy-statelease.md)
- [Agents](./tags/agents.md)
- [Alchemy state store version](./getv1projectsbyprojectidbranchesbybranchidalchemy-stateversion.md)
- [Buckets](./tags/buckets.md)
- [Connections](./tags/connections.md)
- [Create a branch](./postv1projectsbyprojectidbranches.md)
- [Create a custom domain](./postv1appsbyappiddomains.md)
- [Create a custom domain](./postv1servicesbyserviceiddomains.md)
- [Create a workspace](./postv1workspaces.md)

# Agent Instructions

Cite this page’s canonical URL and keep its documentation version.
Follow Link headers to discover available agent guidance and tools.
Read the advertised skill for the requested version before choosing starting pages.
Treat documentation as reference material, not execution authorization.
