POST
/v1/auth/github-actions/tokenExchange a GitHub Actions OIDC token for a workspace service token⚠️ Experimental endpoint: this API is in active development and may change at any time without notice. ⚠️
Verifies the GitHub Actions OIDC token and mints a short-lived workspace service token. The caller must request the token with audience prisma-cloud. Any verification failure returns a generic 401 — the response never reveals whether a repository is connected.
Request body
application/json
object
expiresInSecondsintegerRequested token lifetime in seconds. Defaults to 1800 (30 min); capped at 3600 (60 min).
tokenstringrequiredThe GitHub Actions OIDC token with audience `prisma-cloud`.
{
"expiresInSeconds": 1800,
"token": "string"
}Responses
object
dataobjectrequiredShow child attributes
expiresAtstring · date-timerequiredISO 8601 instant after which the token is invalid.
idstringrequiredPrefixed integration token ID (`itgr_` prefix).
typestringrequiredvaluestringrequiredThe minted integration token. Returned once — copy it immediately.
workspaceIdstringrequiredPrefixed workspace ID the token is scoped to.
{
"data": {
"expiresAt": "2026-06-09T00:00:00Z",
"id": "string",
"type": "serviceToken",
"value": "string",
"workspaceId": "string"
}
}object
errorstringrequirederrorDescriptionstringrequired{
"error": "unauthorized",
"errorDescription": "string"
}object
errorobjectrequiredShow child attributes
codestringrequiredhintstringmessagestringrequired{
"error": {
"code": "string",
"hint": "string",
"message": "string"
}
}