Skip to main content
Prisma Documentation Docs

Search documentation

Type to search this documentation.

Exchange a GitHub Actions OIDC token for a workspace service token

POST/v1/auth/github-actions/tokenExchange a GitHub Actions OIDC token for a workspace service token

⚠️ Experimental endpoint: this API is in active development and may change at any time without notice. ⚠️

Verifies the GitHub Actions OIDC token and mints a short-lived workspace service token. The caller must request the token with audience prisma-cloud. Any verification failure returns a generic 401 — the response never reveals whether a repository is connected.

Request body

application/json
object
expiresInSecondsinteger

Requested token lifetime in seconds. Defaults to 1800 (30 min); capped at 3600 (60 min).

default 1800 · maximum 3600 · minimum 60

tokenstringrequired

The GitHub Actions OIDC token with audience `prisma-cloud`.

minLength 1

Example request
{
  "expiresInSeconds": 1800,
  "token": "string"
}

Responses

201Minted a short-lived workspace service token.application/json
object
dataobjectrequired
Show child attributes
expiresAtstring · date-timerequired

ISO 8601 instant after which the token is invalid.

idstringrequired

Prefixed integration token ID (`itgr_` prefix).

typestringrequired

const "serviceToken"

valuestringrequired

The minted integration token. Returned once — copy it immediately.

workspaceIdstringrequired

Prefixed workspace ID the token is scoped to.

Example response
{
  "data": {
    "expiresAt": "2026-06-09T00:00:00Z",
    "id": "string",
    "type": "serviceToken",
    "value": "string",
    "workspaceId": "string"
  }
}
401Missing, expired, or invalid OIDC token, or no active repository link.application/json
object
errorstringrequired

const "unauthorized"

errorDescriptionstringrequired
Example response
{
  "error": "unauthorized",
  "errorDescription": "string"
}
429Rate limit exceeded.application/json
object
errorobjectrequired
Show child attributes
codestringrequired
hintstring
messagestringrequired
Example response
{
  "error": {
    "code": "string",
    "hint": "string",
    "message": "string"
  }
}
Documentation menu