Skip to main content

Command referencegh secret set

gh secret set command (Linux & Windows / GitHub CLI)

Linux & WindowsGitHub CLIgitintermediate

What it does

Create or update an Actions secret for a repository, environment, or organization. When people search for gh secret set, they usually want practical GitHub CLI flags, safe examples, and how this subcommand fits everyday PR and repo workflows on Linux, Windows, and macOS. Syntax, options, and copyable examples are below.

Create or update an Actions secret for a repository, environment, or organization.

Syntax

gh secret set <secret-name> [flags]

Common options

Flag / optionMeaning
-a, --appApplication: actions, codespaces, or dependabot.
-b, --bodySecret value (prefer stdin in scripts).
-e, --envEnvironment name for environment secrets.
-o, --orgSet an organization secret.
-r, --reposRepo access list for org secrets.

Practical examples

From stdin

printf '%s' "$API_KEY" | gh secret set API_KEY

Sets a repository Actions secret without putting it in argv.

Environment secret

gh secret set DEPLOY_KEY --env production < deploy_key.pem

Stores a secret on the production environment.

Literal body (local only)

gh secret set DEMO_FLAG --body "1"

Fine for non-sensitive flags; avoid for real credentials.

Common mistakes

  • Passing secrets on the command line where shell history can capture them.
  • Setting a repository secret when the workflow expects an environment secret.

FAQ

What does gh secret set do in GitHub CLI?

Create or update an Actions secret for a repository, environment, or organization.

Does gh secret set work on Windows and Linux?

Yes. The GitHub CLI (`gh`) runs on Linux, Windows, and macOS with the same subcommand syntax after you authenticate with `gh auth login`.

What is a practical gh secret set example?

Try `printf '%s' "$API_KEY" | gh secret set API_KEY` — Sets a repository Actions secret without putting it in argv.

Do I need a token in the command line for gh secret set?

Prefer `gh auth login` so credentials stay in the system keyring or secure storage. Avoid pasting personal access tokens into shell history.

Browse the full Linux and Windows command reference to search more bash, CMD, PowerShell, Conda, and GitHub CLI commands.