Command referencegh secret set
gh secret set command (Linux & Windows / GitHub CLI)
What it does
Create or update an Actions secret for a repository, environment, or organization. When people search for gh secret set, they usually want practical GitHub CLI flags, safe examples, and how this subcommand fits everyday PR and repo workflows on Linux, Windows, and macOS. Syntax, options, and copyable examples are below.
Create or update an Actions secret for a repository, environment, or organization.
Syntax
gh secret set <secret-name> [flags]
Common options
| Flag / option | Meaning |
|---|---|
| -a, --app | Application: actions, codespaces, or dependabot. |
| -b, --body | Secret value (prefer stdin in scripts). |
| -e, --env | Environment name for environment secrets. |
| -o, --org | Set an organization secret. |
| -r, --repos | Repo access list for org secrets. |
Practical examples
From stdin
printf '%s' "$API_KEY" | gh secret set API_KEY
Sets a repository Actions secret without putting it in argv.
Environment secret
gh secret set DEPLOY_KEY --env production < deploy_key.pem
Stores a secret on the production environment.
Literal body (local only)
gh secret set DEMO_FLAG --body "1"
Fine for non-sensitive flags; avoid for real credentials.
Common mistakes
- Passing secrets on the command line where shell history can capture them.
- Setting a repository secret when the workflow expects an environment secret.
Related commands
- gh secret deleteDelete an Actions secret from a repository, environment, or organization.
- gh workflow runTrigger a workflow_dispatch event for a GitHub Actions workflow.
- gh auth loginAuthenticate the GitHub CLI with GitHub.com or GitHub Enterprise so other gh commands can run.
- gh pr createCreate a pull request from the current branch with title, body, reviewers, and base branch options.
- gh pr mergeMerge a pull request using merge commit, squash, or rebase strategies.
- gitTrack source history and collaborate through distributed repositories.
- gh repo cloneClone a GitHub repository to your machine using your authenticated gh settings.
- gh pr checkoutCheck out a pull request locally as a branch so you can build, test, or review the changes.
FAQ
What does gh secret set do in GitHub CLI?
Create or update an Actions secret for a repository, environment, or organization.
Does gh secret set work on Windows and Linux?
Yes. The GitHub CLI (`gh`) runs on Linux, Windows, and macOS with the same subcommand syntax after you authenticate with `gh auth login`.
What is a practical gh secret set example?
Try `printf '%s' "$API_KEY" | gh secret set API_KEY` — Sets a repository Actions secret without putting it in argv.
Do I need a token in the command line for gh secret set?
Prefer `gh auth login` so credentials stay in the system keyring or secure storage. Avoid pasting personal access tokens into shell history.
Browse the full Linux and Windows command reference to search more bash, CMD, PowerShell, Conda, and GitHub CLI commands.