# Does actions/checkout Support Private Repositories? Authentication Methods Explained

> Discover how actions/checkout handles private repositories. Learn about authentication methods for your own repo or external private repositories to ensure secure access.

- Repository: [GitHub Actions/checkout](https://github.com/actions/checkout)
- Tags: how-to-guide
- Published: 2026-07-03

---

**Yes, `actions/checkout` supports private repositories, but authentication requirements vary depending on whether you're checking out the workflow's own repository or a different private repo.**

The official GitHub Actions repository `actions/checkout` provides robust support for cloning private repositories through multiple authentication mechanisms. Depending on your use case—whether accessing the repository that triggered the workflow or an external private repository—you can leverage the built-in `GITHUB_TOKEN`, a Personal Access Token (PAT), or SSH keys. Understanding these authentication flows requires examining how the action processes inputs in [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts) and manages credentials in [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts).

## Authentication Methods for Private Repositories

### Default GITHUB_TOKEN for Same-Repository Access

When checking out the private repository that triggered the workflow, `actions/checkout` works out-of-the-box without additional configuration. The action automatically uses the default `${{ github.token }}` (the `GITHUB_TOKEN` provided to the workflow), which is scoped to the repository that owns the workflow.

In [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts) (lines 39-41), the `token` input defaults to the workflow's `GITHUB_TOKEN`, allowing immediate read access to the current repository without extra secrets.

### Personal Access Tokens for External Private Repositories

To checkout a *different* private repository, you must supply a **Personal Access Token (PAT)** with appropriate `repo` scopes. The token is passed via the `token` input and injected as an HTTP header for Git operations. According to the README documentation, this PAT requires access to the target repository to authenticate successfully against GitHub's API and Git endpoints.

### SSH Key Authentication

For organizations preferring SSH-based access, `actions/checkout` supports providing an SSH private key via the `ssh-key` input. You can optionally specify known hosts using `ssh-known-hosts` to prevent man-in-the-middle attacks.

The [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts) file (lines 42-48) handles the parsing of `sshKey` and `sshKnownHosts` inputs, configuring Git to use SSH credentials instead of HTTPS tokens.

## Implementation Details in the Source Code

The authentication flow relies on two critical components in the `actions/checkout` source code.

**Input Processing ([`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts)):** The `getInputs()` function parses workflow inputs including `token`, `ssh-key`, and `repository`, constructing an `IGitSourceSettings` object that drives the entire checkout flow. This module determines whether to use default credentials or custom authentication based on the provided inputs.

**Credential Management ([`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts)):** This helper creates temporary authentication configurations—either a `.extraheader` entry formatted as `x-access-token:<token>` for HTTPS authentication or an SSH-based credential file. Crucially, the action removes these credentials in a post-step to prevent secret leakage in subsequent workflow steps or job artifacts.

## Configuration Examples

*Basic checkout of the same private repository (no extra token needed):*

```yaml
- uses: actions/checkout@v7
  # No extra inputs – the default GITHUB_TOKEN suffices

```

*Checkout a different private repo using a PAT:*

```yaml
- uses: actions/checkout@v7
  with:
    repository: my-org/my-private-tools   # owner/repo of the private repo

    token: ${{ secrets.MY_PAT }}          # PAT with appropriate repo scopes

    path: tools                           # optional, where to place the repo

```

*Checkout a private repo via SSH:*

```yaml
- uses: actions/checkout@v7
  with:
    repository: my-org/my-ssh-repo
    ssh-key: ${{ secrets.SSH_PRIVATE_KEY }}   # SSH private key

    ssh-known-hosts: |
      github.com ssh-rsa AAAAB3Nza...
    ssh-strict: true                         # optional, enforce host-key checking

```

*Checkout multiple private repos side-by-side:*

```yaml
- name: Primary repo (public or private)
  uses: actions/checkout@v7
  with:
    path: main

- name: Secondary private repo
  uses: actions/checkout@v7
  with:
    repository: my-org/second-private
    token: ${{ secrets.SECOND_PAT }}
    path: second

```

## Summary

- **`actions/checkout` fully supports private repositories** through multiple authentication mechanisms.
- **Same-repository access** uses the built-in `GITHUB_TOKEN` by default, requiring no additional configuration in [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts).
- **External private repositories** require a PAT with `repo` scopes passed via the `token` input.
- **SSH authentication** provides an alternative to HTTPS tokens using `ssh-key` and `ssh-known-hosts` inputs.
- **Secure credential handling** occurs in [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts), which automatically removes temporary authentication configurations after checkout.

## Frequently Asked Questions

### Does actions/checkout require a PAT for private repositories?

No, if you are checking out the same private repository that triggered the workflow. The action automatically uses the default `GITHUB_TOKEN` provided by GitHub Actions. However, when accessing a different private repository, you must provide a Personal Access Token via the `token` input.

### How do I checkout multiple private repos in one workflow?

Use multiple `actions/checkout` steps, specifying the `repository` and `token` (or `ssh-key`) inputs for each external private repository. The default step without these inputs checks out the workflow's own repository using the automatic `GITHUB_TOKEN`.

### Is SSH or token-based authentication more secure?

Both methods are secure when implemented correctly. Token-based authentication using `GITHUB_TOKEN` or PATs operates over HTTPS and automatically handles credential cleanup. SSH authentication requires managing private keys and known hosts but eliminates the need to store PATs in secrets. The action securely removes both authentication types after checkout via [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts).

### Where are credentials stored during the checkout process?

Temporary credentials are stored in Git configuration files (`.extraheader` for HTTPS or SSH config files) only for the duration of the job. The [`git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/git-auth-helper.ts) module removes these configurations in a post-action step to prevent credential leakage to subsequent steps or job artifacts.