Does actions/checkout Support Private Repositories? Authentication Methods Explained
Yes, actions/checkout supports private repositories, but authentication requirements vary depending on whether you're checking out the workflow's own repository or a different private repo.
The official GitHub Actions repository actions/checkout provides robust support for cloning private repositories through multiple authentication mechanisms. Depending on your use case—whether accessing the repository that triggered the workflow or an external private repository—you can leverage the built-in GITHUB_TOKEN, a Personal Access Token (PAT), or SSH keys. Understanding these authentication flows requires examining how the action processes inputs in src/input-helper.ts and manages credentials in src/git-auth-helper.ts.
Authentication Methods for Private Repositories
Default GITHUB_TOKEN for Same-Repository Access
When checking out the private repository that triggered the workflow, actions/checkout works out-of-the-box without additional configuration. The action automatically uses the default ${{ github.token }} (the GITHUB_TOKEN provided to the workflow), which is scoped to the repository that owns the workflow.
In src/input-helper.ts (lines 39-41), the token input defaults to the workflow's GITHUB_TOKEN, allowing immediate read access to the current repository without extra secrets.
Personal Access Tokens for External Private Repositories
To checkout a different private repository, you must supply a Personal Access Token (PAT) with appropriate repo scopes. The token is passed via the token input and injected as an HTTP header for Git operations. According to the README documentation, this PAT requires access to the target repository to authenticate successfully against GitHub's API and Git endpoints.
SSH Key Authentication
For organizations preferring SSH-based access, actions/checkout supports providing an SSH private key via the ssh-key input. You can optionally specify known hosts using ssh-known-hosts to prevent man-in-the-middle attacks.
The src/input-helper.ts file (lines 42-48) handles the parsing of sshKey and sshKnownHosts inputs, configuring Git to use SSH credentials instead of HTTPS tokens.
Implementation Details in the Source Code
The authentication flow relies on two critical components in the actions/checkout source code.
Input Processing (src/input-helper.ts): The getInputs() function parses workflow inputs including token, ssh-key, and repository, constructing an IGitSourceSettings object that drives the entire checkout flow. This module determines whether to use default credentials or custom authentication based on the provided inputs.
Credential Management (src/git-auth-helper.ts): This helper creates temporary authentication configurations—either a .extraheader entry formatted as x-access-token:<token> for HTTPS authentication or an SSH-based credential file. Crucially, the action removes these credentials in a post-step to prevent secret leakage in subsequent workflow steps or job artifacts.
Configuration Examples
Basic checkout of the same private repository (no extra token needed):
- uses: actions/checkout@v7
# No extra inputs – the default GITHUB_TOKEN suffices
Checkout a different private repo using a PAT:
- uses: actions/checkout@v7
with:
repository: my-org/my-private-tools # owner/repo of the private repo
token: ${{ secrets.MY_PAT }} # PAT with appropriate repo scopes
path: tools # optional, where to place the repo
Checkout a private repo via SSH:
- uses: actions/checkout@v7
with:
repository: my-org/my-ssh-repo
ssh-key: ${{ secrets.SSH_PRIVATE_KEY }} # SSH private key
ssh-known-hosts: |
github.com ssh-rsa AAAAB3Nza...
ssh-strict: true # optional, enforce host-key checking
Checkout multiple private repos side-by-side:
- name: Primary repo (public or private)
uses: actions/checkout@v7
with:
path: main
- name: Secondary private repo
uses: actions/checkout@v7
with:
repository: my-org/second-private
token: ${{ secrets.SECOND_PAT }}
path: second
Summary
actions/checkoutfully supports private repositories through multiple authentication mechanisms.- Same-repository access uses the built-in
GITHUB_TOKENby default, requiring no additional configuration insrc/input-helper.ts. - External private repositories require a PAT with
reposcopes passed via thetokeninput. - SSH authentication provides an alternative to HTTPS tokens using
ssh-keyandssh-known-hostsinputs. - Secure credential handling occurs in
src/git-auth-helper.ts, which automatically removes temporary authentication configurations after checkout.
Frequently Asked Questions
Does actions/checkout require a PAT for private repositories?
No, if you are checking out the same private repository that triggered the workflow. The action automatically uses the default GITHUB_TOKEN provided by GitHub Actions. However, when accessing a different private repository, you must provide a Personal Access Token via the token input.
How do I checkout multiple private repos in one workflow?
Use multiple actions/checkout steps, specifying the repository and token (or ssh-key) inputs for each external private repository. The default step without these inputs checks out the workflow's own repository using the automatic GITHUB_TOKEN.
Is SSH or token-based authentication more secure?
Both methods are secure when implemented correctly. Token-based authentication using GITHUB_TOKEN or PATs operates over HTTPS and automatically handles credential cleanup. SSH authentication requires managing private keys and known hosts but eliminates the need to store PATs in secrets. The action securely removes both authentication types after checkout via src/git-auth-helper.ts.
Where are credentials stored during the checkout process?
Temporary credentials are stored in Git configuration files (.extraheader for HTTPS or SSH config files) only for the duration of the job. The git-auth-helper.ts module removes these configurations in a post-action step to prevent credential leakage to subsequent steps or job artifacts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →