# How to Configure actions/checkout for GitHub Enterprise Server

> Configure actions/checkout for GitHub Enterprise Server by setting the github-server-url input and providing a valid PAT or SSH key for your GHES instance.

- Repository: [GitHub Actions/checkout](https://github.com/actions/checkout)
- Tags: how-to-guide
- Published: 2026-07-05

---

**To configure actions/checkout for GitHub Enterprise Server, set the `github-server-url` input to your GHES instance URL (e.g., `https://ghes.mycompany.com`) and provide a Personal Access Token or SSH key that is valid for your enterprise environment.**

The `actions/checkout` repository provides the official GitHub Action for cloning repositories during workflow runs. While it defaults to GitHub.com, the action fully supports self-hosted GitHub Enterprise Server (GHES) instances through a specific input parameter. This guide explains how to override the default host URL and authenticate against your enterprise environment using the actual source code implementation.

## Understanding the github-server-url Input

### Input Declaration in action.yml

The `github-server-url` input is declared in [`action.yml`](https://github.com/actions/checkout/blob/main/action.yml) at lines 98-101, where it defaults to the URL of the runner's host environment. According to the source code, this input accepts any valid GHES URL such as `https://ghes.mycompany.com`, allowing the action to target your private instance instead of the public GitHub.com endpoint.

### Implementation in input-helper.ts

In [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts) at line 162, the workflow reads the `github-server-url` value and stores it within the `Input` configuration object that drives the checkout process. This value ensures that all Git operations—including `git clone` and `git fetch`—use your enterprise base URL rather than the default `https://github.com`.

## Configuring Authentication for GHES

When targeting GHES, you must provide credentials that are valid for your enterprise instance, as the default `github.token` only works for GitHub.com.

### Personal Access Token (PAT)

Use a PAT generated from your GHES instance with appropriate repository permissions. Pass this token to the `token` input in your workflow configuration. The [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts) file handles the authentication header setup for these credentials.

### SSH Key Authentication

Alternatively, configure SSH authentication by providing a private key via the `ssh-key` input and specifying known hosts using `ssh-known-hosts`. The [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts) file configures the Git client to use these SSH credentials when connecting to your GHES instance.

## Practical Configuration Examples

### Basic Checkout from GHES

```yaml
jobs:
  build:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout from GHES
        uses: actions/checkout@v7
        with:
          github-server-url: https://ghes.mycompany.com
          repository: my-org/my-repo
          token: ${{ secrets.GHES_PAT }}

```

### Shallow Fetch with Specific Branch

```yaml
- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    ref: feature/awesome-feature
    fetch-depth: 1
    token: ${{ secrets.GHES_PAT }}

```

### SSH Authentication

```yaml
- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    ssh-key: ${{ secrets.GHES_SSH_KEY }}
    ssh-known-hosts: |
      mycompany.com ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQD...
    ssh-strict: true

```

### Sparse Checkout on GHES

```yaml
- uses: actions/checkout@v7
  with:
    github-server-url: https://ghes.mycompany.com
    repository: my-org/my-repo
    sparse-checkout: |
      src/
      docs/
    sparse-checkout-cone-mode: false

```

## Key Source Files and Implementation Details

The checkout flow for GHES relies on several core files in the `actions/checkout` repository:

- **[`action.yml`](https://github.com/actions/checkout/blob/main/action.yml)**: Declares all inputs including `github-server-url` at lines 98-101
- **[`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts)**: Reads workflow inputs at line 162 and builds the configuration object
- **[`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts)**: Constructs clone URLs based on the `github-server-url` value
- **[`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts)**: Handles token and SSH authentication setup for the Git client
- **[`src/main.ts`](https://github.com/actions/checkout/blob/main/src/main.ts)**: Orchestrates the overall checkout execution

## Summary

- Set `github-server-url` to your GHES instance URL (e.g., `https://ghes.mycompany.com`) to redirect all Git operations from GitHub.com to your enterprise server
- Provide a GHES-compatible Personal Access Token or SSH key since the default `github.token` only authenticates against GitHub.com
- All other inputs (`fetch-depth`, `sparse-checkout`, `submodules`, `ref`) behave identically to GitHub.com configurations once the server URL is set
- The action reads the server URL in [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts) and applies it to URL construction in [`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts)

## Frequently Asked Questions

### Can I use the default GITHUB_TOKEN for GHES authentication?

No. The default `github.token` provided by GitHub Actions only authenticates against GitHub.com. For GitHub Enterprise Server, you must create a Personal Access Token (PAT) on your GHES instance with appropriate repository scopes and pass it via the `token` input, as implemented in [`src/git-auth-helper.ts`](https://github.com/actions/checkout/blob/main/src/git-auth-helper.ts).

### Does the github-server-url input support HTTP or only HTTPS?

While the examples typically show HTTPS URLs like `https://ghes.mycompany.com`, the implementation in [`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts) constructs URLs based on the provided string. You should use HTTPS for secure connections, though the underlying Git commands would technically accept HTTP if your enterprise instance configuration supports it.

### How do I configure actions/checkout for GHES when using self-hosted runners?

Self-hosted runners automatically detect the GitHub Enterprise Server URL from the `GITHUB_SERVER_URL` environment variable. However, you can still explicitly set `github-server-url` in your workflow to override this behavior or ensure consistency across different runner environments, as processed by [`src/input-helper.ts`](https://github.com/actions/checkout/blob/main/src/input-helper.ts).

### Will sparse checkout and shallow fetch work the same way on GHES?

Yes. Once you configure `github-server-url`, all standard features like `sparse-checkout`, `fetch-depth`, and submodules function identically to GitHub.com because the action simply redirects the Git operations to your enterprise URL while maintaining the same feature logic in [`src/git-source-provider.ts`](https://github.com/actions/checkout/blob/main/src/git-source-provider.ts).