Skip to main content
The GitHub Actions path in capy deploy can use your authenticated gh CLI to store the generated SECRETS_BLOB and PROJECT_KEY as repository or environment secrets. You can also choose token instructions and add the two generated values yourself.

Set up the pair

From the repository, run capy deploy, choose GitHub Actions, and follow the setup flow. If you use the GitHub CLI path, make sure it is authenticated first:
For manual setup, choose the token path and add the generated values under Settings → Secrets and variables → Actions. Use the exact names below, or change the workflow references to match your chosen secret names:
Paste each value into the GitHub CLI prompt; do not include it in shell arguments or commit it in the workflow.

Minimal workflow

Every capy run invocation decrypts only for its child process. Wrap every build, test, or deployment step that needs the values.
If you stored the pair in a GitHub Actions environment, assign that environment to the job:
Use a separate pair for each GitHub environment when staging and production use different Capy branches.

Forked pull requests and revocation

GitHub does not pass secrets to pull requests from forks by default. Keep those workflows free of Capy deployment credentials, or gate a trusted deployment job before it reads the pair. Revoke a pair with capy deploy revoke <deploy-id>. Revocation blocks new jobs from decrypting, but it does not delete the GitHub secrets; remove or replace them when you rotate the pair.
Last modified on October 2, 2026