Repository navigation
Token seems to expire after 1h #121
Description
Activity
That seems to start happening after exactly 1h.
That is by design. Installation access tokens expire after 1h, there is no way to extend it, I'm afraid. We should probably document that in the README for folks who don't know. We could even log out a message for folks to see when they investigate problems. We could also export the expiration time as an additional output 🤔
Thanks for the insight! Now I know it's expected, I'll look for a workaround 🙂
For long-running processes, I usually write my actions to accept the app ID and private key. If you build your action in JS/TS, you can use the App constructor which provides lots of helpful APIs: https://github.com/octokit/octokit.js?tab=readme-ov-file#app-client. If you use the app.getInstallationOctokit(installationId) API, the returned octokit instance will auto-renew the installation access token.
If you want something lower-level, you can use @octokit/auth-app: https://github.com/octokit/auth-app.js?tab=readme-ov-file#authenticate-as-installation. When you use the authentication strategy with an Octokit constructor, it will auto-renew the installation access token as well.
That is by design. Installation access tokens expire after 1h, there is no way to extend it, I'm afraid. We should probably document that in the README for folks who don't know.
Please do! I wasn't aware of this limitation and started relying on the app in my workflows. I would have re-evaluated if this limitation was documented. I suggest also mentioning the auto-renewal options you listed.
Please do!
can you have a look and tell if it is clear?
#141
Perfect
Ran into this again, this time within the initial actions/checkout with lfs enabled, which unfortunately took more than hour to finish so it failed midway through 😔:
Fetching LFS objects
"C:\Program Files\Git\cmd\git.exe" lfs fetch origin refs/remotes/pull/...
fetch: Fetching reference refs/remotes/pull/...
batch response: Bad credentials
Error: error: failed to fetch some objects from 'https://github.com/...'
The process 'C:\Program Files\Git\cmd\git.exe' failed with exit code 2
I see a new PR for resolving this above, thank you! big +1 for getting it in
do not work
I'm running a workflow (
target-workflow.yml) in another repository (target-repo) of my organization using https://github.com/aurelien-baudet/workflow-dispatch (v2).To that end I'm generating an app token with
actions/create-github-app-token@v1.I can generate the token with no issues, and
aurelien-baudet/workflow-dispatch@v2manages to triggertarget-workflow.ymlall right as well.However, after some time, fetching the status of
target-workflowstarts to fail withWarning: Failed to get workflow status: Bad credentials. This causes my parent job to fail.That seems to start happening after exactly 1h.
Am I correct that the token expires after 1h? Is it documented somewhere?
Also, is there a way to extend the lifetime of this token? Otherwise, do you suggest a workaround?
My workflow:
The output of
aurelien-baudet/workflow-dispatch@v2step: