# How to mask github action tokens safely

**URL:** <https://community.codefresh.io/t/how-to-mask-github-action-tokens-safely/747>\
**Category:** Pipeline Workflows\
**Created:** [March 6, 2022, 11:18pm UTC](https://community.codefresh.io/t/how-to-mask-github-action-tokens-safely/747 "2022-03-06T23:18:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pserwylo](https://avatars.discourse-cdn.com/v4/letter/p/ccd318/32.png) [@pserwylo](https://community.codefresh.io/u/pserwylo)\
**Post date:** [March 6, 2022, 11:18pm UTC](https://community.codefresh.io/t/how-to-mask-github-action-tokens-safely/747/1 "2022-03-06T23:18:41Z")

</div>

I am following the steps at [Git-Clone · Codefresh | Docs](https://codefresh.io/docs/docs/codefresh-yaml/steps/git-clone/) in order to obtain a GitHub access token from the codefresh git integration. When the freestyle stage runs a command such as:

```auto
 - git clone https://my-github-username:$GITHUB_TOKEN@github.com/my-github-username/my-repo.git

```

Then the codefresh build log will include the actual value of the `GITHUB_TOKEN`, rather than a masked version.

(in my case I’m actually updating the origin of the repository cloned by `main_clone` so that it includes the `GITHUB_TOKEN` and I am able to push back commits after bumping version numbers - but it is similar in sentiment)

The only solution I have is to inline the command which fetches the token as such:

```auto
 - git clone https://my-github-username:$(codefresh get context github --decrypt -o yaml | yq -r .spec.data.auth.password)@github.com/my-github-username/my-repo.git

```

but that is quite messy, and I’d rather extract the value to a variable.

Has anybody else done this in such a way that the github token is not leaked to the build?

---

<div class="post-metadata">

**Author:** ![Kostis](https://sea1.discourse-cdn.com/flex019/user_avatar/community.codefresh.io/kostis/32/391_2.png) [@Kostis](https://community.codefresh.io/u/Kostis)\
**Post date:** [March 8, 2022, 10:44am UTC](https://community.codefresh.io/t/how-to-mask-github-action-tokens-safely/747/2 "2022-03-08T10:44:47Z")

</div>

Hello

Could you please post the full YAML of your step? I cannot reproduce this.  
Here is what I get in similar build

 ![no-token](https://us1.discourse-cdn.com/flex019/uploads/codefreshtest/original/1X/2389ed230e2e3f2db91eceb919adb2506e9ec43b.png)

Here is my yaml

```auto
title: Uploading report
stage: report
image: alpine/git
working_directory: '${{my_clone}}'
commands:
  - git config --global user.email "kostis@codefresh.io"
  - git config --global user.name "Kostis Kapelonis"
  - cd /tmp
  - >-
    git clone --depth 1
    https://kostis-codefresh:$GITHUB_TOKEN@github.com/kostis-codefresh/codefresh-plugin-checker.git
    -b gh-pages

```

The full pipeline is here [codefresh-plugin-checker/codefresh.yml at master · kostis-codefresh/codefresh-plugin-checker · GitHub](https://github.com/kostis-codefresh/codefresh-plugin-checker/blob/master/codefresh.yml#L54)
