You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用GitHub REST API创建Actions密钥时值为空的解决咨询

如何通过GitHub REST API正确存储GitHub Actions密钥?

问题描述

通过GitHub REST API创建Actions密钥时,密钥能成功创建但值为空;但通过GitHub Actions网页UI手动创建时,值可正常存储并在脚本中使用。

用户使用的API调用:

curl -L \
  -X PUT \
  -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer <YOUR-TOKEN>" \
  -H "X-GitHub-Api-Version: 2022-11-28" \
  https://api.github.com/repos/OWNER/REPO/actions/secrets/SECRET_NAME \
  -d '{"encrypted_value":"c2VjcmV0","key_id":"012345678912345678"}'

加密encrypted_value的代码:

const sodium = require('libsodium-wrappers')
const secret = 'plain-text-secret' // replace with the secret you want to encrypt
const key = 'base64-encoded-public-key' // replace with the Base64 encoded public key

//Check if libsodium is ready and then proceed.
sodium.ready.then(() => {
  // Convert Secret & Base64 key to Uint8Array.
  let binkey = sodium.from_base64(key, sodium.base64_variants.ORIGINAL)
  let binsec = sodium.from_string(secret)

  //Encrypt the secret using LibSodium
  let encBytes = sodium.crypto_box_seal(binsec, binkey)

  // Convert encrypted Uint8Array to Base64
  let output = sodium.to_base64(encBytes, sodium.base64_variants.ORIGINAL)

  console.log(output)
});

解决步骤

1. 获取目标仓库的Actions公钥

必须使用对应仓库的专属Actions公钥,不能用其他公钥。通过以下API获取:

curl -L \
  -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer <YOUR-TOKEN>" \
  -H "X-GitHub-Api-Version: 2022-11-28" \
  https://api.github.com/repos/OWNER/REPO/actions/secrets/public-key

返回结果包含key(base64编码的公钥)和key_id,这两个值必须配对使用。

2. 正确加密密钥值

确保加密过程严格符合GitHub的要求,修正后的加密代码:

const sodium = require('libsodium-wrappers');

async function encryptGitHubSecret() {
  await sodium.ready;
  
  // 替换为从API获取的公钥
  const repoPublicKey = '从API获取的base64公钥';
  // 替换为你要存储的明文密钥
  const secretPlaintext = 'your-secret-value';

  // 转换公钥为Uint8Array
  const keyBytes = sodium.from_base64(repoPublicKey, sodium.base64_variants.ORIGINAL);
  // 转换明文密钥为Uint8Array
  const secretBytes = sodium.from_string(secretPlaintext);

  // 使用crypto_box_seal进行密封加密(GitHub要求的加密方式)
  const encryptedBytes = sodium.crypto_box_seal(secretBytes, keyBytes);

  // 转换为标准base64字符串
  const encryptedValue = sodium.to_base64(encryptedBytes, sodium.base64_variants.ORIGINAL);
  
  console.log('加密后的值:', encryptedValue);
  console.log('对应的key_id: 从公钥API获取的key_id');
}

encryptGitHubSecret();

3. 发送正确的API请求

确保encrypted_value和key_id是配对的最新值,且JSON格式无错误:

curl -L \
  -X PUT \
  -H "Accept: application/vnd.github+json" \
  -H "Authorization: Bearer <YOUR-TOKEN>" \
  -H "X-GitHub-Api-Version: 2022-11-28" \
  https://api.github.com/repos/OWNER/REPO/actions/secrets/SECRET_NAME \
  -d '{
    "encrypted_value": "上面生成的加密base64字符串",
    "key_id": "从公钥API获取的key_id"
  }'

常见错误排查

  • 公钥不匹配:使用了错误的公钥(如用户SSH公钥、其他仓库的公钥),必须用当前仓库的Actions公钥。
  • base64变体错误:GitHub要求使用标准base64(ORIGINAL),不要使用URL安全的变体。
  • JSON格式错误:请求体的JSON存在语法错误(如遗漏逗号、引号不匹配),导致GitHub无法解析encrypted_value。
  • 令牌权限不足:个人访问令牌(PAT)需要具备repo(私有仓库)或public_repo(公共仓库)权限,且启用了Actions相关权限。

内容的提问来源于stack exchange,提问作者sagar chavan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 18:33:29