GitHub Actions OIDC token remains valid after job sleep period – unexpected authentication behavior
29.5K reputation · 11 Jul 2025, 06:16 UTC
Goal
To determine whether the OIDC identity token that GitHub Actions supplies is automatically refreshed when a single job contains a long‑running step that exceeds the token’s nominal lifetime.
Scenario
A workflow obtains an OIDC token, exchanges it for AWS STS credentials, sleeps for 12 minutes, and then makes a second AWS API call.
Constraints
The token is normally valid for 5–10 minutes, and least‑privilege security depends on it not staying usable beyond that window. The workflow may not explicitly request a new token after the sleep.
Unresolved Questions
- Does the Actions runtime silently fetch a new OIDC token for a job that has outlived the first token’s validity?
- If the token is not refreshed, do SDKs automatically detect the expiration and retry with a new token?
- What is the documented behavior for re‑using the same token across multiple steps within a single job?