How can I test an external API integration in a GitHub Codespace using a non‑production secret without exposing production credentials?
0 reputation · 15 Mar 2026, 13:14 UTC
0 reputation · 15 Mar 2026, 13:14 UTC
I want to run integration tests that call an external API inside a GitHub Codespace, but I must avoid using production credentials in the temporary development environment to reduce risk of accidental exposure. The account‑specific secrets feature lets me store a test token as an environment variable, yet I am unsure how to guarantee that the secret is only available to the test runner and not to other processes or during container build.
Additionally, I need to know whether I can restrict the secret’s repository access to a specific branch or a temporary fork, and if there is a way to automatically invalidate or rotate the secret after the test suite finishes without manual steps.
How do I configure the secret so it is available only to the test stage and not to other processes? Can I limit the secret's repository access to a specific branch or temporary repo for testing? Is there a way to automatically remove or rotate the secret after the test run without manual intervention?
26525 reputation · 15 Mar 2026, 16:00 UTC
# Pass the secret only to the specific test command
EXTERNAL_API_TOKEN=$EXTERNAL_API_TOKEN npm test
echo \$EXTERNAL_API_TOKEN | cut -c1-4
This confirms the variable exists by showing only the first four characters, preventing accidental log exposure.
Note: This approach assumes your testing framework supports environment variable injection. If your tool requires a file-based config, you must write the secret to a temporary file during the test setup and cleanup.
Use comments to ask for clarification. Post a solution as an answer.
26,525 reputation · 15 Mar 2026, 17:32 UTC
When you create a secret with the gh secret set --codespace <name> command, the value is bound to that specific Codespace instance and is not available to other Codespaces, repository workflows, or the container image. Because the secret lives only for the lifetime of the Codespace, you can automate its removal by adding a post‑test step that runs gh codespace delete <codespace-name> or, if you prefer to keep the environment, explicitly unsets the variable with unset EXTERNAL_API_TOKEN after your test script finishes. This ensures the test token is present only during the test command and is cleared before any subsequent processes run in the same terminal.