Claude Code GitHub Actions
Claude Code GitHub Actions brings AI-driven automation to your GitHub workflows.
By simply mentioning it in a PR or Issue@claude, Claude can analyze code, create Pull Requests, implement features, and fix bugs while following your project's standard guidelines.
Why use Claude Code GitHub Actions
- Instant PR creation: Describe your needs, and Claude can create a complete Pull Request
- Automated code implementation: Turn Issues into working code with just one command
- Follows project standards: Respects your
CLAUDE.mdguidelines and existing code patterns - Simple and fast: Get started in minutes
- Secure and reliable: Code stays running on GitHub's runners
Quick Start
Method 1: Automatic Installation (Recommended)
Run in the Claude Code terminal:
/install-github-app
This will guide you through:
- Setting up a GitHub App
- Adding required Secrets
Requirements: You must be a repository administrator. The GitHub App needs read/write permissions for Contents, Issues, and Pull requests. Only applicable to users directly using the Claude API (AWS Bedrock and Google Vertex AI are not supported).
Method 2: Manual Installation
Step 1: Install the Claude GitHub App
Visit:https://github.com/apps/claude
Required permissions:
- Contents: Read/write permissions
- Issues: Read/write permissions
- Pull requests: Read/write permissions
Step 2: Add API key
Add to repository SecretsANTHROPIC_API_KEY
Step 3: Create workflow file
Copy from example file:examples/claude.ymlto.github/workflows/
Workflow Configuration
Basic Workflow (Respond to @claude mentions)
name: Claude Code
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
jobs:
claude:
runs-on: ubuntu-latest
steps:
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
Automatic Code Review
name: Code Review
on:
pull_request:
types: [opened, synchronize]
jobs:
review:
runs-on: ubuntu-latest
steps:
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: "Review this pull request for code quality, correctness, and security."
claude_args: "--max-turns 5"
Scheduled Tasks
name: Daily Report
on:
schedule:
- cron: "0 9 * * *"
jobs:
report:
runs-on: ubuntu-latest
steps:
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: "Generate a summary of yesterday's commits and open issues"
claude_args: "--model opus"
Common @claude Commands
Use in PR or Issue comments:
@claude implement this feature based on the issue description
@claude how should I implement user authentication for this endpoint?
@claude fix the TypeError in the user dashboard component
@claude review this PR for security issues
@claude add tests for this new function
Action Parameters Explained
| Parameter | Description | Required |
|---|---|---|
prompt |
Instructions for Claude (plain text or skill name) | No* |
claude_args |
CLI arguments passed to Claude Code | no |
anthropic_api_key |
Claude API Key | Yes** |
github_token |
GitHub Token (for API access) | no |
trigger_phrase |
Custom trigger word (default:@claude) |
no |
use_bedrock |
Use AWS Bedrock instead of Claude API | no |
use_vertex |
Use Google Vertex AI instead of Claude API | no |
*Omit prompt when used in issue/PR comments; Claude responds to the trigger word
**Required when using Claude API directly, not needed for Bedrock/Vertex
Common CLI Parameters
| Parameter | Description |
|---|---|
--max-turns |
Maximum conversation turns (default 10) |
--model |
Model to use (e.g.claude-sonnet-4-6) |
--mcp-config |
MCP configuration file path |
--allowedTools |
Allowed tools (comma-separated) |
--append-system-prompt |
Append system prompt |
--debug |
Enable debug output |
claude_args Examples
claude_args: | --max-turns 5 --model claude-sonnet-4-6 --mcp-config /path/to/config.json --append-system-prompt "Follow our coding standards"
AWS Bedrock Integration
Prerequisites
- AWS Bedrock access enabled with Claude model permissions
- GitHub configured as OIDC identity provider in AWS
- IAM role with Bedrock permissions
Required Secrets
| Secret Name | Description |
|---|---|
AWS_ROLE_TO_ASSUME |
IAM role ARN for Bedrock access |
APP_ID |
GitHub App ID |
APP_PRIVATE_KEY |
GitHub App private key |
Bedrock Workflow Example
name: Claude PR Action
permissions:
contents: write
pull-requests: write
issues: write
id-token: write
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
jobs:
claude-pr:
if: |
(github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude'))
runs-on: ubuntu-latest
env:
AWS_REGION: us-west-2
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Generate GitHub App token
id: app-token
uses: actions/create-github-app-token@v2
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Configure AWS Credentials (OIDC)
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: ${{ secrets.AWS_ROLE_TO_ASSUME }}
aws-region: us-west-2
- uses: anthropics/claude-code-action@v1
with:
github_token: ${{ steps.app-token.outputs.token }}
use_bedrock: "true"
claude_args: '--model us.anthropic.claude-sonnet-4-6 --max-turns 10'
Google Vertex AI Integration
Prerequisites
- Vertex AI API enabled in GCP project
- Workload Identity Federation configured for GitHub
- Service account with Vertex AI permissions
Required Secrets
| Secret Name | Description |
|---|---|
GCP_WORKLOAD_IDENTITY_PROVIDER |
Workload Identity Provider resource name |
GCP_SERVICE_ACCOUNT |
Service account email with Vertex AI access |
APP_ID |
GitHub App ID |
APP_PRIVATE_KEY |
GitHub App private key |
Vertex AI Workflow Example
name: Claude PR Action
permissions:
contents: write
pull-requests: write
issues: write
id-token: write
on:
issue_comment:
types: [created]
jobs:
claude-pr:
if: github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')
runs-on: ubuntu-latest
steps:
- name: Checkout repository
uses: actions/checkout@v4
- name: Generate GitHub App token
id: app-token
uses: actions/create-github-app-token@v2
with:
app-id: ${{ secrets.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
- name: Authenticate to Google Cloud
id: auth
uses: google-github-actions/auth@v2
with:
workload_identity_provider: ${{ secrets.GCP_WORKLOAD_IDENTITY_PROVIDER }}
service_account: ${{ secrets.GCP_SERVICE_ACCOUNT }}
- uses: anthropics/claude-code-action@v1
with:
github_token: ${{ steps.app-token.outputs.token }}
trigger_phrase: "@claude"
use_vertex: "true"
claude_args: '--model claude-sonnet-4-5@20250929 --max-turns 10'
env:
ANTHROPIC_VERTEX_PROJECT_ID: ${{ steps.auth.outputs.project_id }}
CLOUD_ML_REGION: us-east5
Upgrading from Beta (v1.0 Breaking Changes)
| Beta Input | New v1.0 Input |
|---|---|
mode |
(Removed - auto-detected) |
direct_prompt |
prompt |
override_prompt |
with GitHub variablesprompt |
custom_instructions |
claude_args: --append-system-prompt |
max_turns |
claude_args: --max-turns |
model |
claude_args: --model |
allowed_tools |
claude_args: --allowedTools |
disallowed_tools |
claude_args: --disallowedTools |
Before and After Upgrade Comparison
Beta version:
- uses: anthropics/claude-code-action@beta
with:
mode: "tag"
direct_prompt: "Review this PR for security issues"
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
custom_instructions: "Follow our coding standards"
max_turns: "10"
model: "claude-sonnet-4-6"
GA version (v1.0):
- uses: anthropics/claude-code-action@v1
with:
prompt: "Review this PR for security issues"
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
claude_args: |
--append-system-prompt "Follow our coding standards"
--max-turns 10
--model claude-sonnet-4-6
Troubleshooting
Claude does not respond to @claude commands
- Confirm GitHub App is installed correctly
- Check that the workflow is enabled
- Ensure API key is set in repository Secrets
- Confirm the comment contains
@claude(not/claude)
CI does not run on Claude's commits
- Use GitHub App or custom app (don't use the Actions user)
- Check workflow triggers include necessary events
- Confirm app permissions include CI triggers
Authentication Errors
- Confirm API key is valid and has sufficient permissions
- For Bedrock/Vertex: check credential configuration
- Ensure Secret names are correct in the workflow
Security Considerations
- Never commit API keys directlyto the repository
- Use GitHub Secrets to store API keys:
${{ secrets.ANTHROPIC_API_KEY }} - Limit action permissions; grant only necessary permissions
- Review Claude's suggestions before merging
- For AWS/GCP: use OIDC identity providers instead of static credentials
- Create dedicated service accounts for each repository
Cost Considerations
Cost Breakdown
- GitHub Actions costs: Running on GitHub-hosted runners consumes GitHub Actions minutes
- API costs: Each Claude interaction consumes API tokens based on prompt/response length
Cost Optimization Suggestions
- Use specific
@claudecommands, reduce unnecessary API calls - Configure appropriate
--max-turnsLimit conversation rounds - Set workflow timeouts to prevent tasks from running out of control
- Use GitHub concurrency controls to limit parallel runs
Best Practices
1. Create CLAUDE.md
Create in repository rootCLAUDE.mdfile, define code style guide and project-specific rules:
# 项目开发规范 ## 代码风格 - 使用 TypeScript 4.x - 遵循 ESLint 配置 - 函数必须有 JSDoc 注释 ## PR 要求 - 必须通过所有 CI 检查 - 至少一个代码审查 - 更新相关文档 ## 禁止事项 - 不要修改 `migrations/` 目录 - 不要提交 `.env` 文件
2. Use specific @claude commands
@claude review this PR for SQL injection vulnerabilities
@claude add unit tests for the new validateEmail function
3. Configure appropriate limits
jobs:
claude:
runs-on: ubuntu-latest
timeout-minutes: 15 # 设置超时
steps:
- uses: anthropics/claude-code-action@v1
with:
claude_args: "--max-turns 5 --allowedTools Read,Grep,Glob,Bash,Write,Edit"
4. CI/CD Automation Scenarios
- PR automatic review: Automatically trigger review when PR is opened or updated
- Issue auto-classification: Automatically add labels and assignees when new Issue is created
- Scheduled reports: Generate daily code statistics or security reports
- Automated fixes: Automatically analyze and attempt fixes when CI fails