ChangelogDocsPricingContact
Sign inInstall Self-Hosted
Get Started on Cloud
AboutX (Twitter)support@buddy.works
BasicsPipelinesActions & ServicesEnvironmentsIntegrationsTargetsTestsDomainsSandboxesSelf-HostedAgents & TunnelsYAMLBuddy GitFAQAPI
  • Basics
  • Workspace settings
Basics
Workflows
Node.js
Java
JavaScript
Python
PHP
Ruby
.NET Core
Android
React.js
React Native
iOS
Certificates & profiles
Pipeline configuration
Go
C/C++
Angular
Aurelia
Clojure
Django
Elixir
Ember.js
Gatsby
Haskell
Hexo
Hugo
Jekyll
Middleman
PowerShell
Scala
Deployments
About Deployments
AWS
App Runner
AWS CLI / CDK
CloudFormation
CodeDeploy
CodePipeline
EC2
ECS
Elastic Beanstalk
Lambda
S3 / CloudFront
Azure
Capistrano
DigitalOcean
DigitalOcean Spaces
FTP/FTPS
Git pull
Git push
Google Cloud
App Engine
Cloud Run
Cloud Storage
Firebase CLI
Function
Heroku
Netlify
Rackspace
Rsync
SFTP
Shopify
Vultr
Variables
Introduction to variables
Default variables
Variable phrases
User managment
User management
User Roles
Pipeline permissions
Integration permissions
Groups
Administrators
Activity streams
Billing
Billing & Usage
GB-minutes
Plans and Features
Workspace settings
General settings
Security
OIDC Identity Provider
Introduction
GitHub Actions
CircleCI
Other Provider
Trust Conditions
Single Sign-On (SSO)
SSO in Buddy
Mandatory SSO
Group synchronization
SAML
Generic
AWS
Azure
Google
Okta
OneLogin
OIDC
Generic
AWS Cognito
Azure
Google
Okta
OneLogin
Secrets and encryption
Private data in actions
Variable encryption
Secrets in YAML
Data in configuration files
  • Basics
  • Workspace settings

Identity Provider

Configure OIDC identity providers in Buddy for secure token-based authentication with GitHub Actions, CircleCI and other CI/CD tools. Eliminate hardcoded credentials with short-lived tokens.

  • Introduction

    Learn how Buddy OIDC identity providers enable secure token exchange for GitHub Actions, CircleCI and other CI/CD platforms. Configure short-lived API tokens without storing permanent credentials.

  • GitHub Actions

    Configure an OIDC identity provider for GitHub Actions workflows. Use buddy/login action to exchange tokens and access Buddy API without storing credentials.

  • CircleCI

    Configure an OIDC identity provider for CircleCI pipelines. Exchange CIRCLE_OIDC_TOKEN for Buddy API token without storing permanent credentials.

  • Other Provider

    Configure an OIDC identity provider for any OIDC-compatible service. Set custom issuer URL and trust conditions to securely access Buddy API.

  • Trust Conditions

    Configure trust conditions for an OIDC identity provider. Define repository, branch, and environment rules to control which tokens are accepted by Buddy.

Resources

  • Docs
  • API
  • Terraform
  • Guides
  • Download Self-Hosted
  • Security
  • Blog
  • Tutorials

Company

  • About
  • Customers
  • Support
  • X (Twitter)
  • Responsible Disclosure
  • GDPR
  • Terms of Service
  • Privacy Policy
SOC2
SOC2

© 2026

All systems are operational