Managing Workflow Secrets

Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions composite actions (azure-login →…

About this skill

Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions composite actions (azure-login → get-keyvault-secrets → azure-logout), consume it safely, and get it beyond the job or into a reusable workflow when needed.

Maintained by Bitwarden. The source includes the instructions and any supporting files needed to use this skill.

Inside the instructions

  • 01Boundaries
  • 02Secret exposure is the overriding concern
  • 03The AKV + OIDC lifecycle
  • 04Golden rules (invariants)
  • 05Getting a secret to a downstream job or reusable workflow
  • 06Authoring procedure

Before you start

  1. Read the instructions and check tool or account requirements.
  2. Install the complete folder when the skill references scripts or other files.
  3. Provide your task context, then review the agent's output.

Source

bitwarden/ai-plugins / managing-workflow-secrets

Source reviewed October 2, 2026 · See publisher source