Skip to content

Add tip for retrieving short-lived HF token via CLI - #2683

Merged
Pierrci merged 1 commit into
mainfrom
update-trusted-publishers-docs
Aug 12, 2026
Merged

Add tip for retrieving short-lived HF token via CLI#2683
Pierrci merged 1 commit into
mainfrom
update-trusted-publishers-docs

Conversation

@coyotte508

@coyotte508 coyotte508 commented Aug 4, 2026

Copy link
Copy Markdown
Member

https://moon-ci-docs.huggingface.co/docs/hub/pr_2683/en/trusted-publishers#api-reference

image

Note

Low Risk
Documentation-only change with no runtime or security behavior impact.

Overview
Adds a TIP in the gated-repo CI section of trusted-publishers.md for workflows that need the exchanged token as a string (e.g. curl, git clone, or tools that read HF_TOKEN).

Documents that hf auth token runs the OIDC exchange and prints the short-lived token to stdout, with a GitHub Actions example that sets HF_OIDC_RESOURCE and writes HF_TOKEN to GITHUB_ENV. Notes that scoping applies to both user and repo publishers via HF_OIDC_RESOURCE.

Reviewed by Cursor Bugbot for commit aa30e2f. Bugbot is set up for automated code reviews on this repo. Configure here.

@HuggingFaceDocBuilderDev

Copy link
Copy Markdown

The docs for this PR live here. All of your documentation changes will be reflected on that endpoint. The docs are available until 30 days after the last update.

@Pierrci
Pierrci merged commit 3cd2b17 into main Aug 12, 2026
3 checks passed
@Pierrci
Pierrci deleted the update-trusted-publishers-docs branch August 12, 2026 01:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants