Claude Code GitHub Actions: Set Up @claude on Issues and Pull Requests
How to set up the Claude Code GitHub Action so you can mention @claude on issues and PRs: quick setup with /install-github-app, manual setup, API key vs subscription token, interactive vs automation mode, scheduled runs, cost controls, and security.
The Claude Code GitHub Action runs Claude Code inside your repository's GitHub Actions workflows. Once it's set up, anyone with write access can comment @claude fix the TypeError in the dashboard on an issue or pull request, and Claude works on it in a GitHub runner, pushes commits, and replies in the thread. You can also run it automatically — on every PR, or on a schedule.
Details match Anthropic's documentation and the anthropics/claude-code-action@v1 action as of October 2026.
Quick setup
From a local checkout of the repository, with the GitHub CLI installed and authenticated (gh auth login) and admin access to the repo:
claude
/install-github-app
Claude Code then:
- installs the Claude GitHub App on the repository,
- stores an authentication secret —
ANTHROPIC_API_KEYfor an API key, orCLAUDE_CODE_OAUTH_TOKENfor a Claude subscription token, - pushes a branch with the workflow files you chose and opens a pull request.
Merge that PR, and @claude works. Quick setup only supports github.com repositories.
Manual setup
If you'd rather control each step:
- Install the Claude GitHub App on the repository.
- Add a repository secret: either
ANTHROPIC_API_KEY(from the Claude Console), orCLAUDE_CODE_OAUTH_TOKEN, generated locally withclaude setup-token(Pro, Max, Team and Enterprise plans). - Add a workflow file,
.github/workflows/claude.yml:
name: Claude Code
on:
issue_comment:
types: [created]
pull_request_review_comment:
types: [created]
jobs:
claude:
if: contains(github.event.comment.body, '@claude')
runs-on: ubuntu-latest
permissions:
contents: write
pull-requests: write
issues: write
id-token: write
actions: read
steps:
- uses: actions/checkout@v6
with:
fetch-depth: 1
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
To use a subscription token instead, replace the last line with claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}.
API key or subscription token?
- API key: billed per token in the Claude Console. Best for organisations and shared secrets — an OAuth token is tied to the subscription of whoever generated it.
- Subscription token: runs draw on that person's Claude plan limits instead of API billing. Convenient for personal repositories.
Organisations can avoid long-lived secrets entirely with workload identity federation, exchanging GitHub's OIDC token for Claude API access.
Interactive vs automation mode
The action decides how to behave from your workflow:
- Interactive mode (no
promptinput): Claude waits for the trigger phrase —@claudeby default — in a comment, review, or a new issue's title or body, and replies in a comment that it updates as it works. - Automation mode (a
promptinput is set): Claude runs on whatever event triggers the workflow, with results in the workflow log unless the prompt tells it to post.
Example: a daily report
name: Daily Report
on:
schedule:
- cron: "0 9 * * *"
jobs:
report:
runs-on: ubuntu-latest
permissions:
contents: read
issues: read
id-token: write
steps:
- uses: anthropics/claude-code-action@v1
with:
anthropic_api_key: ${{ secrets.ANTHROPIC_API_KEY }}
prompt: "Summarise yesterday's commits and open issues"
claude_args: |
--allowedTools "mcp__github__list_commits,mcp__github__list_issues"
In automation mode, Claude has no shell or GitHub API access until you grant tools with --allowedTools in claude_args (or invoke a skill whose frontmatter grants them). Cron schedules run in UTC — see cron expressions explained.
For automatic PR reviews without maintaining a workflow, Anthropic also offers a separate Code Review feature.
Who can trigger it
By default:
- on issue and PR events, the person triggering it must have write access to the repository,
- bots can't trigger it unless you list them in
allowed_bots— which prevents loops.
That matters on public repositories: random commenters can't spend your tokens.
Controlling cost
Each run uses GitHub Actions minutes and Claude tokens (or plan usage). Keep both in check:
- write specific requests ("fix the null check in
src/billing.tsthat crashes on empty carts"), - keep
CLAUDE.mdconcise — it's read on every run (how to write a CLAUDE.md), - cap iterations with
claude_args: "--max-turns 5", - set a workflow
timeout-minutes, - use GitHub's
concurrencysettings to limit parallel runs, - choose a model with
--modelinclaude_argsif the default is more than you need. (How to change the model.)
Security
- Never commit keys or tokens — always GitHub secrets.
- Grant the workflow only the permissions it needs.
- Review Claude's PRs like any contributor's. (How to review a pull request written by an AI agent.)
- Mind prompt injection: issue text, PR descriptions and code comments are input Claude reads. Keep tool permissions narrow in automation mode. (Prompt injection in coding agents.)
- When you install the app you grant its full permission set; organisations that need fewer permissions can create a custom GitHub App for the action.
Troubleshooting
- Claude doesn't respond: check the app is installed, workflows are enabled, the secret exists, the comment contains
@claudeas a whole word, and the commenter has write access. - CI doesn't run on Claude's commits: commits made with the default
GITHUB_TOKENdon't trigger workflows. Don't passgithub_token: ${{ secrets.GITHUB_TOKEN }}— let the action authenticate as the Claude app. - Upgrading from
@beta: switch to@v1, renamedirect_prompttoprompt, dropmode, and move options likemax_turnsandmodelintoclaude_args.
The summary
/install-github-appsets everything up in a few minutes; manual setup is three steps.- Interactive mode answers
@claude; automation mode runs aprompton any event or schedule. - Use an API key for shared/org setups, a subscription token for personal repos.
- Control cost with specific requests,
--max-turns, timeouts and concurrency limits.
EasySpawn pairs well with this: Claude Code works on a persistent server with your app and database running, pushes branches and opens pull requests, and GitHub Actions — including @claude — verifies and iterates from there. See how it works or join the waitlist.
Related: Running Claude Code Headless · Set Up CI With GitHub Actions · What Is YAML? · Claude Code vs GitHub Copilot
Keep reading
Running Claude Code Agents in Parallel With Git Worktrees
Two agents in one checkout will overwrite each other's work. Git worktrees give each Claude Code session its own files and branch on the same repository. How to set it up, and the parts nobody warns you about: ports, databases, and dependencies.
Claude Code Subagents: When to Split the Work (and When Not To)
Subagents give Claude Code a second context window: a helper that does a noisy job — running tests, searching a codebase, reading logs — and hands back only the summary. How they work, how to write your own, and the tasks where they help versus the ones where they just add cost.