Skip to content
Latchkey

GitHub Actions composite action cannot access secrets directly

Composite actions cannot read the secrets context directly; only the calling workflow can. A composite action that references secrets.* gets an unrecognized context error or an empty value - secrets must be passed in as inputs.

What this error means

A composite action fails validation referencing secrets.*, or a secret it expected is empty at runtime.

github-actions
Error: Unrecognized named-value: 'secrets'. Located at position 1 within expression: secrets.NPM_TOKEN

Common causes

Direct secrets reference inside composite

The composite action body references secrets.NPM_TOKEN, but the secrets context is not exposed to composite actions.

How to fix it

Pass the secret in as an input

  1. Declare an input on the composite action for the secret value.
  2. In the calling workflow, pass the secret via with.
  3. Reference inputs.<name> inside the composite action; re-run.
action.yml + caller
# action.yml (composite)
inputs:
  npm-token:
    required: true
runs:
  using: composite
  steps:
    - run: npm publish
      shell: bash
      env:
        NODE_AUTH_TOKEN: ${{ inputs.npm-token }}
# caller workflow
- uses: ./.github/actions/publish
  with:
    npm-token: ${{ secrets.NPM_TOKEN }}

How to prevent it

  • Pass secrets into composite actions as explicit inputs.
  • Never reference the secrets context inside composite action bodies.

Frequently asked questions

What causes ""composite action cannot access secrets""?
The composite action body references secrets.NPM_TOKEN, but the secrets context is not exposed to composite actions.
How do I fix "composite action cannot access secrets"?
Pass the secret in as an input

Related guides

References

Latchkey auto-heals failures like this one - detected, fixed, and retried without you. Start free → 30-day trial · No credit card