Get started

Getting started

Six steps from a plan to a check run. Apex Actions installs as a GitHub App, and your workflow files stay exactly as they are.

Six steps

  1. Pick a plan

    Every plan starts with a 10-day trial, without a card. Start here — the trial is attached to a plan, so this one comes first.

  2. Sign in with GitHub

    Continue with GitHub, using the account you already have. We ask first, so everything after it happens under your name.

  3. Create your Account

    Your company’s Account in Apex — its name and billing address. You are its Owner, and it can hold several GitHub organisations on one bill.

  4. Install the App

    Connect a GitHub organization sends you to GitHub. Choose an organisation you own, or your personal account, and its repositories; GitHub returns you to Apex, which connects it to your Account. Your workflow files stay exactly as they are.

  5. Start your trial

    Continue to your trial, choose the plan — each shows its price — and accept the terms. The trial starts on your Account, and it is still no card.

  6. Push

    The next push produces a check run for each job, with each step’s result and time and any annotations. The full log is in the Apex dashboard.

Your Account comes first

An Account is your company in Apex: one bill, one plan, and the GitHub organisations you connect to it. After you sign in, the first screen confirms Your details — the GitHub identity you will be the Owner as — and the next, Your Account, asks for the Account's name and billing address, with an optional tax ID. Press Create the Account and you are its Owner: you can invite colleagues, connect organisations and manage billing, and hand ownership on later.

Installing is not the whole of it

The installation is the part people remember, so it is worth saying plainly what it does and does not do. Installing the App on its own does not start anything. It tells GitHub to send us your events; it does not create an Account, choose a plan or begin a trial, and an installation that no Account holds runs nothing. Someone who finds the App in GitHub's directory and installs it from there is brought back to Apex to sign in and create an Account, and the organisation then waits on the connect screen under Already installed, waiting for an Account, with a button Connect organisation to your Account.

The step that starts runs is Start your trial, on the last screen of ours. Until it is pressed there is nothing to run your workflows against.

What happens on GitHub

The connect screen, Connect your GitHub organizations, has a button labelled Connect a GitHub organization. It takes you to the App's installation page on github.com — you will not need to go looking for it, and there is nothing to search for in your settings.

On GitHub's page you choose two things:

  1. Where to install it. Your personal account, or an organisation you own. Apex asks GitHub, as you, whether you are an owner of it before it connects it to your Account.
  2. Which repositories. All repositories, or Only select repositories and a list. You can change this later from GitHub, and adding a repository later does not need anything from us.

Press Install and GitHub returns you to the connect screen, which connects the organisation to your Account and lists it under Connected to your Account. Its repositories appear as GitHub reports them; there is nothing to push first. One Account can hold several organisations: connect each the same way.

When the ones you want are connected, press Continue to your trial. That screen shows each plan with its price, its concurrency and its included minutes, and the terms you accept by pressing Start your trial. For now a trial covers one organisation, and the screen names the one it is billed on. The screen after it offers to take a card, which you do not have to do to finish.

What the App asks for

PermissionWhy
Checks: read and writeA check run for each job, with its annotations and the flaky-test warning
Contents: read and writeTo read the workflow files and check out the repository. Write is used only when you ask Apex to pin actions: it proposes that change as a pull request
Pull requests: read and writeTo open that proposal
Workflows: read and writeFiles under .github/workflows/ need their own permission for that proposal
Actions: readTo read GitHub's own runs of the same commit, for the side-by-side comparison
Secrets: readSecret names only; GitHub never gives an app a secret's value
Members: readTo tell who owns an organisation, for paying for its installation. Who may act on a repository is your Apex Account's roles, not GitHub's
Organization administration: readTo read what GitHub bills you for Actions, for the savings figure. You may decline it
Packages: read and writeSo a job's GITHUB_TOKEN can pull images from the GitHub Container Registry. GitHub refuses an app's token for publishing an organisation's packages and for installing from its npm registry, so use a personal access token as a secret for those
Metadata: readTo know which repositories the App is installed on

Turning off hosted runners

While both are enabled, GitHub-hosted runners and Apex will each run the workflow. Add the secrets your workflows use to Apex, as the secrets and variables page describes, then disable Actions on the organisation, or on the repositories you move, once you have seen the first Apex run — the App keeps receiving the events either way.

Apex names each check run <workflow name> / <job name>; GitHub names its own after the job alone. If a branch protection rule requires a status check, select the Apex check in its place.

The apex CLI

The CLI runs workflows on your machine, sets secrets from a terminal, and reads a run's logs, timing and tests. It is published on npm and needs Node 24 or later:

npm install -g @apex-actions/cli
apex --version
apex login        # opens your browser to approve the CLI

Over SSH or in a container, apex login prints a code to enter on any device instead, a phone included — the API tokens guide's Signing in with no browser section has the details.

For scripts and CI, skip apex login and export a token from Settings → API tokens as APEX_TOKEN. Every command is in the CLI reference, under Reference in the docs menu.