Get started
Getting started
Six steps from a plan to a check run. Apex Actions installs as a GitHub App, and your workflow files stay exactly as they are.
Six steps
Pick a plan
Every plan starts with a 10-day trial, without a card. Start here — the trial is attached to a plan, so this one comes first.
Sign in with GitHub
Continue with GitHub, using the account you already have. We ask first, so everything after it happens under your name.
Create your Account
Your company’s Account in Apex — its name and billing address. You are its Owner, and it can hold several GitHub organisations on one bill.
Install the App
Connect a GitHub organization sends you to GitHub. Choose an organisation you own, or your personal account, and its repositories; GitHub returns you to Apex, which connects it to your Account. Your workflow files stay exactly as they are.
Start your trial
Continue to your trial, choose the plan — each shows its price — and accept the terms. The trial starts on your Account, and it is still no card.
Push
The next push produces a check run for each job, with each step’s result and time and any annotations. The full log is in the Apex dashboard.
Your Account comes first
An Account is your company in Apex: one bill, one plan, and the GitHub organisations you connect to it. After you sign in, the first screen confirms Your details — the GitHub identity you will be the Owner as — and the next, Your Account, asks for the Account's name and billing address, with an optional tax ID. Press Create the Account and you are its Owner: you can invite colleagues, connect organisations and manage billing, and hand ownership on later.
Installing is not the whole of it
The installation is the part people remember, so it is worth saying plainly what it does and does not do. Installing the App on its own does not start anything. It tells GitHub to send us your events; it does not create an Account, choose a plan or begin a trial, and an installation that no Account holds runs nothing. Someone who finds the App in GitHub's directory and installs it from there is brought back to Apex to sign in and create an Account, and the organisation then waits on the connect screen under Already installed, waiting for an Account, with a button Connect organisation to your Account.
The step that starts runs is Start your trial, on the last screen of ours. Until it is pressed there is nothing to run your workflows against.
What happens on GitHub
The connect screen, Connect your GitHub organizations, has a button labelled Connect a GitHub organization. It takes you to the App's installation page on github.com — you will not need to go looking for it, and there is nothing to search for in your settings.
On GitHub's page you choose two things:
- Where to install it. Your personal account, or an organisation you own. Apex asks GitHub, as you, whether you are an owner of it before it connects it to your Account.
- Which repositories. All repositories, or Only select repositories and a list. You can change this later from GitHub, and adding a repository later does not need anything from us.
Press Install and GitHub returns you to the connect screen, which connects the organisation to your Account and lists it under Connected to your Account. Its repositories appear as GitHub reports them; there is nothing to push first. One Account can hold several organisations: connect each the same way.
When the ones you want are connected, press Continue to your trial. That screen shows each plan with its price, its concurrency and its included minutes, and the terms you accept by pressing Start your trial. For now a trial covers one organisation, and the screen names the one it is billed on. The screen after it offers to take a card, which you do not have to do to finish.
What the App asks for
| Permission | Why |
|---|---|
| Checks: read and write | A check run for each job, with its annotations and the flaky-test warning |
| Contents: read and write | To read the workflow files and check out the repository. Write is used only when you ask Apex to pin actions: it proposes that change as a pull request |
| Pull requests: read and write | To open that proposal |
| Workflows: read and write | Files under .github/workflows/ need their own permission for that proposal |
| Actions: read | To read GitHub's own runs of the same commit, for the side-by-side comparison |
| Secrets: read | Secret names only; GitHub never gives an app a secret's value |
| Members: read | To tell who owns an organisation, for paying for its installation. Who may act on a repository is your Apex Account's roles, not GitHub's |
| Organization administration: read | To read what GitHub bills you for Actions, for the savings figure. You may decline it |
| Packages: read and write | So a job's GITHUB_TOKEN can pull images from the GitHub Container Registry. GitHub refuses an app's token for publishing an organisation's packages and for installing from its npm registry, so use a personal access token as a secret for those |
| Metadata: read | To know which repositories the App is installed on |
Turning off hosted runners
While both are enabled, GitHub-hosted runners and Apex will each run the workflow. Add the secrets your workflows use to Apex, as the secrets and variables page describes, then disable Actions on the organisation, or on the repositories you move, once you have seen the first Apex run — the App keeps receiving the events either way.
Apex names each check run <workflow name> / <job name>; GitHub names its own after the job alone.
If a branch protection rule requires a status check, select the Apex check in its place.
The apex CLI
The CLI runs workflows on your machine, sets secrets from a terminal, and reads a run's logs, timing and tests. It is published on npm and needs Node 24 or later:
npm install -g @apex-actions/cli
apex --version
apex login # opens your browser to approve the CLIOver SSH or in a container, apex login prints a code to enter on any device instead, a phone included — the
API tokens guide's Signing in with no browser section has the details.
For scripts and CI, skip apex login and export a token from Settings → API tokens as
APEX_TOKEN. Every command is in the CLI reference, under Reference in the docs menu.