Learn how to set up Claude Code with GitHub Actions for automated code review, issue triage, and CI/CD workflows. Covers workflow configuration, authentication, CLI flags, and best practices.
This guide walks you through setting up Claude Code with GitHub Actions to automate code review, issue triage, and other CI/CD workflows. It is written for developers who already have a GitHub repository and want to use Claude Code to review pull requests, analyze code changes, and run automated tasks without manual intervention. By the end, you will understand how to configure a GitHub Actions workflow that invokes Claude Code, how to handle authentication in CI, and what flags and settings control Claude Code's behavior in a non-interactive environment.
Before you begin, ensure you have the following:
Claude Code is an agentic coding tool that reads your codebase, edits files, runs commands, and integrates with your development tools. It is available on multiple surfaces: terminal, VS Code, JetBrains IDEs, desktop app, web, and CI/CD. The official documentation states that "In CI, you can automate code review and issue triage with GitHub Actions or GitLab CI/CD." This means Claude Code can run as part of your automated pipeline, reviewing pull requests, analyzing code changes, and even creating commits or pull requests based on its analysis.
When running in CI, Claude Code operates non-interactively. You provide a prompt via the -p flag, and Claude Code executes the task, then exits. It does not wait for user approval because there is no human in the loop. This is a key difference from interactive sessions where Claude asks for approval before changing files. In CI, you must design your workflow to either trust Claude Code's edits or use a review step that requires human sign-off before merging.

In your GitHub repository, create a new file at .github/workflows/claude-code-review.yml. This file defines the workflow that will trigger Claude Code on events like pull requests or pushes.
Here is a basic workflow that runs Claude Code on every pull request to review the changed files:
name: Claude Code Review
on:
pull_request:
types: [opened, synchronize]
jobs:
review:
runs-on: ubuntu-latest
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install Claude Code
run: |
curl -fsSL https://claude.ai/install.sh | bash
- name: Run Claude Code review
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
claude -p "Review the changes in this pull request. Look for security issues, bugs, and style problems. Provide a summary of your findings." --print
pull_request events with types opened (when a PR is first created) and synchronize (when new commits are pushed to the PR branch). You can add other types like ready_for_review or reopened as needed.ANTHROPIC_API_KEY containing your Anthropic API key. According to the quickstart guide, you can log in using a Claude Console account (API access with pre-paid credits) or a Claude subscription. For CI, using an API key from the Claude Console is the recommended approach because it does not require browser-based authentication.-p flag: This tells Claude Code to run a one-off query and then exit. The prompt instructs Claude to review the changes. The --print flag makes Claude Code output the response to stdout, which is captured in the GitHub Actions logs.ANTHROPIC_API_KEY.Your API key is now available in the workflow as ${{ secrets.ANTHROPIC_API_KEY }}. Never hardcode the key in the workflow file.
A more useful workflow posts Claude Code's review as a comment on the pull request. Here is an example that uses the GitHub CLI (gh) to comment:
name: Claude Code PR Review
on:
pull_request:
types: [opened, synchronize]
jobs:
review:
runs-on: ubuntu-latest
permissions:
pull-requests: write
contents: read
steps:
- name: Checkout code
uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Install Claude Code
run: |
curl -fsSL https://claude.ai/install.sh | bash
- name: Run Claude Code review
id: review
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
claude -p "Review the changes in this pull request. Focus on security vulnerabilities, potential bugs, and code quality issues. Provide a concise summary with bullet points." --print > review_output.txt
cat review_output.txt
- name: Post review comment
env:
GH_TOKEN: ${{ github.token }}
run: |
gh pr comment ${{ github.event.pull_request.number }} --body "$(cat review_output.txt)"
permissions block grants pull-requests: write so the workflow can post comments. contents: read is the default and sufficient for checking out the code.id: review allows later steps to reference this step's outputs if needed.review_output.txt. The cat command prints it to the logs for debugging.gh) is pre-installed on GitHub Actions runners. ${{ github.token }} is an automatically generated token that allows the workflow to comment on the PR. The gh pr comment command posts the review output as a comment.Beyond pull request review, you can automate issue triage. The official documentation mentions "automate code review and issue triage with GitHub Actions." Here is a workflow that runs when an issue is opened:
name: Claude Code Issue Triage
on:
issues:
types: [opened]
jobs:
triage:
runs-on: ubuntu-latest
permissions:
issues: write
steps:
- name: Checkout code
uses: actions/checkout@v4
- name: Install Claude Code
run: |
curl -fsSL https://claude.ai/install.sh | bash
- name: Analyze issue
id: analyze
env:
ANTHROPIC_API_KEY: ${{ secrets.ANTHROPIC_API_KEY }}
run: |
claude -p "Analyze this GitHub issue: '${{ github.event.issue.title }}' - '${{ github.event.issue.body }}'. Suggest a priority level (low, medium, high), identify which part of the codebase it likely relates to, and propose a next step for a developer." --print > analysis.txt
cat analysis.txt
- name: Add label and comment
env:
GH_TOKEN: ${{ github.token }}
run: |
gh issue comment ${{ github.event.issue.number }} --body "$(cat analysis.txt)"
# Optionally add a label based on analysis
# gh issue edit ${{ github.event.issue.number }} --add-label "needs-triage"
This workflow triggers on new issues, analyzes the title and body, and posts a comment with Claude's analysis. You can extend it to automatically add labels based on Claude's output, though that requires parsing the output in a subsequent step.
When running Claude Code locally, you authenticate via a browser-based OAuth flow. In CI, there is no browser, so you must use an API key. The official documentation states: "You can log in using any of these account types: Claude Pro, Max, Team, or Enterprise (recommended); Claude Console (API access with pre-paid credits); Amazon Bedrock, Google Cloud's Agent Platform, or Microsoft Foundry." For CI, the Claude Console account is the most straightforward because it provides an API key that you can store as a GitHub secret.
If you use a Claude subscription (Pro, Max, Team, or Enterprise), you cannot easily authenticate in CI because the login flow requires a browser. The API key from the Console is the recommended approach for automated workflows.
Claude Code provides several flags that are particularly useful in CI environments. These are documented in the CLI reference and the quickstart guide:
| Flag | Description | Example |
|---|---|---|
-p "query" | Run a one-off query, then exit. This is the primary flag for CI. | claude -p "review this code" |
--print | Print the response to stdout. Without this, Claude Code may not output anything visible in CI logs. | claude -p "summarize" --print |
-c | Continue the most recent conversation in the current directory. Less useful in CI because each run is isolated. | claude -c |
-r | Resume a previous conversation. Not typically used in CI. | claude -r |
--version | Print the version number followed by (Claude Code). Useful for debugging. | claude --version |
The -p flag is the workhorse for CI. It accepts a string prompt and executes it non-interactively. The --print flag ensures the output is captured in the CI logs, which you can then use in subsequent steps (e.g., to post a comment).
In interactive mode, Claude Code has several permission modes that control whether it asks for approval before making changes. The official documentation describes these modes: acceptEdits auto-approves file edits, plan lets Claude propose changes without editing, and some accounts have an auto mode that runs a background safety check and blocks risky actions. In CI, however, there is no interactive prompt. Claude Code will execute the task without asking for approval. This means you must be careful about what prompts you give it. If you ask Claude to edit files in CI, it will do so without human review. For code review workflows, this is fine because Claude is only reading and analyzing code, not modifying it. If you want Claude to make changes (e.g., auto-fix lint errors), you should have a separate human review step before merging.
Based on the quickstart guide's pro tips and common workflows, here are best practices for crafting prompts in CI:
git diff main...HEAD | claude -p "review this diff" --print. The overview shows this pattern: git diff main --name-only | claude -p "review these changed files for security issues".
If you see an authentication error in the CI logs, check that:
ANTHROPIC_API_KEY secret is correctly set in your GitHub repository.If the native install script fails with syntax error near unexpected token, you are likely running it in the wrong shell. The official documentation provides guidance: "If you see The token '&&' is not a valid statement separator, you're in PowerShell, not CMD. If you see 'irm' is not recognized as an internal or external command, you're in CMD, not PowerShell." On GitHub Actions, the default shell on ubuntu-latest is bash, which should work fine with the curl command. If you are using a Windows runner, use the PowerShell install command: irm https://claude.ai/install.ps1 | iex.
If the workflow runs but you see no output from Claude Code, you may have forgotten the --print flag. Without it, Claude Code may not print the response to stdout. Add --print to the command.
If the output is too long, the gh pr comment command may fail or truncate. Consider asking Claude for a concise summary. You can also split the output into multiple comments if needed.
If the workflow fails with a permission error when trying to post a comment, ensure the permissions block includes pull-requests: write. Also check that the workflow is running on the default branch (usually main) for pull request events from forks. By default, GitHub Actions does not give write permissions to workflows triggered by pull requests from forked repositories. You may need to adjust the workflow settings in your repository to allow write access for fork PRs, or use a different approach like creating a check run instead of a comment.
Once you have basic automated code review working, explore these next steps from the official documentation:
claude "write tests for the auth module, run them, and fix any failures".CLAUDE.md file to your project root to set coding standards, architecture decisions, preferred libraries, and review checklists. Claude Code reads this file at the start of every session, including CI sessions.For more details, refer to the official documentation on Claude Code overview and the quickstart guide.
Learn how to run Claude Code in CI/CD pipelines without interactive prompts. Covers authentication, permission configuration, GitHub Actions and GitLab CI integration, and troubleshooting common issues.
Learn how to install, configure, and start using Claude Code to automate desktop tasks, fix bugs, manage Git workflows, and build features directly from your terminal, IDE, or desktop app.
Complete guide to Claude Code settings, permissions, and configuration scopes. Learn how to manage user, project, local, and managed settings, use the /config command, and handle invalid entries.
Learn to use the Claude Message Batches API for cost-effective, high-throughput processing of multiple prompts. Covers setup, batch creation, monitoring, result retrieval, and troubleshooting with practical examples.
Learn how to connect Claude Code to your database using the Model Context Protocol (MCP). This guide covers setup, configuration, querying, and advanced usage with real-world examples.
Learn how to write Claude system prompts that produce measurably better results using hooks, settings, CLAUDE.md files, and permission rules. Covers official Anthropic patterns and community-proven techniques.
Workflows from the Neura Market marketplace related to this Claude resource