# How to run the DunSocial CLI in GitHub Actions > Create a token in Settings → CLI, add DUN_TOKEN & DUN_WORKSPACE_ID as repository secrets, then call npx dunsocial from a workflow step. Pin the version, use the smallest scopes you need & set a schedule delay so a person can review. Updated: 2026-10-05. ## What you're building A workflow step that posts or schedules an announcement when something happens in your repository, such as a release. It runs unattended, so authentication is a token rather than a browser sign-in. ## Step 1: create a token In DunSocial open Settings → CLI & create an access token. It's shown once, so copy it straight away. Pick the smallest scopes the job needs, such as `posts:schedule`. Tokens are bound to one workspace. ## Step 2: add repository secrets | Secret | Value | |--------|-------| | `DUN_TOKEN` | The `dun_pat_…` token | | `DUN_WORKSPACE_ID` | The workspace id, from the app or `dun workspace list` | | `DUN_X_ACCOUNT_ID` | The account id to post to, from `dun accounts list` | Never print the token in logs & never commit it. ## Step 3: call the CLI from a step ```yaml - uses: actions/setup-node@v4 with: node-version: 20 - name: Announce release env: DUN_TOKEN: ${{ secrets.DUN_TOKEN }} DUN_WORKSPACE_ID: ${{ secrets.DUN_WORKSPACE_ID }} run: | npx --yes dunsocial@0.4.0 posts schedule \ --text "Shipped ${{ github.event.release.tag_name }}" \ --accounts ${{ secrets.DUN_X_ACCOUNT_ID }} \ --in 5m \ --json ``` When the `CI` environment variable is set, the CLI defaults to JSON output & treats destructive commands as confirmed. Export `CI=1` in the step if your runner doesn't set it. DunSocial's CLI needs nothing in the runner beyond Node.js, so there's no extra install step. ## Pin the version `dunsocial@0.4.0` above is only an example. Pin the version you tested so a new release can't change behaviour in your pipeline. Update it deliberately, then re-run. DunSocial publishes the CLI on npm as `dunsocial`, so any version you pin can be reinstalled later. ## Schedule, don't publish Use `schedule` with a short delay instead of `publish`. The post then lands on the DunSocial calendar for a few minutes, so a person can edit or cancel it if the release notes need a tweak. DunSocial shows CLI-created posts with a CLI source badge, so the team can tell a pipeline post from a manual one. ## Handle failures Add `--json` & check the exit code, as described in the exit-codes article. A 3 usually means a missing scope, & a 6 means rate limiting. If the token leaks, revoke it in Settings → CLI straight away & create a new one. A personal access token can't manage other tokens or billing, so its reach is limited, but it can still post. DunSocial's webhooks can also tell your own systems when a post fails to publish, through the `post.publish_failed` event. ## Related guides - [How to automate social media posting in a CI/CD pipeline](https://www.dunsocial.com/hub/social-media-automation-for-developers/how-to-automate-social-media-posting-in-a-ci-cd-pipeline.md) - [What do the DunSocial CLI exit codes mean?](https://www.dunsocial.com/hub/dunsocial-cli-guides/what-do-the-dunsocial-cli-exit-codes-mean.md) - [Which PAT scopes should you grant for each automation job?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/which-pat-scopes-should-you-grant-for-each-automation-job.md) - [How to sign in to the DunSocial CLI](https://www.dunsocial.com/hub/dunsocial-cli-guides/how-to-sign-in-to-the-dunsocial-cli.md) ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/dunsocial-cli-guides/how-to-run-the-dunsocial-cli-in-github-actions. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login