# Pass a token to subsequent steps

**URL:** <https://forum.buildkite.community/t/pass-a-token-to-subsequent-steps/4323>\
**Category:** Pipelines\
**Created:** [March 24, 2025, 2:21pm UTC](https://forum.buildkite.community/t/pass-a-token-to-subsequent-steps/4323 "2025-03-24T14:21:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ehsan.soure](https://avatars.discourse-cdn.com/v4/letter/e/53a042/32.png) [@ehsan.soure](https://forum.buildkite.community/u/ehsan.soure)\
**Post date:** [March 24, 2025, 2:21pm UTC](https://forum.buildkite.community/t/pass-a-token-to-subsequent-steps/4323/1 "2025-03-24T14:21:54Z")

</div>

Hey team,  
I was looking through the documents and the topics here. I am looking into generating a github token in a step and passing it down to the next steps. I wonder what is the best way to do so? I tried `buildkite-agent env` but the value is not available on the next step this way and is limited to the current step. I tried `buildkite-agent metadata`, but the token is not being redacted. I see in the newer version of agent this is fixed, but I wonder if this is the best way to do it or if there is a better way.

---

<div class="post-metadata">

**Author:** ![ivanna](https://sea2.discourse-cdn.com/flex016/user_avatar/forum.buildkite.community/ivanna/32/1410_2.png) [@ivanna](https://forum.buildkite.community/u/ivanna)\
**Post date:** [March 24, 2025, 3:40pm UTC](https://forum.buildkite.community/t/pass-a-token-to-subsequent-steps/4323/2 "2025-03-24T15:40:38Z")

</div>

Hey @ehsan.soure,

Welcome to the Buildkite community!

You can store the token as a secret environment variable in a [Buildkite hook](https://buildkite.com/docs/pipelines/security/secrets/managing#without-a-secrets-storage-service-exporting-secrets-with-environment-hooks) (eg environment hook).  
Alternatively, you could store token in a [secret management service](https://buildkite.com/docs/pipelines/security/secrets/managing#without-a-secrets-storage-service-exporting-secrets-with-environment-hooks) ( like AWS Secret Manager, HashiCorp Vault or SSM). Buildkite provides various [plugins](https://buildkite.com/docs/pipelines/integrations/plugins) that integrate reading and exposing secrets to your build steps using secrets storage services, such as the following. If a plugin for the service you use is not listed below or in [Buildkite’s plugins directory](https://buildkite.com/docs/pipelines/integrations/plugins/directory), please contact support.

Hope this helps!
