trust commands require the org:trusts scope on your organization role.
create
Create a trust on a service account:The subject is matched exactly. Some GitHub organizations emit ID-qualified claims —
repo:<owner>@<org-id>/<repo>@<repo-id>:ref:refs/heads/main — and a trust created from the plain form is then rejected with invalid_grant: No OIDC trust is configured for this issuer and subject in the specified organization. Create one trust per form; both can point at the same service account. See CI Integration.
