Vercel's new `vercel/vcr-action/login` GitHub Action lets you push container images to Vercel Container Registry without storing long-lived credentials. It works via GitHub OIDC: the action exchanges a workflow OIDC token for a short-lived Vercel access token, authenticates Docker against vcr.vercel.com, then revokes the token when the job ends.

Setup requires three things: an OIDC policy on your Vercel team scoped to the specific GitHub repository and workflow with read-write VCR access, a GitHub repo variable holding your Vercel team ID alongside team slug, project slug, and repo name, and `id-token: write` permission on the workflow or job. The action defaults to Docker but accepts an `engines` parameter to swap in Podman or Buildah.

The practical payoff is direct: a prepared `linux/amd64` image from VCR can be referenced as `<repository>:<tag>` and used as a custom Vercel Sandbox image within the same project. The full setup walkthrough, including the exact login step placement in your workflow file, is in the GitHub Actions guide linked in the original changelog. Read it for the precise OIDC policy configuration, which is where most teams will hit friction.

[READ ORIGINAL →]