Docs / Guides

GitHub

Let AI agents read repositories and create issues through GitHub App installation tokens scoped to one repo and the least permission.

The broker holds a GitHub App private key and exchanges it, per operation, for an installation token scoped to the target repository and the smallest permission the action needs.

Actions

ActionPermission requestedParameters
REPO_READcontents: readnone
ISSUE_READissues: readnone
ISSUE_CREATEissues: writetitle, optional body
PR_READpull requests: readnone

The resource is owner/repo.

Setup

  1. Create a GitHub App with the repository permissions you plan to allow, and install it on the repositories agents may touch.
  2. Seal the App's private key (PEM) and store it as the github credential.
  3. Set on the broker:
    GITHUB_APP_ID=123456
    GITHUB_APP_INSTALLATION_ID=7890123

Installation tokens last about an hour; GitHub does not allow shorter ones, so credential_ttl cannot shorten them. Use constraints, for example limiting issue labels, to narrow what an agent may write.