Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
GitHub
Let AI agents read repositories and create issues through GitHub App installation tokens scoped to one repo and the least permission.
The broker holds a GitHub App private key and exchanges it, per operation, for an installation token scoped to the target repository and the smallest permission the action needs.
Actions
| Action | Permission requested | Parameters |
|---|---|---|
REPO_READ | contents: read | none |
ISSUE_READ | issues: read | none |
ISSUE_CREATE | issues: write | title, optional body |
PR_READ | pull requests: read | none |
The resource is owner/repo.
Setup
- Create a GitHub App with the repository permissions you plan to allow, and install it on the repositories agents may touch.
- Seal the App's private key (PEM) and store it as the
githubcredential. - Set on the broker:
GITHUB_APP_ID=123456 GITHUB_APP_INSTALLATION_ID=7890123
Installation tokens last about an hour; GitHub does not allow shorter ones, so credential_ttl cannot shorten them. Use constraints, for example limiting issue labels, to narrow what an agent may write.