GitHub is where most Coders do their work. Connect it and the Coder reads your repositories, issues, and pull requests, copies the repository into its own workspace, and turns finished work into a pull request you can review. When your house rules allow it, it can also merge, and the CEO can have a new private repository made for a Coder.
On GitHub, open your profile picture, then Settings, Developer settings, Personal access tokens, Fine-grained tokens.
Choose Generate new token.
Token name: something you will recognise later, such as "StellarFirm Coder".
Expiration: pick a date. When the token expires, the Coder stops as Blocked and asks you for a new one.
Resource owner: your own account, or the organization that owns the repositories.
Repository access: choose Only select repositories and pick the ones the Coder may use. Choose All repositories only if you want the CEO to create new repositories.
Under Repository permissions, set:
Contents: Read and write
Pull requests: Read and write
Issues: Read and write
Commit statuses: Read-only
Metadata: Read-only (GitHub sets this for you)
Workflows: Read and write, only if the Coder may change files in .github/workflows
Administration: Read and write, only if the CEO may create repositories
Choose Generate token and copy it. GitHub shows it once.
If the resource owner is an organization that reviews tokens, an owner approves it under the organization's Settings, Personal access tokens, Pending requests. Until then the token cannot see those repositories.
The card shows Connected. Your token is saved on your computer by the desktop app, never shown back to you, and handed to one git command at a time. It is never written into the repository's settings.
The Coder needs a repository, written as owner/repository. Give it one of two ways.
In your message. Name it, or paste its link: "Coder, in acme/web, fix the login redirect."
For good, per Coder. Open Settings, Coders, edit the Coder, and under Repository and login choose GitHub as source control and fill in Repository. A message that names that repository then goes to that Coder. See several Coders.
Each Coder can also act as its own GitHub account. Under Repository and login, choose Its own login and paste a token for that account, for example a machine account that only has access to one repository. Its pull requests then show that account instead of yours. The token needs the same permissions as above.
You can ask for a new repository in chat. The Coder creates it after you Approve. It is always private, starts with a README so it has a main branch, and becomes that Coder's repository for the rest of the run.
What the token needs:
A classic token with repo, or a fine-grained token with Administration: Read and write and All repositories. A token limited to selected repositories cannot see one that does not exist yet.
For a repository in an organization, your account must be allowed to create repositories there, and a fine-grained token must have that organization as its resource owner.
Where it goes: the owner you name ("in the acme org"), otherwise the owner of the Coder's current repository, otherwise your own account. To keep using it after you restart the app, set it as the Coder's repository under Settings, Coders.
Creating repositories is a GitHub feature. On GitLab and Bitbucket, create the project yourself and give it to the Coder.
Pushing and merging follow your house rules. The Coder pushes to a new branch of its own, never to your default branch, and never force pushes. Pushing waits for your Approve. Merging follows your merge policy: review only by default, and never while checks are failing or still running. Your branch protection on GitHub still applies.
Drafts and your GitHub plan. GitHub allows draft pull requests on private repositories only on its Team and Enterprise plans. On a personal account or a free organization, the Coder opens a regular pull request instead and tells you so. It still waits for your review.
Drafts cannot be merged. Before you ask the Coder to merge, open the pull request on GitHub and choose Ready for review.
If the clone fails, the job stops as Blocked before any coding and says what to fix, usually that the token cannot read that repository.
Several code hosts connected? A link or the host's name in your message picks the host. Otherwise the Coder uses the one that has a repository set.
GitHub Enterprise Server is not connected from the app. Ask support if you need it.
Revoke at any time. Delete the token on GitHub and the Coder loses access straight away. Then choose Turn off on the GitHub card.