IntegrationsIntegration setup guides

GitHub

Connect GitHub to your Appstrate agents: the REST API, GitHub's hosted MCP server, or a sandboxed git workflow.

Overview

GitHub hosts code and collaboration. Appstrate ships three GitHub integrations, each a separate package with separate connections.

IntegrationSourceUse it for
@appstrate/github (version 1.0.5)api_callCalling the GitHub REST API directly
@appstrate/github-mcp (version 1.1.3)Remote MCPGitHub's hosted MCP server: 93 tools covering repositories, issues, pull requests, Actions, code security, notifications, projects, gists and discussions
@appstrate/github-git (version 1.0.3)Local runnerA clone, edit, commit, push and pull request loop on a real working tree

GitHub (API): @appstrate/github

PropertyValue
Typeoauth2
Credential sent asAuthorization: Bearer <credential>
Default scopesrepo, read:user
Token endpoint authclient_secret_post

Scopes

ScopeDescriptionDefault
repoFull repository accessyes
read:userRead user profileyes
user:emailRead user emails
read:orgRead org membership
gistCreate gists
notificationsAccess notifications
workflowUpdate GitHub Actions workflows

Authorized URIs

  • https://api.github.com/**
  • https://codeload.github.com/**
  • https://raw.githubusercontent.com/**
  • https://gist.githubusercontent.com/**
  • https://objects.githubusercontent.com/**
  • https://media.githubusercontent.com/**
  • https://release-assets.githubusercontent.com/**
  • https://pipelines.actions.githubusercontent.com/**

A call or redirect hop to another githubusercontent.com host, such as avatars.githubusercontent.com, is refused.

GitHub (MCP): @appstrate/github-mcp

Two authentication methods, both accepted:

Auth keyTypeDetails
oauthoauth2An OAuth App registered by an administrator. GitHub's MCP server does not support dynamic client registration. Default scopes: read:user, repo, read:org, workflow, security_events, notifications, gist, read:discussion, write:discussion, read:project, project
patapi_keyA personal access token (classic or fine-grained), pasted into the connect form as personal_access_token, sent as Authorization: Bearer <token>

Each tool declares the scopes it needs (public_repo, repo, security_events, notifications, workflow, gist, read:discussion, write:discussion, read:user, read:org, read:project, project), so OAuth consent asks only for what the selected tools use. A personal access token carries whatever permissions you gave it.

This integration allows tools: "*": an agent can select every tool the server advertises instead of listing them. Prefer an explicit list.

Authorized URIs: https://api.githubcopilot.com/** and https://api.github.com/**.

GitHub Git: @appstrate/github-git

Runs the @appstrate/github-git-mcp server in a sandboxed runner container. The platform gives the runner an OAuth token with the repo scope as a Basic credential for git over HTTPS, mounts a per-run workspace at /workspace, and the server shells out to git. The agent edits the files with its own file tools. Tools: clone, checkout_branch, status, diff, commit, push, open_pr.

Authorized URIs: https://api.github.com/**, https://github.com/** and https://codeload.github.com/**. Needs the docker or firecracker run adapter.

Connect GitHub

An administrator registers an OAuth App once (not needed for a personal access token).

Create an OAuth App under Settings, Developer settings, OAuth Apps (open).

Set the "Authorization callback URL" to APP_URL followed by /api/integrations/callback, as shown in the integration's setup panel.

In Appstrate, open the integration and register the OAuth client (client ID and client secret). See How integrations work.

Use it in an agent

Excerpt of the agent manifest:

{
  "dependencies": {
    "integrations": { "@appstrate/github-mcp": "^1.0.0" }
  },
  "integrations_configuration": {
    "@appstrate/github-mcp": {
      "tools": ["list_issues", "issue_read", "issue_write"]
    }
  }
}

Example prompt:

Every Monday, list the issues opened last week in acme/api without a label,
propose a label for each one, and add it after my approval.

On this page