GitHub App Setup

Create/configure a GitHub App with repository Contents: read and write and Pull requests: read and write. Install it only on approved repositories. Exact App owner/name and installation approval process are TO_BE_CONFIRMED.

For installation/hybrid mode configure GITHUB_APP_ID, GITHUB_APP_PRIVATE_KEY, and GITHUB_APP_INSTALLATION_ID. For delegated/hybrid mode also configure OAuth GITHUB_APP_CLIENT_ID, GITHUB_APP_CLIENT_SECRET, the exact public GITHUB_OAUTH_CALLBACK_URL ending at /auth/github/callback, TOKEN_ENCRYPTION_KEY, and preferably persistent AUTHORIZATION_DATABASE_PATH.

Set KB_ALLOWED_REPOS independently of installation scope. The application requires both allowlist authorization and usable GitHub credentials. In GitHub, configure the callback URL exactly; the service’s /auth/github/start endpoint validates its own state then redirects to GitHub.

Validate with /knowledge connect, /knowledge status, a draft approval into a test repository, and /knowledge disconnect. See GitHub authorization.