GitHub
Action requiredNot connectedMOCKRepositories, branches and pull requests as the source of truth for code.
- How it connects
- Paste a key or token
- Health
- healthy
- Integration status
- connected
- Credential
- Not configured
- Last sync
- never
- Connected
- not yet
1 of 3 steps done
Setup
Create a read-only personal access token
You are hereNot done yetYouProvider console (one time)GitHub → Settings → Developer settings → Personal access tokens. A fine-grained token scoped to the repositories you want visible, with read-only Contents, Metadata and Pull requests, is enough. PAXX never writes to GitHub.
Open the provider's consoleEncrypted credential storage initialized
DoneAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.
Paste the token into PAXX
Not done yetYouIn the HubPress Connect and paste it. PAXX calls GET /user with it first — if GitHub does not answer, nothing is stored and you see why.
Paste a key or token
Connect
Create a read-only personal access token on GitHub, then paste it into the Connect form.
Live check
Connection test
GET https://api.github.com/user — confirms the token is live and reports which account it belongs to.
1 declared
Permissions
What PAXX asks the provider for. The provider's own consent screen is the authoritative grant — this list is what will be requested, and after connecting, what was actually returned.
- readRead repositoriesnot requested yetList repos, branches and open pull requests.
Capabilities
What you get
Repositories and branches
readNot availableThe repository list and default branches behind project selection and import.
Available once this provider is connected.
/paxxAdd Project (/paxx/new)Open pull requests
readNot availablePull requests awaiting review, as attention items.
Available once this provider is connected.
Dashboard → AttentionClone source for provisioning
readNot availableThe repository a provisioning run clones onto this VPS. The clone itself is a separate, explicitly approved action — connecting GitHub does not grant it.
Available once this provider is connected.
Add Project (/paxx/new)
Requirements
Diagnostics
Administrator requirements
One-time work for whoever administers this PAXX instance.
Encrypted credential storage initialized
SatisfiedAdministrator (once)In the HubCredentials are sealed with AES-256-GCM before they reach the database, and PAXX refuses to store them at all without a key. Initialize it with one click in the Integration Hub, or set the key in the server environment if you would rather manage it yourself.
Your requirements
Per-person steps — the authorization is yours, not the deployment's.
Create a read-only personal access token
Not satisfiedYouProvider console (one time)GitHub → Settings → Developer settings → Personal access tokens. A fine-grained token scoped to the repositories you want visible, with read-only Contents, Metadata and Pull requests, is enough. PAXX never writes to GitHub.
OpenPaste the token into PAXX
Not satisfiedYouIn the HubPress Connect and paste it. PAXX calls GET /user with it first — if GitHub does not answer, nothing is stored and you see why.