---
title: "@playstack/github-app"
description: "GitHub App JWT and scoped installation-token lifecycle with explicit cache and webhook boundaries."
tags: ["package","identity","github","github-app","installations","pro"]
---

{/* package-access:start */}

> **Pro.** Covered by the Playstack Pro License. Registry access is required; check preview availability before installing. See [package access](/docs/packages#access-policy).

{/* package-access:end */}

`@playstack/github-app` creates, scopes, caches, and refreshes short-lived GitHub App installation tokens. It does not wrap Octokit, persist installations, receive raw webhooks, or decide which repositories a subscriber may access.

```ts
const githubApp = createGitHubApp({
  appId: env.GITHUB_APP_ID,
  privateKey: env.GITHUB_APP_PRIVATE_KEY,
  crypto: githubJwtSigner,
  client: githubInstallationClient,
  cache,
  clock,
})

const access = await githubApp.getInstallationToken({
  installationId,
  repositoryIds,
  permissions: { contents: 'read' },
})
```

The service backdates and bounds App JWTs, refreshes installation tokens before expiry, and keys cached access by installation plus requested scope. Verified installation deletion or suspension events from `@playstack/webhooks` invalidate related cached credentials. Repository policy and reconciliation remain application-owned.

{/* package-install:start */}

## Install

After confirming [preview access](/docs/packages#access-policy), install the package at your application's shared Playstack version:

```sh
npm install --save-exact @playstack/github-app@0.1.0-beta.1
```

Check the peer requirements below before choosing a runtime or provider.

{/* package-install:end */}

{/* package-reference:start */}

## API entry points and requirements

Reference snapshot: `@playstack/github-app@0.1.0-beta.1`. Import only the entry point your runtime needs. Paths below are relative to the installed package; use **Go to Definition** in your editor to inspect exact parameters, return types and overloads. Do not import the declaration-file paths directly.

| Public entry point | Declaration file |
| --- | --- |
| `@playstack/github-app` | `./dist/index.d.ts` |
| `@playstack/github-app/errors` | `./dist/errors.d.ts` |
| `@playstack/github-app/testing` | `./dist/testing.d.ts` |
| `@playstack/github-app/package.json` | No TypeScript declaration (asset or metadata export). |

Node.js engine requirement: `>=20`. This is not a claim that every entry point works in browsers or Workers.

### Peer dependencies

This package declares no peer dependencies. Its ordinary dependencies are resolved by the package manager.

For a complete first program, start with [Getting started](/docs/getting-started). For API lookup and partial-example conventions, see [Reading the reference](/docs/packages#reading-the-reference). Provider failures, lifecycle requirements and application responsibilities remain described in the guide above; types alone do not establish production safety.

{/* package-reference:end */}
