GitHub App access

Authenticate GitHub App installations and compose application-owned repository access workflows with scoped, short-lived tokens.

Supported approaches

Installation authentication

available

Create scoped, short-lived installation tokens from application-owned GitHub App credentials without persisting them.

Packages

@playstack/github-app

Frameworks and integrations

Repository access provisioning

preview

Translate entitlement changes into explicit invitations and removals for application-configured repositories and teams.

Reconciliation workflows

planned

Compare desired and observed access, retry transient provider failures, and record durable outcomes.

Frameworks and integrations

framework

NestJS

Connect portable Playstack capabilities to dependency injection, guards, decorators, request context, workers, and lifecycle hooks.

integration

BullMQ

Dispatch and process typed Playstack jobs through BullMQ with explicit Redis ownership and native queue access.

integration

Inngest

Dispatch portable Playstack queue jobs through Inngest and serve the generated functions from Next.js, NestJS, or another supported framework.

integration

GitHub

Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.

Package reference

@playstack/github-app

Provision from desired access

GitHub is an application edge, not the source of subscription or entitlement truth. The application resolves desired access first, obtains the narrowest installation token it needs, and performs repository or team operations through its own GitHub client.

ts
import { createGitHubApp } from '@playstack/github-app'

const github = createGitHubApp({
  appId: config.github.appId,
  privateKey: config.github.privateKey,
  crypto: githubJwtSigner,
  client: githubInstallationClient,
  cache,
  clock,
})

const access = await github.getInstallationToken({
  installationId: account.githubInstallationId,
  repositoryIds: account.repositoryIds,
  permissions: { contents: 'read' },
})

Keep provider tokens temporary

Installation access tokens are short-lived implementation details. The package scopes, caches, and refreshes them when needed, then returns the token to the application boundary that performs provider operations. It does not wrap Octokit, store installations, or decide which repositories a subscriber may access.

Reconcile after every edge case

Invitation acceptance is asynchronous, users rename accounts, and organization policy can reject an otherwise valid request. A queue-backed reconciler should record desired versus observed state and retry only operations that remain current. That orchestration remains application-owned today rather than being claimed as an implemented @playstack/github-app service.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software