GitHub

Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.

Visit GitHub ↗

Supported features

Authentication

Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.

OAuth connections

Connections

Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.

OAuth connections · Named providers

Webhooks

Verify provider requests from raw bytes, claim events transactionally, enqueue normalized work exactly once, and keep provider parsing outside domain handlers.

Raw-request verification · Provider normalization

GitHub App access

Authenticate GitHub App installations and compose application-owned repository access workflows with scoped, short-lived tokens.

Installation authentication · Repository access provisioning · Reconciliation workflows

Package reference

@playstack/connections

Choose the GitHub identity you need

@playstack/connections/providers/github stores refreshable OAuth App credentials for acting on a user's or account's behalf. @playstack/github-app creates scoped, short-lived installation tokens for application automation. They solve different identity problems and can be used independently.

ts
import { githubConnectionProvider } from '@playstack/connections/providers/github'
import { createGitHubApp } from '@playstack/github-app'

const github = githubConnectionProvider({
  clientId: env.GITHUB_CLIENT_ID,
  clientSecret: env.GITHUB_CLIENT_SECRET,
})

const githubApp = createGitHubApp({
  appId: env.GITHUB_APP_ID,
  privateKey: env.GITHUB_APP_PRIVATE_KEY,
  crypto: githubJwtSigner,
  client: githubInstallationClient,
  cache,
  clock,
})

Verify lifecycle events before acting

githubWebhookProvider() from @playstack/webhooks verifies the exact raw request body and X-Hub-Signature-256, then normalizes the delivery ID and event name. The GitHub App service can consume verified installation deletion or suspension events to invalidate cached credentials.

Repository membership, team policy, reconciliation state, and the full Octokit client remain application-owned. The Playstack packages establish credentials and trusted input without pretending that every product has the same access model.

Go

Playstack Pro tag
OriginsPricingBlogNewsletterChangelogStatusRoadmap
ContributorsCommunityIn Use ShowcaseCase StudiesPartnersSponsors
FAQsSupportContact

© 2026 Playstack. All rights reserved.

With OSS
Terms of ServicePrivacy PolicyCookie PolicyImprint

By

Commune Software