Authentication
Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
OAuth connections
Connect OAuth credentials, GitHub App installation tokens, and verified webhook delivery through explicit Playstack boundaries.
Visit GitHub ↗Compose credentials, magic links, sessions, passkeys, MFA, and connected-provider access without handing application identity to a framework.
OAuth connections
Authorize, encrypt, refresh, and revoke third-party credentials without moving provider APIs or product workflows into a generic abstraction.
OAuth connections · Named providers
Verify provider requests from raw bytes, claim events transactionally, enqueue normalized work exactly once, and keep provider parsing outside domain handlers.
Raw-request verification · Provider normalization
Authenticate GitHub App installations and compose application-owned repository access workflows with scoped, short-lived tokens.
Installation authentication · Repository access provisioning · Reconciliation workflows
@playstack/connections/providers/github stores refreshable OAuth App credentials for acting on a user's or account's behalf. @playstack/github-app creates scoped, short-lived installation tokens for application automation. They solve different identity problems and can be used independently.
import { githubConnectionProvider } from '@playstack/connections/providers/github'
import { createGitHubApp } from '@playstack/github-app'
const github = githubConnectionProvider({
clientId: env.GITHUB_CLIENT_ID,
clientSecret: env.GITHUB_CLIENT_SECRET,
})
const githubApp = createGitHubApp({
appId: env.GITHUB_APP_ID,
privateKey: env.GITHUB_APP_PRIVATE_KEY,
crypto: githubJwtSigner,
client: githubInstallationClient,
cache,
clock,
})githubWebhookProvider() from @playstack/webhooks verifies the exact raw request body and X-Hub-Signature-256, then normalizes the delivery ID and event name. The GitHub App service can consume verified installation deletion or suspension events to invalidate cached credentials.
Repository membership, team policy, reconciliation state, and the full Octokit client remain application-owned. The Playstack packages establish credentials and trusted input without pretending that every product has the same access model.