GitHub
Call the GitHub API from a workbench
The GitHub tool lets a workbench agent call the GitHub REST API for repositories, issues, and pull requests. Authenticate with a personal access token or a GitHub App installation, including GitHub Enterprise Server.
Prerequisites
Before you begin, make sure you have:
- Permission in Plural Console to create a configured tool and edit the target workbench.
- Either a GitHub personal access token, or the App ID, installation ID, and PEM private key for a GitHub App you have installed on the target account or organization.
- For GitHub Enterprise Server, the API root for your instance (for example
https://github.mycompany.com/api/v3/).
Option A — personal access token
- In GitHub, open Settings → Developer settings and create a token (classic or fine-grained).
- Grant the scopes your workbench needs — for example
repofor repository and pull request access, plussecurity_eventsif you want the agent to read code scanning, Dependabot, or secret scanning alerts. - Copy the token for the Console form.
Option B — GitHub App
A GitHub App scopes access to only the repositories it is installed on, instead of everything the token owner can see.
- In GitHub, go to Settings → Developer settings → GitHub Apps (use the organization's developer settings if the app should belong to an org) and click New GitHub App.
- Set Repository permissions to only what the workbench needs — for example Contents, Issues, Pull requests, Metadata, and Security events for the capabilities you plan to enable. Leave the webhook disabled unless you separately rely on GitHub sending events to Plural.
- After creation, note the numeric App ID at the top of the app settings page.
- Install the app on the account or organization that owns the target repositories, then open the installation — its URL ends in a numeric installation ID (
.../installations/12345678). Note that ID. - On the app page, scroll to Private keys and generate a key. Upload or paste that PEM file into the Console form; it is stored encrypted.
If you configure both a personal access token and a GitHub App, the GitHub App takes priority and the integration authenticates with installation tokens.