Your code,
connected carefully.
Alloyqa uses GitHub to access the repositories you choose, run coding Tasks, and create pull requests for review. This page describes the current GitHub App flow and the controls applied while a Task is running.
GitHub, connected to the work
Connect the repositories Alloyqa needs for the Tasks you choose to run.
Alloyqa's current web and macOS connection flow uses the Alloyqa GitHub App. GitHub handles the installation and repository selection; Alloyqa then syncs the repositories made available by that installation into your workspace.
That connection is used for repository-aware Task work: reading code, making changes, creating pull requests, and bringing back the checks and review context needed for you to decide what ships.
Connect GitHub
- 1Choose Connect GitHub
Start from Settings → Integrations, or from the repository prompt in New Task.
- 2Authorize the GitHub App
GitHub opens its installation screen, where you choose the account and repositories the App can access.
- 3Return to Alloyqa
The signed callback records the installation and refreshes the repository list for the current workspace.
Repository access
Alloyqa only exposes repositories returned by your GitHub App installation. You can connect with no repositories selected and update the installation later; until a repository is available, the New Task composer stays open and explains that a repository is required.
When you select a repository for a Task, Alloyqa checks that the connection belongs to the current workspace. The worker receives an explicit repository allow-list, and installation credentials are minted for the repository used by that Task.
From Task to pull request
Every Task has a repository. Create a Task by choosing the connected repository and assigning the work to Alloyqa or a teammate. Alloyqa validates the repository connection before creating the Task.
For Alloyqa execution, the worker performs the repository work in the execution environment and the GitHub integration handles the branch, commit, and pull-request operations. Review Tasks return Ready for review; Auto-merge can merge when the configured completion conditions succeed.
Branches and pull requests
Alloyqa creates work on a task-scoped branch rather than writing directly to the repository's default branch. The base branch comes from the Task/repository configuration and falls back to the repository's default branch when available.
When the change is ready, Alloyqa creates or reuses the pull request for that branch and publishes it for review. You can inspect the pull request, checks, and review context in Alloyqa, then merge when you are ready.
For Tasks that select more than one repository, each selected repository is tracked separately so its branch and pull request can be handled with that repository's own installation credential.
What the GitHub App can do
The runtime requests permissions by operation. The strongest agent profile is used for Alloyqa execution; read-only profiles are used for repository picking, review, previews, and merge checks.
The exact permissions shown by GitHub are controlled by the installed App and may reflect the combined permissions requested by the current Alloyqa operation.
Credentials and execution
Alloyqa uses GitHub App installation credentials rather than asking you to paste a repository token into a Task. The server requests the smallest runtime profile needed for the operation and verifies the returned permissions and repository association before use.
Alloyqa uses short-lived installation credentials with an expiry time, minted for the repository being operated on.
Repository code is checked out temporarily for execution and is not kept as a permanent copy after the execution environment is cleaned up.
Stored integration credentials are encrypted at the application layer. Tasks run in isolated, job-scoped Cloud environments, and the execution infrastructure is cleaned up after the work is finished.
Alloyqa does not autonomously deploy production changes. Review and merge remain part of the Task completion path you choose.
Reconnect or disconnect
Use Settings → Integrations to reconnect GitHub or update the repositories available to Alloyqa. Reconnecting refreshes the installation reference and reconciles the current repository list.
Disconnecting removes Alloyqa's stored GitHub installation reference and GitHub workflow configuration for the workspace. To revoke the App's access at the GitHub level as well, remove the Alloyqa App installation in GitHub.
Disconnecting does not erase historical Task, pull-request, or review metadata already stored in Alloyqa.
Troubleshooting
No repositories appear
Open Settings → Integrations and reconnect or update the GitHub App installation, then refresh the repository picker. The GitHub account may have completed installation with zero repositories selected.
Connect GitHub opens again after canceling
Canceling or closing the GitHub page before the callback completes does not connect anything. Return to Alloyqa and start a new attempt; the Task draft remains local to the composer where supported.
A Task says the repository is unavailable
Confirm that the repository is still selected in the GitHub App installation and connected to the current workspace. Reconnect GitHub if its permissions or installation changed.
A pull request or check cannot be read
Reconnect GitHub if the installation permissions need updating. Alloyqa checks the permission response and reports when an operation needs the installation to be updated.