Alloyqa
DocsSecurityPrivacyPricing
Sign inDownload
Contents01GitHub, connected to the work02Connect GitHub03Repository access04From Task to pull request05Branches and pull requests06What the GitHub App can do07Credentials and execution08Reconnect or disconnect09Troubleshooting
GitHub integration

Your code,
connected carefully.

Alloyqa for GitHubRepository-scoped access9 sections

Alloyqa uses GitHub to access the repositories you choose, run coding Tasks, and create pull requests for review. This page describes the current GitHub App flow and the controls applied while a Task is running.

01

GitHub, connected to the work

Alloyqa for GitHub

Connect the repositories Alloyqa needs for the Tasks you choose to run.

Alloyqa's current web and macOS connection flow uses the Alloyqa GitHub App. GitHub handles the installation and repository selection; Alloyqa then syncs the repositories made available by that installation into your workspace.

That connection is used for repository-aware Task work: reading code, making changes, creating pull requests, and bringing back the checks and review context needed for you to decide what ships.

02

Connect GitHub

  1. 1
    Choose Connect GitHub

    Start from Settings → Integrations, or from the repository prompt in New Task.

  2. 2
    Authorize the GitHub App

    GitHub opens its installation screen, where you choose the account and repositories the App can access.

  3. 3
    Return to Alloyqa

    The signed callback records the installation and refreshes the repository list for the current workspace.

03

Repository access

Alloyqa only exposes repositories returned by your GitHub App installation. You can connect with no repositories selected and update the installation later; until a repository is available, the New Task composer stays open and explains that a repository is required.

When you select a repository for a Task, Alloyqa checks that the connection belongs to the current workspace. The worker receives an explicit repository allow-list, and installation credentials are minted for the repository used by that Task.

Repository selection is scoped.Connecting GitHub does not make every GitHub repository available to Alloyqa. GitHub's installation selection and the repository you choose in the Task composer both apply.
04

From Task to pull request

Every Task has a repository. Create a Task by choosing the connected repository and assigning the work to Alloyqa or a teammate. Alloyqa validates the repository connection before creating the Task.

Task→Isolated execution→Pull request→Review

For Alloyqa execution, the worker performs the repository work in the execution environment and the GitHub integration handles the branch, commit, and pull-request operations. Review Tasks return Ready for review; Auto-merge can merge when the configured completion conditions succeed.

05

Branches and pull requests

Alloyqa creates work on a task-scoped branch rather than writing directly to the repository's default branch. The base branch comes from the Task/repository configuration and falls back to the repository's default branch when available.

When the change is ready, Alloyqa creates or reuses the pull request for that branch and publishes it for review. You can inspect the pull request, checks, and review context in Alloyqa, then merge when you are ready.

For Tasks that select more than one repository, each selected repository is tracked separately so its branch and pull request can be handled with that repository's own installation credential.

06

What the GitHub App can do

The runtime requests permissions by operation. The strongest agent profile is used for Alloyqa execution; read-only profiles are used for repository picking, review, previews, and merge checks.

PermissionAccessWhy it is used
MetadataReadRequired by GitHub for repository identity.
ContentsRead / writeRead code; create commits and branches for Task execution.
Pull requestsRead / writeRead PR context and create or update pull requests.
WorkflowsWriteNeeded only when a Task modifies files under .github/workflows/**.
Commit statusesReadRead verification status for review and repair decisions.
IssuesReadRead pull-request conversation comments.
ChecksReadRead check-run results alongside commit statuses.

The exact permissions shown by GitHub are controlled by the installed App and may reflect the combined permissions requested by the current Alloyqa operation.

07

Credentials and execution

Alloyqa uses GitHub App installation credentials rather than asking you to paste a repository token into a Task. The server requests the smallest runtime profile needed for the operation and verifies the returned permissions and repository association before use.

Alloyqa uses short-lived installation credentials with an expiry time, minted for the repository being operated on.

Repository code is checked out temporarily for execution and is not kept as a permanent copy after the execution environment is cleaned up.

Stored integration credentials are encrypted at the application layer. Tasks run in isolated, job-scoped Cloud environments, and the execution infrastructure is cleaned up after the work is finished.

Alloyqa does not autonomously deploy production changes. Review and merge remain part of the Task completion path you choose.

Read Security at Alloyqa →

08

Reconnect or disconnect

Use Settings → Integrations to reconnect GitHub or update the repositories available to Alloyqa. Reconnecting refreshes the installation reference and reconciles the current repository list.

Disconnecting removes Alloyqa's stored GitHub installation reference and GitHub workflow configuration for the workspace. To revoke the App's access at the GitHub level as well, remove the Alloyqa App installation in GitHub.

Disconnecting does not erase historical Task, pull-request, or review metadata already stored in Alloyqa.

09

Troubleshooting

No repositories appear

Open Settings → Integrations and reconnect or update the GitHub App installation, then refresh the repository picker. The GitHub account may have completed installation with zero repositories selected.

Connect GitHub opens again after canceling

Canceling or closing the GitHub page before the callback completes does not connect anything. Return to Alloyqa and start a new attempt; the Task draft remains local to the composer where supported.

A Task says the repository is unavailable

Confirm that the repository is still selected in the GitHub App installation and connected to the current workspace. Reconnect GitHub if its permissions or installation changed.

A pull request or check cannot be read

Reconnect GitHub if the installation permissions need updating. Alloyqa checks the permission response and reports when an operation needs the installation to be updated.

Contact Alloyqa about a security or access concern →

Alloyqa
Security at Alloyqa →
DocsSecurityPrivacyTermsContact
© 2026 Alloyqa