@kody/github
Call GitHub REST, GraphQL, and pull requests with a GitHub OAuth App or a personal access token.
README.md
72 lines · 4.4 KB · Markdown@kody/github
Intent
Reusable GitHub REST, GraphQL, and pull request helpers for Kody agents. One package covers a GitHub OAuth App you register and personal access tokens. Multi-account routing is an integrationName (OAuth) or secretName (PAT) parameter — there are no hard-coded personal aliases.
What it does
- Call the GitHub REST and GraphQL APIs with the correct saved credential
- Verify which GitHub identity will perform an action
- Fetch pull request details and CI check-runs
- Preview or apply PR merges and draft/ready status (
dryRun/confirm)
Prerequisites / setup
Create a GitHub OAuth App (or save a PAT) before calling helpers. If a github connection already exists, reuse it. Never paste tokens into chat. Agents: see AGENTS.md for import paths and smoke checks.
Auth lanes
| Lane | Credential | When to use |
|---|---|---|
| A. Personal access token | User secret (documented name githubAccessToken) as secretName | Fastest for many automations; fine-grained tokens for read-only private-repo access. |
| B. Bring-your-own OAuth App | Saved integration github (or another name as integrationName) | Durable OAuth with your own client and rate limits. |
This is not a GitHub App / installation-token package. Required hosts: api.github.com, uploads.github.com.
Lane A: personal access token
- Open github.com/settings/personal-access-tokens and generate a fine-grained token (classic tokens at github.com/settings/tokens also work but are coarser).
- Set an expiration, choose repositories, and pick the minimum permissions (for reporting: Contents: Read-only and Pull requests: Read-only; add write only for mutations).
- Copy the token once. Never paste it into chat.
- Save it in Kody and approve the hosts:
https://kody.codes/account/secrets/new?name=githubAccessToken&description=GitHub%20fine-grained%20personal%20access%20token&allowedHosts=api.github.com%2Cuploads.github.com&scope=user- Call helpers with
secretName: 'githubAccessToken'(or your chosen name).secretNameselects the PAT lane and ignoresintegrationName.
Lane B: bring-your-own OAuth App
- Open github.com/settings/developers → OAuth Apps → New OAuth App.
- Set the Authorization callback URL exactly to
https://kody.codes/connect/oauth. - Generate a client secret. GitHub still requires the client secret at the token endpoint even with PKCE, so the Kody flow is
confidential. - Connect (adjust
providerandscopesas needed):
https://kody.codes/connect/oauth?provider=github&authorizeUrl=https%3A%2F%2Fgithub.com%2Flogin%2Foauth%2Fauthorize&tokenUrl=https%3A%2F%2Fgithub.com%2Flogin%2Foauth%2Faccess_token&flow=confidential&scopes=read%3Auser%20repo%20user%3Aemail&allowedHosts=api.github.com%2Cuploads.github.comDecoded: authorize https://github.com/login/oauth/authorize, token https://github.com/login/oauth/access_token, flow=confidential, scopes read:user repo user:email, hosts api.github.com,uploads.github.com. Add pkce=true to layer S256 PKCE on the confidential exchange.
Suggested BYO scope tiers (space-delimited):
- Read-mostly public:
read:user,user:email,notifications,public_repo,read:org - Private repos:
repo(write comes with it), plusgist/workflowonly if needed
Multiple GitHub identities
Every export accepts optional integrationName (OAuth, default github) and secretName (PAT). Connect extra accounts under their own integration names — for example github-work — by changing provider in the connect URL. Pass that name on every call. Do not hard-code personal aliases in forks of this package.
account is accepted as an alias for integrationName. The retired alias bot throws with the connect and PAT setup URLs above.
Mutations
pr/merge, pr/set-review-status, GraphQL mutation operations, and REST methods other than GET / HEAD / OPTIONS require dryRun: true (preview) or confirm: true (live write).
Done when
- OAuth integration
githubis connected and/or secretgithubAccessTokenis saved with GitHub hosts approved - Identity check returns a
loginfor the selected lane - Mutations refuse to write GitHub unless
dryRun: trueorconfirm: true