The GitHub App integration provides fine-grained, organization-approved access to repositories and resources. Unlike the GitHub OAuth integration which uses personal access tokens, GitHub Apps are installed at the organization or user level with explicit repository and permission grants.This is the recommended approach for teams that need organizational control over what repositories and permissions agents can access.
Go to your GitHub organization settings (or personal settings) > Developer settings > GitHub Apps > New GitHub App.Configure the app with the permissions your agents need:
Permission
Access
Description
Contents
Read & Write
Code, commits, and branches
Pull requests
Read & Write
Create, review, and merge PRs
Issues
Read & Write
Create and manage issues
Actions
Read & Write
View runs and trigger workflows
Checks
Read & Write
Read CI results, create check runs
Metadata
Read
Repository metadata (always required)
Generate a private key from the app settings page.
2
Install the app
Install the GitHub App on your organization or user account. Choose which repositories to grant access to. You can select all repositories or specific ones.
3
Connect in OneCLI
Open the OneCLI dashboard, go to Connections > GitHub App, and provide:
The GitHub App connect window on OneCLI Cloud.
App ID: The numeric ID from your GitHub App settings
App Slug: The URL-friendly name from your GitHub App settings
Private Key: The PEM private key you generated
OneCLI uses these to generate short-lived installation access tokens automatically.
Skip this section on OneCLI Cloud unless you want your own GitHub App. On self-hosted OneCLI without GITHUB_APP_ID set, this is required. You can enter the app in the dashboard, or set it once for the whole server.
1. Create the GitHub App
In GitHub, open Settings > Developer settings > GitHub Apps > New GitHub App (use your organization’s settings to own it there). Name it, set the homepage URL, and choose the repository permissions your agents need.In OneCLI, open Connections > GitHub App > Custom credentials and copy the Redirect URI. In GitHub, paste it into Redirect URI and into Setup URL, and keep Redirect on update ticked. Under Webhook, untick Active: OneCLI doesn’t use GitHub webhooks, so no webhook URL is needed. Then select Create GitHub App.
The new GitHub App form with the OneCLI Redirect URI. Fill Setup URL and untick Webhook Active further down the same form.
Copy the Redirect URI from Custom credentials in OneCLI.
2. Generate a private key
On the app’s page, select Generate a private key. GitHub downloads a .pem file.
3. Add the app to OneCLI
Paste the app into Connections > GitHub App > Custom credentials:
Field
Value
App ID
The numeric App ID on the app’s page
App Slug
The app’s URL name, from github.com/apps/<slug>
Private Key
The contents of the .pem file
Select Save credentials. To set one app for the whole server instead, set GITHUB_APP_ID, GITHUB_APP_SLUG, and GITHUB_APP_PRIVATE_KEY and restart OneCLI.
4. Connect
Open Connections > GitHub App and select Connect. GitHub asks which account and repositories to install the app on.
Access is per agent: grant the connection to each agent that needs it, choosing per tool what runs freely, what needs human approval, and what stays blocked — a read-only agent is a single grant. Organization rules add guardrails on top, like rate limits and blanket blocks. Everything is checked before credential injection, so a blocked request never reaches GitHub.