Skip to content
StellarFirmStellarFirm
Mission manual
Esc

Type a word to search every page. Try , or .

Module 06 · Integrations

GitHub

Connect GitHub for the Coder: which token to create, the exact permissions for each step, where to paste it, and how to fix the usual errors.

View as Markdown
On this page

GitHub is where most Coders do their work. Connect it and the Coder reads your repositories, issues, and pull requests, copies the repository into its own workspace, and turns finished work into a pull request you can review. When your house rules allow it, it can also merge, and the CEO can have a new private repository made for a Coder.

At a glance#

CategorySource control
StatusAvailable
Used byCoder (available now), Product owner (Coming soon)
Connect inThe StellarFirm desktop app, under Integrations
What you pasteOne personal access token
Works withgithub.com repositories, personal or in an organization

What assistants can do#

Each step needs a permission on the token. The table shows which one, so you can give exactly what you want and no more.

AbilityHow it runsFine-grained token permissionClassic token scope
Read repositories, issues, and pull requestsReads on its ownMetadata: Read, Issues: Read, Pull requests: Readrepo
Read the changed files of a pull requestReads on its ownPull requests: Readrepo
Read check resultsReads on its ownCommit statuses: Read (see the note below)repo
Copy the repository into its workspaceReads on its ownContents: Readrepo
Open an issueWaits for your ApproveIssues: Read and writerepo
Push a branch with its workWaits for your ApproveContents: Read and writerepo
Push a change to a workflow fileWaits for your ApproveWorkflows: Read and writeworkflow
Open a pull request, a draft by defaultWaits for your ApprovePull requests: Read and writerepo
Merge a pull requestOnly as your merge policy allowsContents: Read and writerepo
Create a private repositoryWaits for your ApproveAdministration: Read and write, with All repositoriesrepo

Pick a token#

Fine-grained tokenClassic token
Best forThe narrowest access: chosen repositories, chosen permissionsEverything working first time, check runs included
Starts withgithub_pat_ghp_
Limited toThe repositories you pick, under one account or organizationEvery repository your account can reach
Reads check runsNo, commit statuses onlyYes
OrganizationsThe organization may need to approve it firstAuthorize it for single sign-on if your organization uses it

If you are unsure, start with a fine-grained token limited to one test repository. You can widen it later.

Create a fine-grained token#

  1. On GitHub, open your profile picture, then Settings, Developer settings, Personal access tokens, Fine-grained tokens.
  2. Choose Generate new token.
  3. Token name: something you will recognise later, such as "StellarFirm Coder".
  4. Expiration: pick a date. When the token expires, the Coder stops as Blocked and asks you for a new one.
  5. Resource owner: your own account, or the organization that owns the repositories.
  6. Repository access: choose Only select repositories and pick the ones the Coder may use. Choose All repositories only if you want the CEO to create new repositories.
  7. Under Repository permissions, set:
    • Contents: Read and write
    • Pull requests: Read and write
    • Issues: Read and write
    • Commit statuses: Read-only
    • Metadata: Read-only (GitHub sets this for you)
    • Workflows: Read and write, only if the Coder may change files in .github/workflows
    • Administration: Read and write, only if the CEO may create repositories
  8. Choose Generate token and copy it. GitHub shows it once.
  9. If the resource owner is an organization that reviews tokens, an owner approves it under the organization's Settings, Personal access tokens, Pending requests. Until then the token cannot see those repositories.

Create a classic token#

  1. On GitHub, open your profile picture, then Settings, Developer settings, Personal access tokens, Tokens (classic).
  2. Choose Generate new token, then Generate new token (classic).
  3. Add a Note, such as "StellarFirm Coder", and pick an Expiration.
  4. Tick repo. Tick workflow too if the Coder may change files in .github/workflows.
  5. Choose Generate token and copy it. GitHub shows it once.
  6. If your organization uses single sign-on, choose Configure SSO next to the token in the list and Authorize it for that organization.

Connect it in StellarFirm#

  1. Open the StellarFirm desktop app and sign in.
  2. Open Integrations and pick GitHub.
  3. Paste the token into Personal access token.
  4. Leave Use live GitHub on and press Connect.
  5. The card shows Connected. Your token is saved on your computer by the desktop app, never shown back to you, and handed to one git command at a time. It is never written into the repository's settings.

Tell the Coder where to work#

The Coder needs a repository, written as owner/repository. Give it one of two ways.

  • In your message. Name it, or paste its link: "Coder, in acme/web, fix the login redirect."
  • For good, per Coder. Open Settings, Coders, edit the Coder, and under Repository and login choose GitHub as source control and fill in Repository. A message that names that repository then goes to that Coder. See several Coders.

Each Coder can also act as its own GitHub account. Under Repository and login, choose Its own login and paste a token for that account, for example a machine account that only has access to one repository. Its pull requests then show that account instead of yours. The token needs the same permissions as above.

Let the CEO create a repository#

You can ask for a new repository in chat. The Coder creates it after you Approve. It is always private, starts with a README so it has a main branch, and becomes that Coder's repository for the rest of the run.

What the token needs:

  • A classic token with repo, or a fine-grained token with Administration: Read and write and All repositories. A token limited to selected repositories cannot see one that does not exist yet.
  • For a repository in an organization, your account must be allowed to create repositories there, and a fine-grained token must have that organization as its resource owner.

Where it goes: the owner you name ("in the acme org"), otherwise the owner of the Coder's current repository, otherwise your own account. To keep using it after you restart the app, set it as the Coder's repository under Settings, Coders.

Creating repositories is a GitHub feature. On GitLab and Bitbucket, create the project yourself and give it to the Coder.

Good to know#

  • Pushing and merging follow your house rules. The Coder pushes to a new branch of its own, never to your default branch, and never force pushes. Pushing waits for your Approve. Merging follows your merge policy: review only by default, and never while checks are failing or still running. Your branch protection on GitHub still applies.
  • Drafts and your GitHub plan. GitHub allows draft pull requests on private repositories only on its Team and Enterprise plans. On a personal account or a free organization, the Coder opens a regular pull request instead and tells you so. It still waits for your review.
  • Drafts cannot be merged. Before you ask the Coder to merge, open the pull request on GitHub and choose Ready for review.
  • If the clone fails, the job stops as Blocked before any coding and says what to fix, usually that the token cannot read that repository.
  • Several code hosts connected? A link or the host's name in your message picks the host. Otherwise the Coder uses the one that has a repository set.
  • GitHub Enterprise Server is not connected from the app. Ask support if you need it.
  • Revoke at any time. Delete the token on GitHub and the Coder loses access straight away. Then choose Turn off on the GitHub card.

Troubleshooting#

What you seeWhat it meansWhat to do
Blocked: the Coder cannot clone the repositoryThe token cannot see itAdd the repository to the fine-grained token, approve the token in the organization, or authorize the classic token for single sign-on
Bad credentialsThe token expired or was deletedCreate a new token and paste it on the GitHub card
Resource not accessible by personal access tokenA permission is missingCheck the table above for the step that failed and add that permission
The push is refused on a workflow fileWorkflow files need their own permissionAdd Workflows: Read and write, or the workflow scope
No checks show, but GitHub shows themFine-grained tokens cannot read check runsUse a classic token with repo
The merge is refused as a draftThe pull request is still a draftChoose Ready for review on GitHub, then ask again
Creating a repository is refusedThe token cannot create repositories thereGive it Administration: Read and write with All repositories, or use a classic token

Prompts#

PromptPick up a ticket

Coder, GitHub is connected. Pick up the top open issue on [owner]/[repository], implement it, and open a pull request for review once I Approve.

PromptReview an open pull request

Coder, read pull request [number] on [owner]/[repository], check its tests, and tell me what you would change before I merge it.

PromptTriage issues

Coder, list the open issues on [owner]/[repository], group them by area, and tell me which one to do first.

PromptFix a failing check

Coder, the checks on [owner]/[repository] are failing on main. Find the cause, fix it with the smallest change, and open a pull request for review.

PromptCreate a repository

Coder, create a new private repository called [name] in the [organization] org for [what it is for]. Then add a README that explains the plan.

Next#