Title: Connect GitHub · Codemany docs
URL: https://codemany.com/docs/get-started/github
Description: Connect Codemany to GitHub by signing in, with your GitHub CLI login, or with a token; which permissions repository and organization runners need, and where the token is kept.
All pages as Markdown: https://codemany.com/llms.txt

---

[Get started](https://codemany.com/docs#get-started)

# Connect GitHub

Codemany registers runners on your repositories with your GitHub account. You connect it once, on the machine that runs the jobs, and the token stays on that machine.

## Who can connect

A GitHub account that can add self-hosted runners to the repository or organization: a repo admin, or an org owner for an organization.

## Three ways to connect

### Sign in with GitHub

Setup shows a code; enter it on github.com. Codemany asks for the `repo`, `read:org` and `user:email` scopes. Runners for a whole organization also need `admin:org`: when you pick an organization without it, setup asks you to re-authorize.

### Your GitHub CLI login

If `gh` is signed in, setup offers to use that account. On the command line:

```
codemany setup --target your-org/your-repo --token-from-gh
```

For organization runners, add the scope first: `gh auth refresh -s admin:org`.

### A token

Paste a token instead (**Paste a token instead** in setup, or `codemany setup --token-stdin`). A [fine-grained personal access token](https://github.com/settings/personal-access-tokens/new) is the narrowest choice:

- Limit it to the repositories Codemany serves.
- Give it **Administration: read and write** for repository runners, or **Self-hosted runners** for an organization.
- Give it an expiry date.

## Where the token is kept

- **macOS:** in Codemany's Keychain vault (`com.codemany.vault`), whose access list trusts only Codemany.app and its bundled daemon.
- **Linux:** in a vault file readable only by you (mode 0600), or in the desktop keyring with `codemany vault keyring` (locked until you log in, so not for machines nobody logs in to).

API calls to GitHub are made directly from your machine with your token. It is never sent to Codemany's servers. See [Privacy](https://codemany.com/privacy).

## Public repositories

Codemany refuses a public repository unless you opt in for that repo, because anyone can open a pull request from a fork. It re-checks every 30 minutes, since a repo can be made public later. See the [security model](https://codemany.com/docs/security#public-repos).

## If the token stops working

If the token is revoked, running jobs keep running and new runners retry every 5 minutes; reconnect GitHub and the next retry picks up the new token.

## Disconnect

On GitHub, remove "Codemany" under Settings › Applications, or delete the token you gave it. Delete any offline runners left under the repo's Settings › Actions › Runners.

[Previous Install on Linux](https://codemany.com/docs/get-started/linux)[Next Your first runner](https://codemany.com/docs/get-started/first-runner)
