Choose a GitHub credential

Decide between GitHub App installation authority and GitHub user OAuth for your agent workload.

Constal provides both GitHub authorization modes to every tenant. Use the Constal-managed provider immediately, or install the bring-your-own package when the GitHub App must carry your product's identity and permission policy.

Comparison

QuestionGitHub App installationGitHub user OAuth
Who acts?The installed GitHub AppA specific GitHub user through the App
Best forBackground agents and automationUser-attributed actions
External authoritySelected repositories and App permissionsIntersection of App permissions and user access
Constal scopeTenant or customerPrincipal, sometimes customer
Platform-managed setupInstall the Constal GitHub AppAuthorize the Constal GitHub App
Bring-your-own setupApp private keyApp client secret
Output materialShort-lived installation tokenUser access token plus private refresh state
Browser authorizationInstallation and repository selectionUser consent

Use installation authority when

  • the agent must continue when a user leaves;
  • an organization selects repositories during App installation;
  • operations should be attributed to the App;
  • one Credential should represent one customer installation.

Continue with GitHub App installation credentials.

Use user OAuth when

  • GitHub activity must be attributable to a person;
  • effective authority must be constrained by that person's access;
  • each user explicitly consents;
  • a principal-scoped binding selects the user's grant.

Continue with GitHub user OAuth credentials.

Platform-managed and bring-your-own

The Constal-managed installation and OAuth providers are shared platform Resources. Their application secrets are not copied into tenants. Each resulting Credential and scoped binding remains owned by the tenant, customer, or principal that authorized it.

Bring your own GitHub App when downstream customers should see your product's name, permissions, callback, and installation experience. One tenant-owned GitHub App can support both installation credentials and user OAuth credentials; configure its provider instances once, then create one output Credential per installation or user grant.

Channel sign-in is separate

These CredentialProviders give agents outbound GitHub authority. They do not restrict who may invoke a Channel. A GitHub organization AuthProvider would authenticate the caller, verify organization membership, return identity evidence, and let Policy gate channel:receive and agent:invoke.

The authenticated principal or customer can then drive the scoped binding that selects one of these outbound Credentials.