Connect GitHub with a token or an App
This guide connects GitHub, which gives Casebox pull requests, reviews, checks, reverts and, if you want them, issues. Choose a token for a trial and an App for an organisation.
| Fine-grained token | GitHub App | |
|---|---|---|
| Updates | A poll every 5 minutes | Webhooks, and the poll as a safety net |
| Who creates it | Any member with access to the repositories | An organisation owner |
| Comments and proposals | As the token’s owner | As the App |
Both need: metadata and contents (read), issues (read), checks (read), and pull requests (read and write). Proposals push a branch, so they also need contents write.
A token
Section titled “A token”export CASEBOX_GITHUB_TOKEN=<fine-grained token>casebox initThe server checks the token before it stores it (CBX071 when GitHub refuses it). Add --github-issues to track GitHub Issues as work items.
An App
Section titled “An App”-
Create a GitHub App with the permissions above and these webhook events: pull request, pull request review, pull request review comment, check run, workflow run, push and issues. Set the webhook URL to
https://<your server>/webhooks/githuband choose a webhook secret. -
Install the App on the repositories, and note the App ID and the installation ID.
-
As an Admin, connect it:
Terminal window casebox api PUT /api/v1/integrations/github --data '{"mode":"app","appId":123,"installationId":456,"privateKey":"<PEM>","webhookSecret":"<secret>"}'
The server checks each delivery’s signature before QueueBox stores it, and QueueBox stores a redelivered webhook once.