Skip to main content
Scaling reaches your code through a GitHub App that you install on the repositories you choose. Nothing is pasted: there is no access token to create, copy or rotate. A connected repository is a project, and a project is what a session works on.

What you need

  • An account that is signed in, with an active organisation (Quickstart).
  • The admin role in that organisation, for every step that changes something. A member can read what is connected and nothing else on this page.
  • To be the GitHub account that owns the repository, or an owner of the GitHub organisation that does. Being a member of the organisation, or a collaborator on one of its repositories, is not enough.

What the app can do

The app asks GitHub for four permissions and no others. It does not ask for the workflow permission, so it cannot change your CI files even if a session asked it to. You choose which repositories it can see when you install it, and you can change that on GitHub at any time.

Start the installation

Response
Open installUrl in a browser and choose the repositories. state is what ties the installation you are about to make to your organisation. It works once, for the person who asked for it, until expiresAt, which is ten minutes away.

Finish the installation

GitHub asks you to authorise the App while you install it, and then sends you back with an installation_id, a code and the same state. Hand all three over, signed in as the same person who started.
Response
The organisation the installation is linked to is the one you are signed in to. There is no parameter for it, and an installation_id on its own links nothing.
The code is how GitHub tells us who made the installation. It is exchanged once to ask GitHub who you are, and nothing from that exchange is kept. It works once and expires quickly, so finish soon after GitHub sends you back. An installation is linked only by the GitHub account it belongs to. For an installation on a personal account, that is the account itself. For an installation on a GitHub organisation, it is an owner of that organisation, the role GitHub’s API calls admin. Being a member of the organisation, or a collaborator on one of its repositories, is not enough. If you are neither, nothing is linked and the answer is 404 with the code not_found. That is the same answer as for an installation that does not exist. Either way the state and the code are both used up, so start the installation again. If GitHub does not accept the code, because it has expired or was already used, the answer is 400. Start the installation again.

Choose a repository

List what the installation can see.
Response
projectId is null until the repository is connected. Connect it with the two ids.
Response
Connecting a repository that is already connected answers with the project that exists. A repository is one project however many times somebody clicks.

See what is connected

Any member of the organisation can read both lists.
An installation’s status is active, suspended or removed. A project’s disabled is null while it can be used. Otherwise it says when access was lost and why: installation_removed, installation_suspended or repository_removed. A disabled project keeps its history, and no new work can read or publish its code. Giving the app access to the repository again on GitHub, or connecting it again here, brings it back.

Remove the installation

This uninstalls the app from the GitHub account and disables every project that was connected through it. Uninstalling it on GitHub yourself has the same effect.

When it fails

An invalid_request on the finish step is fixed by starting again, which takes one request. Branch on code, never on message.