This guide explains how to set up a GitHub App for Oracode to enable organization-level repository access.
- GitHub account with organization admin access
- Convex deployment set up
- Environment variables access in Convex dashboard
-
Go to GitHub Settings → Developer settings → GitHub Apps → New GitHub App
-
Basic Information:
- Name:
Oracode(or your preferred name) - Homepage URL: Your app URL (e.g.,
https://oracode.dev) - Description: Brief description of your app
- Name:
-
Callback URL:
- Setup URL:
https://<your-deployment>.convex.site/github/callback - Example:
https://happy-animal-123.convex.site/github/callback
- Setup URL:
-
Webhook:
- Webhook URL:
https://<your-deployment>.convex.site/github/webhook - Webhook Secret: Generate a random secret (save this for later)
- Example secret generation:
openssl rand -hex 32
- Webhook URL:
-
Permissions:
Repository permissions:
- Contents: Read & write
- Metadata: Read-only
- Pull requests: Read & write (if needed)
Organization permissions:
- Members: Read-only
-
Subscribe to events:
- Installation
- Installation repositories
-
Where can this GitHub App be installed?
- Select "Any account" for public app
- Or "Only on this account" for private testing
-
Click Create GitHub App
- After creating the app, scroll to "Private keys" section
- Click Generate a private key
- Download the
.pemfile - save this securely - You'll need to add this to Convex environment variables
From the GitHub App settings page, note:
- App ID (shown at top of settings page)
- App Slug (in the URL:
https://github.com/apps/<app-slug>) - Webhook Secret (the one you generated)
- Private Key (the
.pemfile contents)
-
Go to your Convex Dashboard → Settings → Environment Variables
-
Add the following variables:
GITHUB_APP_ID=<your-app-id>
GITHUB_APP_SLUG=<your-app-slug>
GITHUB_WEBHOOK_SECRET=<your-webhook-secret>
GITHUB_APP_PRIVATE_KEY=<paste-entire-pem-file-contents>Important for Private Key:
- Copy the entire contents of the
.pemfile - Include the
-----BEGIN RSA PRIVATE KEY-----and-----END RSA PRIVATE KEY-----lines - Paste as-is into Convex (newlines will be preserved)
Add to your .env or .env.local:
VITE_GITHUB_APP_SLUG=<your-app-slug>
SITE_URL=http://localhost:5173 # or your production URLDeploy your Convex functions to activate the HTTP endpoints:
cd packages/convex
pnpm deploy- Start your Vite app:
pnpm dev - Sign in with a new user (or one without an organization)
- You should be redirected to
/install-github-app - Click "Install GitHub App"
- You'll be redirected to GitHub to select an organization
- After installation, you'll be redirected back to your app
After setup, verify:
-
Webhook deliveries: Check GitHub App settings → Advanced → Recent Deliveries
- Should see
installationevent with 200 response
- Should see
-
Convex database: Check
githubInstallationstable- Should have entry with your installation details
-
Installation tokens: Test generating a token:
// In your app const token = await getInstallationToken({ clerkOrgId: org.id });
- Check
GITHUB_WEBHOOK_SECRETmatches what you set in GitHub - Ensure secret is the same in both places
- Check Convex logs for errors
- Verify
GITHUB_APP_IDandGITHUB_APP_PRIVATE_KEYare set correctly
- Ensure newlines are preserved (use
\nin env vars if needed) - Check the key includes BEGIN/END markers
- Verify
VITE_GITHUB_APP_SLUGis set correctly - Check Convex HTTP action logs
- Never commit private keys or secrets to version control
- Rotate webhook secrets periodically
- Use separate GitHub Apps for dev/staging/production
- Limit repository access permissions to minimum required
- Monitor webhook deliveries for suspicious activity
- GitHub App created with correct permissions
- Webhook secret generated and configured
- Private key downloaded and stored securely
- All environment variables set in Convex
- Convex functions deployed
- Vite app environment variables configured
- Installation flow tested end-to-end
- Webhook deliveries verified (200 responses)
- Database entries confirmed