Skip to content

4 min read

Connecting GitHub

What gets linked, what gets stored, and what a merge is allowed to do.

Installed, not authorised

Vorkhurry connects as a GitHub App that you install on specific repositories, rather than as an OAuth app holding a user's token or a personal access token holding everything.

The only thing stored is the installation id. Every call to GitHub mints a fresh installation token from that id and the app's private key, and it expires in an hour — there is no long-lived credential to leak.

How work gets linked

Issue keys are extracted from branch names, commit messages and pull-request text, then intersected with the project keys that belong to your organization. A key from someone else's numbering scheme does not match yours by accident.

Each match becomes an activity row on that issue. Webhook deliveries are signature-verified and recorded once, so a redelivery is acknowledged rather than applied twice.

Letting a merge move the issue

You can map a pull-request event to a status — opened to In Review, merged to Done. Nothing about that mapping is built in; it is your configuration.

The move runs through the same transition guards a person would hit. A transition your workflow forbids is skipped and logged, never forced.

All guides

Start with your team, not with a sales call

Create a workspace, invite the people you work with, and bring your existing issues in from Jira, Linear or a CSV.