ArxDeck
Integrations

GitHub

Connect repositories, browse docs, manage PRs on tickets, and maintain the connection.

GitHub integration

Per-project GitHub settings link a repository to tickets, agents, documentation browse, MCP tools, skill injection, and optional CI-gated PR merge automations.

Why connect a repo

With a linked repository:

  • Cursor Cloud agents start from a configured base ref and sync branches and pull requests to tickets
  • MCP list_docs, get_docs, and create_pr operate on repo contents
  • The dashboard Docs page renders markdown from the configured docs root
  • Publish validates and deploys from the agent starting ref (not the docs branch)
  • Project skills can be injected into .claude/skills/ on the agent starting ref

Authentication model

ArxDeck uses a GitHub App with project-scoped repository bindings.

Binding modeWhen it appliesWhat you do
Platform-managedRepository created via Create repository under the operator GitHub orgNothing after create
Customer-managedYour own GitHub repositoryConnect repository wizard with repo owner or admin access

An ArxDeck organization can link multiple projects to different repositories. Each project has at most one active binding.

Short-lived installation tokens (~1 hour) power server API calls. Automated git operations appear as arxdeck[bot]. Fresh Cursor Cloud agent creates receive envVars.GITHUB_TOKEN with the same minted token.

Setup & configuration

Project

Project admins open Settings → GitHub:

  1. Use Connect repository and paste a repository URL (https://github.com/{owner}/{repo}), or use Create repository when the platform GitHub App is configured for managed repos.
  2. Complete GitHub user OAuth. You must be the repository owner (personal repos) or have admin access (collaborators) or be an organization owner/admin (org repos). Personal repo owners are not listed as collaborators on GitHub — that is expected.
  3. If the ArxDeck GitHub App is not yet installed on the repository owner account, you are redirected to install it first (even when you own the repo — GitHub App user tokens cannot read private repos until the app is installed). After install and granting repository access, connect runs a scoped post-install OAuth pass. If your user token still cannot read the repository (common with GitHub App ghu_ tokens), ArxDeck completes binding using app credentials when the installation covers the repo, then confirms the repository appears in your installation repository list.
  4. Configure Docs branch (default main), docs root (default docs/), and default entry file (default PROJECT.md).
  5. Set Agent starting ref — branch or commit used when agents start work and when skills are injected (may differ from the docs branch).
  6. Optionally enable Force PR base to agent starting ref so MCP create_pr always targets that ref.
  7. Optionally enable CI before merge for automation merge actions — pick a workflow_dispatch workflow on the repo default branch and click Validate workflow.

After connect, the page shows inline status for callback results (for example success, insufficient permission, repository not found, or temporary GitHub API errors).

Use Collaborators on the same page to add or remove direct collaborators and pending invitations. Suggested logins come from project members who saved a GitHub username in account settings.

Connection maintenance

When a binding needs attention, the GitHub settings page shows actionable status:

  • Check connection — verify the installation token and repository access
  • Reauthenticate — refresh OAuth when permissions or tokens expire
  • Disconnect — remove the project binding (does not delete the GitHub repository)

GitHub settings revisions (update_settings, set_ci_workflow) appear in History with diffs and restore. Binding and OAuth operations themselves are not revision-tracked — see Configuration revision history.

ArxDeck Helper can propose GitHub settings changes (including connect and reauthenticate flows that redirect through OAuth). Approve proposals in Project → Proposals.

Connect callback messages

CodeMeaningAction
connectedBinding succeededContinue configuring docs and CI settings
insufficient_permissionSigned-in GitHub user lacks owner/admin rightsSign in with the repo owner or an admin account
repo_not_foundRepository missing or not visible to the OAuth accountCheck the URL and GitHub account
installation_not_foundApp not installed on repository ownerComplete GitHub App install during connect
installation_repo_access_requiredApp installed but repo not in installation scopeGrant repository access in GitHub app settings
user_installation_access_requiredRepository not in your installation list or app not authorized for your accountRe-authorize during connect; grant repository access in GitHub app settings
github_api_errorTemporary GitHub API failureRetry connect in a few minutes

Pull requests on tickets

Pull requests appear on ticket detail from agent run sync and MCP create_pr. Members with ticket edit access can open PRs in GitHub and merge open PRs from the ticket page (manual merge is not CI-gated; automation merge may be).

Technical details

TopicDetail
AuthenticationGitHub App installation tokens (~1 hour); project-scoped bindings
AttributionServer and Cursor agent git operations as arxdeck[bot]
Cursor CloudFresh agent create receives envVars.GITHUB_TOKEN with minted installation token
Repo createPlatform-managed repos under the operator GitHub org
Docs pathsBrowse and MCP accept docs-root-relative or repo-relative paths under the configured docs root
PR base branchMCP create_pr defaults to Agent starting ref; invalid refs fall back to the repository default branch
Live readsGitHub REST API — no cached doc tree in v1
CI before mergeOne workflow_dispatch workflow per project; webhook-triggered reconciliation when the platform GitHub App webhook is configured, with automation-worker polling as fallback
Auto-deploy (Publish)Uses the platform GitHub App push webhook; no extra GitHub permissions beyond repository access

Platform operators configure the GitHub App and deployment secrets — that is not part of the tenant dashboard.