Connect GitHub
Argus scans a GitHub organization or user read-only with a personal access token, an OAuth token, or a GitHub App. Nothing is installed beyond the credential you choose, and Argus only ever reads.
Before you start
- A read-only credential for the org or user: a personal access token, an OAuth token, or a GitHub App installed on the org.
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
Choose one credential:
- Personal access token (recommended): create a token with read-only access to the org or user.
- OAuth token: use an OAuth app token with read-only access.
- GitHub App: install a GitHub App on the org and note its numeric App ID and its private key (a PEM block).
Required permissions
For a fine-grained personal access token, grant read-only access:
- Repository: Administration (read), Contents (read), Metadata (read, auto-selected), Dependabot alerts (read)
- Organization: Administration (read), Members (read)
- Account: Email addresses (read, optional)
An OAuth token uses the broader repo, read:org and read:user scopes. A
GitHub App uses the same read-only permission set as the fine-grained token.
Connect in Argus
Go to Accounts and click Connect account. Pick GitHub, then the recommended Personal access token method. Enter:
| Field | Value |
|---|---|
| Organization / user | the org or user to scan |
| Personal access token | the read-only token |
Other methods
- OAuth token: takes an OAuth app token.
- GitHub App: takes the numeric App ID and the App private key (PEM).
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the credential and use Test connection on the account card to retry.