GitHub in the catalog

Install GitHub once. Repos, pulls, and reviews become Orkestia workflows, the same engine as deploy and runners.

Orkestia2 min readUpdated

Orkestia is the backbone that connects software, AI, and the real world. GitHub is a connection on that backbone, not a sidecar. Install it once. Repos, webhooks, pulls, and the path from repository to live all use it.

SPAD publishes a site from a repo on your cloud. Runners are GitHub Actions runners provisioned in your account. Agents read code context through the same connection. Hook can take signed GitHub events. One credential, several products.

How you authenticate

Two modes:

  • GitHub App installation, org-level, the one to use when an org owns the repos.
  • PAT, classic or fine-grained, the fastest way to try it.

There is no OAuth mode on this connection. Pick App or PAT in the console after you create an account.

The token stays on the connection. An agent that comments on a pull or triggers a workflow does not hold a PAT in the chat.

What it is for

  • Read repos and contents the products need
  • Subscribe to push, pull request, release, and workflow_job events
  • Drive the Git-backed path used by SPAD and Deploy
  • Let an AI client open or comment on a pull as a workflow, with a history

Live types sit in the catalog. Filter by GitHub, by SPAD, by runner. Dedicated apps: runners.orkestia.dev for runners, the catalog for SPAD.

From MCP

whoami()
list_workflow_types(q="github")
get_workflow_schema("<type>")
start_workflow(workflow_type="<type>", initial_data={...})

If has_prerequisites is true, finish the GitHub connection before you start. Read-only types are the right first run.

Cursor and Codex are the clients that usually sit next to the repo: Orkestia for Cursor, Orkestia for Codex.

App versus PAT

Use the GitHub App when an organization owns the repos. The install is revocable without rotating a person's PAT, and it does not inherit that person's unrelated access. Use a PAT when you are trying the platform on a personal repo and you want to be done in ten minutes. Move to the App before you point Runners or SPAD at an org you care about.

Webhooks for push, pull request, release, and workflow_job belong on this connection as well. Hook can receive them as a signed URL if you need a generic inbound path. The GitHub connection is still the one SPAD and Runners expect.

A first afternoon: connect, list a read-only repo type, start it, read the payload. Then open runners.orkestia.dev or SPAD from the catalog and follow those prerequisites. They will ask for this same GitHub connection.

hello@orkestia.dev

  • github
  • connections