GitHub connector
Read repository files, create review branches, write content, and open draft pull requests with explicit authorization.
import { github } from '@noir-agent/agent/connectors/github'
const repository = 'owner/repo'
const connector = github({
repository,
token: process.env.GITHUB_TOKEN!,
branch: 'main',
branchPrefix: 'noir/',
verifyRepositoryAuthorization(request) {
return isAllowed(request)
? { authorized: true, authorizationId: 'grant-2026-08' }
: { authorized: false }
},
})Tools and client
The connector exposes repository tools for reading and listing files, creating branches, writing text or current-message attachments, and opening draft pull requests. Host code can also use connector.client methods: readFile, writeFile, writeBytes, createBranch, createDraftPullRequest, and paginated listFiles.
Authorization
Routine writes require an authorization verifier. The callback receives:
- repository
- installation ID
- actor ID
- operation
- target branch
Return an authorization ID that can be recorded with the write result. The old repositoryAccess: 'user-owned' option does not establish ownership and is deprecated.
Branch safety
Configure a base branch and review branch prefix. Deny writes to the base branch in the authorization verifier. The connector opens draft pull requests; it does not provide merge or release tools as a routine authoring operation.
Images and attachments
imageArtifacts can bind an agent-owned image artifact store. Attachment writes resolve an opaque reference already associated with the current verified message. This avoids server-side request forgery through a model-provided URL.
Pagination and bounds
Repository trees can be large. Use prefix, suffix, after, and limit; follow nextCursor. A truncated provider tree is surfaced rather than silently presented as complete. Read representative files for voice matching instead of loading an entire content repository into one prompt.
Use a fine-grained token or GitHub App installation limited to the target repository and contents/pull-request permissions needed by the workflow.