neosourceDocs
Search docs

Get a repository's GitHub App binding

GET/api/repos/{owner}/{repo}/github-installation

getGithubInstallation

The repository's App binding: which installation it runs under, which GitHub repository id it is pinned to, and the last health probe's verdict. `404` when the repository has no binding, and when this deployment has no GitHub App configured. No token ever appears here — `token_expires_at` is a timestamp, and installation tokens are never stored.

Authentication optional — this operation also accepts anonymous requests. When authenticating, use a bearer token or a session cookie.

curl

curl -X GET 'https://neosource.dev/api/repos/OWNER/REPO/github-installation' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/github-installation", {
  method: "GET",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
  },
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

Responses

200The repository's binding

application/json

GithubAppBindingResponse

object

A repository's App binding.

app_installation_idrequired

GithubInstallationId

integerint64

GitHub's App installation id (`installation.id` on every App webhook). Nothing is rejected at the type level; the `> 0` invariant is a database CHECK, because the only values that reach here come from GitHub.

created_atrequired

integerint64

Epoch milliseconds.

github_repository_idrequired

GithubRepositoryId

integerint64

GitHub's immutable numeric repository id (`repository.id`). Distinct from [`GithubInstallationId`] on purpose: both are `bigint`, and a swapped argument would otherwise type-check and bind the wrong repository.

healthrequired

GithubAppBindingHealth

string

Health of a repo's App binding (`github_app_bindings.health`). Mirrors the Phase 0a CHECK exactly; a new variant needs a migration.

"unverified""healthy""insufficient_scope""ruleset_unverified""revoked""error"

last_health_checked_at

integer | nullint64

Epoch milliseconds of the last health probe.

token_expires_at

integer | nullint64

Epoch milliseconds at which the last installation token minted for this binding expires. The token itself is never stored or returned.

updated_atrequired

integerint64

Epoch milliseconds.

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget