Overview
Connect GitHub to nOps with a personal access token and your organization slug (and optionally an enterprise slug if you report at enterprise level). We validate the token before saving it, store it securely, and never show it again in the UI. We recommend a fine-grained PAT owned by your organization: you can grant read-only org and repository permissions instead of the broad classic scopes. If you need enterprise billing or consumed licenses, use a classic PAT for that part. GitHub does not support those endpoints on fine-grained tokens. This card is your cost and usage integration. It is separate from GitHub Issues in Clara’s recommendation workflow (that flow uses WorkOS Pipes and a repository destination). Connecting here does not turn on issue creation. After you connect, nOps can ingest:- Cost and usage: metered spend by product, SKU, repository, and day (Actions, Codespaces, Packages, storage, Copilot, GHAS, and more).
- Copilot attribution: premium requests and AI credits by user and model, plus Copilot seat assignments when your token allows it.
- Members and seats: your organization member roster and paid seat counts.
- Engineering activity: read-only metadata from pull requests, commits, and Actions runs to enrich anomaly context (no source code or file contents).
Only nOps admins and owners can connect, re-validate, or disconnect. Members see Admin Only on the integration card.
Who can create the token?
The person who creates the token needs the right role in GitHub:
Your org or enterprise should use GitHub’s enhanced billing platform (required for the billing usage APIs nOps calls). You also need nOps Settings → Integrations admin access to connect the card.
Choose your token type
The connect modal asks you to pick Fine-grained PAT (recommended) or Classic PAT. The permission checklist in the modal matches the lists below.Fine-grained PAT (recommended)
Create the token with Resource owner = your organization (not your personal account). Grant read-only permissions. nOps only sends GET requests. Organization permissions- Administration: read: organization billing usage, premium requests, AI credits
- Members: read: member roster
- GitHub Copilot Business: read: Copilot seats (optional, if you use Copilot)
- Organization Copilot metrics: read: Copilot usage metrics (optional)
- Metadata: read: repository list (included automatically)
- Pull requests: read: PR metadata for activity context
- Contents: read: commit metadata on the default branch (not file contents)
- Actions: read: workflow run metadata
Classic PAT
Use a classic token when you need enterprise billing, when fine-grained org billing is unavailable for your org, or when you prefer the older scope model. Scopes to selectadmin:org: required for organization billing (read:organdwrite:orgare not enough; GitHub often returns “not found” instead of “forbidden” when billing scope is missing)manage_billing:copilot: Copilot seats (optional)read:enterprise: required if you enter an Enterprise slug (enterprise billing and consumed licenses)repo: private repository activity (optional for activity data; includes write. Prefer fine-grained for read-only repo access)
Create the token in GitHub
Fine-grained
- Sign in to GitHub as an org owner or billing manager.
- Go to Settings → Developer settings → Personal access tokens → Fine-grained tokens.
- Click Generate new token, set Resource owner to your organization, and choose All repositories (or the repos you need).
- Add the organization and repository permissions from the list above.
- Set an expiration, generate the token, and copy it. GitHub shows it once.
Classic
- Sign in as an org owner, billing manager, or enterprise admin (as needed).
- Go to Settings → Developer settings → Personal access tokens → Tokens (classic).
- Click Generate new token (classic), add a note (for example
nOps Inform), and set an expiration. - Select the scopes from the classic list above.
- Generate and copy the token immediately.
Connect in nOps
Where to open GitHub
- First-time connect: Settings → Integrations, then the GitHub card.
- Manage an existing connection: Settings → Account Status → Connected apps, then the GitHub chip.
Connect steps
- Open the GitHub modal.
- Choose Token type (fine-grained or classic).
- Paste your token (
github_pat_…orghp_…). nOps detects the prefix if it does not match your selection and shows a clear error. - Enter your Organization slug (the URL segment from
github.com/your-org, not the display name). - Optionally enter an Enterprise slug (classic PAT only).
- Click Connect.
Manage your connection
From the same modal, admins can Re-validate (check the stored token still works), Update (new token or slugs), or Disconnect. Rotate tokens in GitHub before they expire, then update the connection in nOps.Troubleshooting
- Invalid token: Confirm the token owner has a billing or admin role and the token has not expired.
- Fine-grained + enterprise slug: Remove the enterprise slug or switch to a classic PAT with
read:enterprise. - Token type mismatch: If you chose Classic but pasted
github_pat_…, switch the dropdown to Fine-grained (or paste aghp_…classic token). - Organization not found / validation fails: Double-check the slug from the URL. For classic org billing, add
admin:org. For fine-grained, grant Administration: read on a token whose resource owner is the org. The token owner must still be an org owner or billing manager. - No enterprise data: Use a classic PAT with
read:enterpriseand an enterprise billing role. - No Copilot or member data: Add Copilot or Members permissions (fine-grained) or
manage_billing:copilot/ member-related classic access. Missing optional permissions skip those datasets but do not block core cost and usage. - No billing data: Your org may not be on the enhanced billing platform yet; check GitHub billing settings.
- No data in Inform yet: Allow up to 24 hours after the first successful connect for the initial sync.