What the connection keeps
The installation record stores the installation id, the GitHub account id, the account login, the account type, the repository selection, and the status. That is enough to mint a token later. It is not itself a token. The App id, the App private key, and the webhook secret stay in control-plane configuration. They are not stored on the installation row.A token exists for one build
When a build starts, Springwinter mints an installation access token and passes it to CodeBuild in your account so git can clone over HTTPS. The token is not written to the application database. When the build is over, Springwinter does not have a copy to reuse. The next build mints another token. A public image deploy does not use GitHub. Create accepts a public image reference with a tag or a digest, and it rejects a registry password. Fargate pulls that image in your account.Webhooks
GitHub sends installation and push events toPOST /api/github/webhook. The request is not a browser session. Springwinter computes HMAC-SHA256 over the raw body with the webhook secret and compares it to X-Hub-Signature-256. A request whose signature does not match is rejected.
The install redirect uses a state value compared in constant time, so a callback has to match the sign-in that started it.