> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHub

> How the GitHub App installation, build tokens, and webhook signatures work.

GitHub access is a GitHub App installation on an account you choose. Springwinter does not ask for a personal access token, and it does not store the token used to clone.

## What the connection keeps

The installation record stores the installation id, the GitHub account id, the account login, the account type, the repository selection, and the status. That is enough to mint a token later. It is not itself a token.

The App id, the App private key, and the webhook secret stay in control-plane configuration. They are not stored on the installation row.

## A token exists for one build

When a build starts, Springwinter mints an installation access token and passes it to CodeBuild in your account so git can clone over HTTPS. The token is not written to the application database. When the build is over, Springwinter does not have a copy to reuse. The next build mints another token.

A public image deploy does not use GitHub. Create accepts a public image reference with a tag or a digest, and it rejects a registry password. Fargate pulls that image in your account.

## Webhooks

GitHub sends installation and push events to `POST /api/github/webhook`. The request is not a browser session. Springwinter computes `HMAC-SHA256` over the raw body with the webhook secret and compares it to `X-Hub-Signature-256`. A request whose signature does not match is rejected.

The install redirect uses a state value compared in constant time, so a callback has to match the sign-in that started it.

## What you can revoke

Uninstall the GitHub App, or suspend the installation, and Springwinter can no longer mint a token for that account. Repositories already built stay in your AWS account as images and running services until you remove them.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.