Skip to main content
The instance must use HTTPS with a certificate from a public certificate authority. If it is behind a firewall, allow inbound HTTPS from StackOne’s IP addresses.

Register a GitHub App on your instance

Create the app on the same GitHub Enterprise Server instance you are connecting. An app registered on GitHub.com does not work here.

1

Open Developer settings

Sign in to your GitHub Enterprise Server instance.

  • Click your profile photo in the upper-right corner, then click Settings
  • In the left sidebar, click Developer settings, then GitHub Apps
  • Click New GitHub App
2

Configure the app

Fill in the app details.

  • GitHub App name: StackOne
  • Homepage URL: https://stackone.com
  • Callback URL: https://api.stackone.com/connect/oauth2/github/callback
  • Leave Expire user authorization tokens selected
  • Leave Request user authorization (OAuth) during installation unselected
  • Under Webhook, deselect Active
3

Set permissions for user access reviews

Enables actions: Check Organization Membership, Get Authenticated User, Get Branch, Get Branch Rules, Get Organization, Get Organization Membership, Get Repository, Get Repository Ruleset, Get Team, Get Unified Credentials, Get Unified Group, Get Unified Organization, Get Unified Role, Get User, List Authenticated User Organizations, List Authenticated User Repositories, List Branches, List Collaborators, List Forks, List Organization Branch Protection, List Organization Members, List Organization Members With Two-Factor Status, List Organization Repositories, List Outside Collaborators, List Repository Rulesets, List Team Members, List Team Repositories, List Teams, List Unified Groups, List Unified Organizations, List Unified Roles, List Unified Users, List User Organizations, List User Repositories, List Users, Search Code, Search Issues, Search Repositories

Under Organization permissions, set Members to Read-only. Under Account permissions, set Email addresses to Read-only. Leave Metadata at its default, Read-only. The connection test reads your own profile, which needs no extra permission.

4

Add permissions for compliance checks

Enables actions: Create Pull Request, Create Pull Request Review, Create Pull Request Review Comment, Get Branch, Get Branch Protection, Get Combined Status For Ref, Get Commit, Get Git Reference, Get Latest Release, Get Organization Ruleset, Get Pull Request, Get Repository, Get Repository Content, List Authenticated User Repositories, List Branches, List Check Runs For Ref, List Commits, List Forks, List Matching Git References, List Organization Audit Log, List Organization Branch Protection, List Organization Repositories, List Organization Rulesets, List Pull Request Reviews, List Pull Requests, List Pull Requests For Commit, List Releases, List Repository Teams, List User Repositories, Merge Pull Request, Search Code, Search Issues, Search Pull Requests With Reviews, Search Repositories, Update Organization, Update Pull Request

For branch protection, reviews, checks and audit logs, also set these to Read-only: under Organization permissions, Administration; under Repository permissions, Administration, Contents, Pull requests, Checks and Commit statuses. Organization rulesets need organization Administration set to Read and write.

5

Add permissions for other actions

Enables actions: Add Collaborator, Add Team Member, Add Team Repository, Cancel Workflow Run, Create Deployment, Create Deployment Status, Create Git Reference, Create Issue, Create Issue Comment, Create Or Update File, Create Organization Repository, Create Pull Request, Create Pull Request Review, Create Pull Request Review Comment, Create Release, Create Team, Create User Repository, Create Webhook, Delete Deployment, Delete File, Delete Git Reference, Delete Release, Delete Repository, Delete Team, Delete Webhook, Download Artifact, Fork Repository, Get Authenticated User, Get Branch, Get Branch Protection, Get Combined Status For Ref, Get Commit, Get Git Reference, Get Issue, Get Latest Release, Get Organization Ruleset, Get Pull Request, Get Repository, Get Repository Content, Get Unified Credentials, Get Webhook, Get Workflow Run, List Artifacts, List Authenticated User Repositories, List Branches, List Check Runs For Ref, List Code Scanning Alerts, List Commits, List Dependabot Alerts, List Deployments, List Forks, List Issue Comments, List Issues, List Matching Git References, List Organization Audit Log, List Organization Branch Protection, List Organization Repositories, List Organization Rulesets, List Pull Request Reviews, List Pull Requests, List Pull Requests For Commit, List Releases, List Repository Teams, List Secret Scanning Alerts, List User Repositories, List Webhooks, List Workflow Jobs, List Workflow Runs, Merge Pull Request, Ping Webhook, Re-run Workflow, Remove Collaborator, Remove Organization Member, Remove Team Member, Search Code, Search Issues, Search Pull Requests With Reviews, Search Repositories, Star Repository, Trigger Workflow, Unstar Repository, Update Code Scanning Alert, Update Dependabot Alert, Update Git Reference, Update Issue, Update Organization, Update Pull Request, Update Release, Update Repository, Update Secret Scanning Alert, Update Team, Update User, Update Webhook

Add these only for the actions you plan to use.

6

Create the app

Under Where can this GitHub App be installed?, select Any account, then click Create GitHub App. On GitHub Enterprise Server the app still stays inside your instance, and Only on this account would stop you installing it on an organization.

7

Copy the credentials

On the app’s page, copy the Client ID. Under Client secrets, click Generate a new client secret and copy it. GitHub shows it only once.

8

Install the app

In the app’s sidebar, click Install App, then Install next to each organization StackOne should read, and choose the repositories. For compliance checks choose All repositories; repositories left out are missing from every list, with no error.

Find your server URL

Use the address you open GitHub Enterprise Server at, such as https://github.example.com. Only the host name is used, so a path such as an organization page or /api/v3 is ignored. The connection always uses https://, even if you type http://.

Linking the Account from the Hub

1

Navigate to the Hub

Use one of the three Linking Account Methods to access the Hub.
2

Fill out the fields

Fill out the following fields using details from your provider:
  • GitHub Enterprise Server URL
  • Client ID
  • Client Secret
  • Organization ID (Optional)
3

Connect

  • Click Connect
  • If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider’s authorization flow.
  • Once authorization is successful, you will see a confirmation popup

If the account linking is successful, you will see the newly linked account in your Accounts page.

Next Steps

Webhooks setup

Configure receiving Events for GitHub into StackOne.