---
title: GitHub
description: Install the Ysra GitHub App to give Developer access to the repositories you choose — what it can do, which permissions it asks for, and how to change or revoke access.
---

Developer works on your code through the **Ysra GitHub App**. You choose which
repositories it can see; you can change that at any time on GitHub.

## Connect

1. **Workspace → Integrations → GitHub → Connect.**
2. On GitHub, choose the organisation or account and the repositories to grant —
   *all repositories* or a selected list.
3. You return to Ysra with the connection marked **Ready**, listing what it can
   do.

The connection belongs to a workspace: sessions in that workspace can use the
granted repositories.

## What it can do

| Capability | Used for |
|---|---|
| **Clone** | Reading the repository into an isolated workspace for a session. |
| **Deliver** | Pushing a branch and opening a pull request — only as your [delivery policy](../workspace/autonomy-policy.md) allows. |
| **Create repositories** | Starting a new repository for greenfield work. |

GitHub shows the exact permissions it grants before you confirm: read access to
repository metadata and contents, write access to contents and pull requests.

## Using a repository

After connecting, repositories appear in the Build composer's repository picker.
The first time you use one, Ysra prepares it — learning its structure and
commands, without running its code — so later sessions start faster.

Pick the **branch** to start from; Ysra always writes to a new branch.

## Delivery credentials stay separate

Having a repository connected doesn't let a session push to it. Delivery happens
only through the delivery step, after your policy or your click allows it, and
the credentials used for it are short-lived and never given to the workspace
doing the coding.

## Change or revoke access

- **Add or remove repositories** in the app's settings on GitHub. Then use
  **Refresh** in Ysra.
- **Uninstall** the app on GitHub to revoke access entirely.

If a session can't reach a repository — for example after its access was removed —
it stops with a clear reason instead of retrying.
