Purpose
Purpose
Supported Versions
Supported Versions
Authentication Method
Authentication Method
Required Credentials
How GitHub App Authentication Works
GitHub App authentication works in the following sequence:- AirMDR uses the App ID and PEM private key to generate a JWT
- GitHub uses that JWT to issue an installation access token
- AirMDR uses the installation access token to call GitHub APIs for the installed app scope
Role-Based Access Considerations
To create or install a GitHub App, the user must have sufficient administrative access to the target account, organization, or repository. GitHub notes that installing a GitHub App generally requires organization ownership, repository admin rights, or equivalent authority depending on the target scope.Pre-requisites
Before configuring the GitHub App integration, ensure the following:- A valid GitHub account or GitHub organization
- Permission to create a GitHub App
- Permission to install the app on the required account, organization, or repositories
- Administrative access to AirMDR Integrations
- A secure location to store the downloaded PEM private key
Setup Steps
Create a GitHub App
- Sign in to GitHub.
- In the upper-right corner, click your profile picture.
- Navigate to the correct settings page:
- For a personal account app: click Settings
- For an organization-owned app: click Your organizations → select the organization → Settings
- In the left sidebar, click Developer settings → GitHub Apps
- Click on New GitHub App.
Configure the App
Enter the required app information, such as:- GitHub App name
- Homepage URL

- Webhook URL (if your use case requires webhooks)

- Permissions
- Repository Permissions
- Repository Permissions
Retrieve the App ID
- Remain on the GitHub App settings page.
- Locate the App ID shown in the app details.
Example
Generate the PEM Private Key
- On the GitHub App settings page, scroll to the Private keys section.
- Click on “Generate a private key”.
- A PEM file is downloaded to your local machine.
Install the GitHub App
- In the GitHub App settings page, click Install App.
- Select the target:
- Personal account
- Organization
- Choose one of the following:
- All repositories
- Only selected repositories
- Complete the installation.
Retrieve the Installation ID
UI Method
- Open the GitHub App installation page.
- Look at the browser URL.
Provide the Credentials in AirMDR
(or)
Self Configure GitHub App in the AirMDR Integrations Dashboard.
UI Path Reference
Skills Provided by this Integration
Repository and User Activity
Repository and User Activity
Detection
Detection
Automated Response and Pull Requests
Automated Response and Pull Requests
Configure GitHub App in AirMDR Integrations Dashboard
- Navigate to AirMDR, provide the credentials and click Login.
- Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select Integrations.
- Use the search option, enter the keyword “GitHub App”, select the Connections tab, and click Add New Connection.
-
In the Add New Connection window, enter a name and description for the connection, then provide the following credentials:
Expand Advanced Configuration if required. (Optional)
- In Remote Agent, leave the field unselected. The GitHub App connection uses AirMDR’s cloud connection; Remote Agent routing is not supported for this integration.
- In Expiry, select the date on which AirMDR should treat the stored GitHub App connection credentials as expired, according to your organization’s credential rotation policy.
The AirMDR Expiry setting is a connection management control. It does not revoke or rotate the GitHub App’s PEM private key in GitHub. When you rotate the private key, update the Pem Key in the AirMDR connection as well. - Click Save.
Additional Information
🛑 Security & Access Best Practices
🛑 Security & Access Best Practices
👉 Support & Maintenance
👉 Support & Maintenance
- 📧 Contact AirMDR Support through your designated support channel.
- 🔁 Rotate credentials regularly in GitHub App.
- 🔄 Reconnect in AirMDR when secrets are changed.
🛑 Data Flow & Security
🛑 Data Flow & Security
Data Exchanged
Depending on the permissions granted to the GitHub App, AirMDR may access:- Repository metadata
- Organization metadata
- Security findings
- Pull request context
- Workflow and commit information
- Other GitHub resources within the approved installation scope
Security Controls
GitHub Endpoints
Typical GitHub endpoints include:Authentication Security Model
- AirMDR does not authenticate with a personal access token
- Authentication is scoped to the installed GitHub App
- Effective permissions depend on:
- App permissions
- Installation scope
- Repository selection
🔄 Monitoring & Logs
🔄 Monitoring & Logs
🧰 Error Handling
🧰 Error Handling

