Reference
Per-tool setup for Tier-1 integrations, ChangeGraph MCP, the Investigation Agent and ChangeGraph provider router, plus local replay / seed / e2e. Use the tabs below to jump between providers and local tooling.
Source of PRs, commits, changed files, and deployments that feed the change graph.
GitHub App webhooks + API normalize installations, pull requests, commits, file lists, and deployment metadata into tenant-scoped entities with natural keys.
| Variable | Purpose |
|---|---|
| GITHUB_APP_ID | GitHub App id |
| GITHUB_APP_PRIVATE_KEY | PEM private key for App JWT |
| GITHUB_WEBHOOK_SECRET | HMAC verification for webhook deliveries |
| GITHUB_TOKEN | Optional PAT for local/API backfill when App not used |
| Symptom | Check |
|---|---|
| 401 / signature fail | Secret mismatch; HMAC must use raw request body |
| Events ignored | installation_id not mapped to a tenant |
| Empty file lists | App missing Contents / Pull requests permissions |
Related: Connect integrations · MCP server · Open source tools · Architecture