ChangeGraphChangeGraph

Reference

Tools reference

Per-tool setup for Tier-1 integrations, ChangeGraph MCP, the Investigation Agent and ChangeGraph provider router, plus local replay / seed / e2e. Use the tabs below to jump between providers and local tooling.

GitHub

Source of PRs, commits, changed files, and deployments that feed the change graph.

What it does

GitHub App webhooks + API normalize installations, pull requests, commits, file lists, and deployment metadata into tenant-scoped entities with natural keys.

How to connect / configure

  1. Create a GitHub App (preferred) or use a PAT for API backfill.
  2. Setup (/setup) shows integration status cards with Test, Reconnect, and Disconnect, plus feature-gate toggles. Map installation_id → tenant there.
  3. Point the webhook at POST /api/webhooks/github with the App webhook secret.
  4. Backfill is API only: POST /api/v1/setup/backfill (returns 202). Setup has no backfill button. See Getting started: Where the running app reads data.

Environment variables

VariablePurpose
GITHUB_APP_IDGitHub App id
GITHUB_APP_PRIVATE_KEYPEM private key for App JWT
GITHUB_WEBHOOK_SECRETHMAC verification for webhook deliveries
GITHUB_TOKENOptional PAT for local/API backfill when App not used

Permissions

  • Contents (read)
  • Pull requests (read)
  • Metadata
  • Deployments (read), when available

Example workflow

  1. Engineer merges a PR → webhook delivers pull_request / push.
  2. ChangeGraph upserts PR + commits + files (tenant + PR number / SHA).
  3. Later Vercel deploy and Sentry error correlate against those changes.

Troubleshooting

SymptomCheck
401 / signature failSecret mismatch; HMAC must use raw request body
Events ignoredinstallation_id not mapped to a tenant
Empty file listsApp missing Contents / Pull requests permissions

Related: Connect integrations · MCP server · Open source tools · Architecture