Integrations
The admin page that registers the Madebook GitHub App and lists every source-control connection on the deployment.
Admin → Integrations. Needs platform.manage_integrations.
The page opens with a statement that applies to everything on it:
Every source-control connection is read-only. The write half of the interface exists so coding agents are a feature flag rather than an integration workspace later, and nothing in this version turns it on.
The Madebook GitHub App
One App per Madebook. Organizations install it in one click; Madebook reads their repositories, receives webhooks and posts the supervised-merge check run as itself — no personal tokens.
The header badge reads registered, registered · no webhook secret, or not registered.
Two things can stop you before you start:
Secrets cannot be stored yet — no encryption key is configured on this server.
Madebook does not know its own address — Madebook does not know its own public API address: Bookbag SSO has no API base registered for it (Platform admin › Apps), and MADEBOOK_PUBLIC_URL is not set. Register the address GitHub can reach, then register the App.
Madebook's public API address comes from Bookbag's app registry — the API base registered for Madebook under Platform admin → Apps at Bookbag. MADEBOOK_PUBLIC_URL on the host overrides it for local development. The webhook and callback URLs on this page are built from that address. See Linked products.
The quick way: one button
Create the App on GitHub sends the browser to GitHub with the App already described — name, webhook address, callback address, the five permissions and the five events. GitHub shows one page: press Create GitHub App there and it sends the browser straight back. Madebook stores the App ID, the slug, the private key and the webhook secret itself; nothing is downloaded and nothing is pasted.
The button offers a GitHub organization field. Leave it blank and the App is owned by your personal GitHub account; name an organization and it is created there instead (you must be an owner of it). Ownership only decides who can edit the App on GitHub later — an App owned by a person still installs on any organization. GitHub's Transfer ownership moves it afterwards, and the stored credentials stay valid.
Back on the page, a toast reports the outcome: "The Madebook GitHub App is registered", "Registration was cancelled on GitHub — nothing changed", or the reason it failed. Then press Verify with GitHub once.
The link GitHub sends the browser back to is signed and names the admin who pressed the button, so it cannot be replayed by anyone else and expires after an hour.
By hand
The manual walkthrough — what to create on GitHub, which permissions and events, and what to paste back — is in The pull request check. It exists for GitHub Enterprise Server and for anyone who prefers to see every field.
What the panel shows
Section 1 gives you the two URLs to copy into GitHub, the five required repository permissions, and the seven events to subscribe to.
Section 2 takes the App ID, the slug, the private key and the webhook secret, plus an optional GitHub Enterprise Server base.
The two secret fields are write-only. The page shows a fingerprint of the key and whether a secret is stored, never the values. An unreadable fingerprint says so plainly: "unreadable — the encryption key may have changed." Leaving a secret field blank on a re-save keeps the stored one.
Verify with GitHub signs a token with the key, asks GitHub who the App is, and reports back:
GitHub knows this App as Madebook (madebook), owned by acme-inc.
followed by either "Every permission and event Madebook needs is declared." or the missing ones by name, with:
Fix them on the App's settings page on GitHub; existing installations are asked to accept the new permissions.
Section 3 lists installations as GitHub reports them: the target, whether it covers all or only selected repositories, whether it is suspended, and either which organization it is connected to here or:
installed on GitHub, not yet connected to an organization here
Empty: "Nobody has installed it yet. An organization installs it from its Connections page (Repositories tab, Option A)."
Connections
Created when an organization connects GitHub on its Connections page — an App installation, or a pasted token.
Each row shows its kind, its status, the account it resolved to, the organization it belongs to (or platform-wide), a hint of its credential, when it was last verified, and how many repositories read through it.
A connection with repositories attached cannot be removed. The button is disabled with the tooltip "Disconnect its repositories first", and the API refuses:
3 repositories are read through this connection. Disconnect them first.
Removing one deletes its stored credential along with it.
Empty: "Connect a repository from an organization's Connections page and the connection appears here."
Two things that are visible but not switchable
A write enabled badge can appear on a connection. Nothing in this version turns it on and there is no control anywhere to do so. The write half of the source-control interface exists so that it is a flag rather than a workspace later — and it is off.
Email settings are not here either. Email delivery moved to Bookbag, shared by every product.
Related
- The pull request check — the full GitHub App walkthrough.
- Connections — where an organization installs the App.
- Connecting a repository
- The platform admin area