GitHub agents that triage issues and review the queue

Paste one fine-grained token, limited to the repositories you pick. Qoren registers the webhooks, wakes an agent on issues, pull requests and failed workflow runs, and lets it search, label and comment.

Request early accessSee pricing

Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations

How do I connect GitHub to an AI agent?

Create a fine-grained personal access token for only the repositories your agents should work on, with Webhooks read and write plus read access to issues and pull requests. Paste it in Qoren with the repository or organization. Qoren checks it and sets up the GitHub webhooks when you pick an event. Merging a pull request or closing an issue always waits for a person's approval.

What agents do with GitHub

Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.

For agencies running it for clients

  • First response on a client's new issues

    When someone opens an issue on a client's repository, the agent reads it, searches for duplicates, adds labels and asks for anything missing. On a public repository its comment is published to the world, so it can wait for your approval.

    Wakes on
    Issue opened
    Uses
    Read an issue
    Search issues and pull requests
    Add labels
    Comment
  • A clear note when a build breaks

    When a GitHub Actions workflow run fails, the agent opens an issue that says which workflow failed on which branch, so the client's team sees it in their own tracker.

    Wakes on
    Workflow run failed
    Uses
    Search issues and pull requests
    Open an issue
  • Release notes the client can read

    When a release is published, the agent reads the pull requests behind it and writes a plain-language summary for the client's team.

    Wakes on
    Release published
    Uses
    Search issues and pull requests
    Read a pull request

For founders running it for themselves

  • A summary on every pull request

    When a pull request is opened, the agent reads its description and changed files and comments with a short summary and anything a reviewer should look at first.

    Wakes on
    Pull request opened
    Uses
    Read a pull request
    Comment

The path one event takes

9 GitHub events that can wake an agent

Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.

EventWhen it fires
Issue openedSomeone opens an issue.
Issue labeledA label is added to an issue. Add a condition on label.name to react to one label only.
Comment on an issue or pull requestSomeone comments on an issue or on a pull request's conversation (reviews are a separate event).
Pull request openedSomeone opens a pull request.
Pull request mergedA pull request is merged.
Pull request reviewedSomeone submits a review on a pull request: approved, changes requested or a comment.
PushCommits are pushed to a branch or a tag.
Release publishedA release is published.
Workflow run failedA GitHub Actions workflow run finishes with a failure or times out.

9 tools agents can use

Curated GitHub tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.

ToolWhat it doesAccessApproval
Search issues and pull requestsSearch issues and pull requests in the connection's repositories. Returns number, title, state, labels, author and link.ReadNone
Read an issueRead one issue (or a pull request's conversation): title, body, state, labels, assignees and its latest 10 comments.ReadNone
Read a pull requestRead one pull request: title, body, state, branches, review requests, size and the names of up to 30 changed files.ReadNone
List recent issuesList a repository's issues and pull requests, most recently updated first, at most 30.ReadNone
CommentComment on an issue or a pull request. On a public repository the comment is public.WritePer autonomy setting
Open an issueOpen a new issue. Search first so you do not open a duplicate.WritePer autonomy setting
Add labelsAdd labels to an issue or a pull request. A label that does not exist yet is created by GitHub.WritePer autonomy setting
Close an issue or pull requestClose an issue or a pull request without merging. Always asks a person to approve first.WriteAlways asks
Merge a pull requestMerge a pull request. Always asks a person to approve first.WriteAlways asks

How connecting GitHub works

  1. 01Make a GitHub key with the least access it needs, following the guide below. Only the account owner can connect a tool.
  2. 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where GitHub says, when it expires.
  3. 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
  4. 04Pick the events that should wake the agent. Qoren registers the GitHub webhook itself, so there is no URL or signing secret to copy.

Making the GitHub key

  1. 1

    Create a fine-grained token

    In GitHub, open Settings > Developer settings > Personal access tokens > Fine-grained tokens and choose Generate new token.

    Qoren's connect dialog links straight to this page in GitHub.

  2. 2

    Pick the owner and only the repositories you need

    Set the resource owner to the account or organization that owns the repositories, then choose Only select repositories and pick the ones your agents should work on.

  3. 3

    Tick the least permissions

    Under Repository permissions give Webhooks Read and write (so Qoren can set up triggers), and Issues, Pull requests or Contents Read only, or Read and write only if agents should change things. Leave everything else at No access. For triggers on every repository of an organization, an organization owner gives Organization permissions > Webhooks Read and write instead.

  4. 4

    Set an expiry, then paste the token here

    Pick an expiry date: Qoren reminds you before it lapses. Copy the token and paste it here with the repository (owner/repository) or organization your triggers watch. Never send the token by email or chat.

GitHub setup guide, with screenshots

Connecting a client's account? Send a link

An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.

Client connect links

Security in plain words

  • Keys never reach the agent's machine

    The GitHub key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to GitHub. It is never written to the agent's environment, and after you connect only its last four characters are shown.

  • Read only until you say otherwise

    Each agent gets read only or read and write access, granted one agent at a time. The GitHub key itself can be limited too, and the guide asks for the least it needs.

  • Risky actions always ask

    In GitHub, these always wait for a person's approval, whatever the agent's autonomy setting: close an issue or pull request and merge a pull request.

  • Capped reads and a full audit log

    By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.

  • Event data is treated as data

    Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.

  • Stored events expire

    Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.

GitHub limits worth knowing

When you disconnect, Qoren cannot revoke the key at GitHub, so it tells you where to delete it. In GitHub, open Settings > Developer settings > Personal access tokens and delete the token.

  • A fine-grained token covers one resource owner: one account or one organization. Agents' tools only reach that owner's repositories.
  • GitHub allows 20 webhooks per event on a repository or organization. Qoren checks there is room first.
  • GitHub never retries a failed delivery. Qoren's daily check redelivers the failed ones from the last 3 days.
  • Tokens can expire. When GitHub reports an expiry date, Qoren reminds you 14 and 3 days before it lapses.

Frequently asked questions

Does it work with an organization's repositories?

Yes. Set the token's resource owner to the organization and pick its repositories. For triggers on every repository of the organization, an organization owner gives the token the organization Webhooks permission instead and you enter the organization's name.

Will an agent comment publicly on my open source repository?

Only within the rules you set. Comments and new issues are marked as sending data out, and on a public repository they wait for your approval after the agent has read connected data. Merging and closing always wait for approval.

Does my agent ever see the GitHub key?

No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to GitHub. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.

Can an agent close an issue or pull request without asking?

No. In GitHub, these tools always wait for a person's approval, whatever the agent's autonomy setting: close an issue or pull request and merge a pull request. The approval shows the exact details the agent wants to send.

Approvals
What happens when I disconnect GitHub?

Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at GitHub, so it shows you where to delete it: In GitHub, open Settings > Developer settings > Personal access tokens and delete the token.

What does the GitHub integration cost?

Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.

Qoren pricing

Connect GitHub once. Let agents handle the rest.

Integrations is in early access, turned on account by account. Request it and tell us how your agents should use GitHub.