Skip to main content
Connect GitHub so your agents can work in your GitHub account. You choose an access level for each account, and Squad refuses any agent action outside that level.

Access levels

Each GitHub account has an access level: Read-only, Read + write code, and Full access. Squad refuses any agent action outside that level. You can also narrow or block single agents under Per-agent access. The description of Read-only does not cover every action at that level. This level also allows: Create inference chat completions and Create inference embeddings. Read + write code is the recommended level. The connect window selects it for you, and you can choose another level. The GitHub sign-in page asks you to approve full access to your account. This is expected. Squad does not narrow the sign-in. It checks every agent action against the level you chose, and it refuses actions outside that level.

What agents can do at each level

Each level opens with a short summary in plain tasks, then lists every action it adds, grouped by what the action works on. You do not need to name actions. Ask in plain words, and the agent searches for the matching action.
Find an action. Open a level and use your browser’s find (Ctrl+F, or Cmd+F on a Mac) with a word from the task or part of a slug. Or ask your agent in plain words, for example “What can you do in my GitHub account?” The agent can search the GitHub actions for you.
Each action shows its name, a one-line description where the GitHub action catalog has one, and its slug. The slug is the ID that agents use when they call the action.
Agents can use 449 of the 793 GitHub actions at this level:
  • View comments
  • View and search repositories
  • View keys
  • View events
  • View and search code
  • View roles and permissions
  • View and search commits
  • View and search users
  • View variables
  • View versions
  • View and search labels
  • View members
All 449 actions at this level:
Agents can use 793 of the 793 GitHub actions at this level: everything in Read + write code, plus:
  • Delete secrets
  • Delete branch protection
  • Delete members
  • Create and delete repositories
  • Delete versions
  • Update and delete organizations
  • Delete packages
  • Delete roles and permissions
  • Delete and cancel runs
  • Update and delete tokens
  • Delete variables
  • Delete caches
The 127 actions that this level adds to Read + write code:

Connect GitHub

Before you start:
  • You need a GitHub account that you can sign in to.
  • Your Squad subscription must be active. Squad does not connect apps while the subscription is not active.
1

Open Integrations

Open Settings > Integrations.
2

Add an integration

On the Connected apps tab, click + Add integration.
3

Find GitHub

Find GitHub in the catalog and click it. You can type the name in Search the catalog….
4

Choose an access level

Under Default scope, choose an access level. This level applies to every agent.
5

Click Connect GitHub

Click Connect GitHub. The GitHub sign-in page opens in a new tab.
6

Sign in to GitHub

Sign in to GitHub and approve the request.
Check that it works: GitHub shows under YOUR CONNECTIONS, with a row for the account and its access level.

Change the access level

  1. Under YOUR CONNECTIONS, find the GitHub account.
  2. Open the account menu (⋯) and click Manage scope.
  3. Under Default scope, choose the new level.
  4. Click Save access.
The change does not need a new sign-in. Agents get the new level from their next call.

Set access for one agent

Every agent uses the account’s level unless you set something else for it. You can narrow one agent to a lower level, or block it.
  1. Under YOUR CONNECTIONS, open the account menu (⋯) on the GitHub account.
  2. Click Manage scope.
  3. Under Per-agent access, find the agent.
  4. Choose the Default option to follow the account’s level, choose a lower level, or choose No access.
  5. Click Save access.
An agent never gets more than the account’s level, even if you choose a higher level for it. Changes apply from the agent’s next call. An agent with No access does not see the account.

Use more than one GitHub account

Click + Account on the GitHub card to connect another account. Agents use the primary account unless they are asked to use a specific one.
  • After you click + Account, follow the connect steps above.
  • Each account has its own access level.
  • The first account you connect becomes the primary account. It shows ★ PRIMARY.
  • To change the primary account, open the account menu (⋯) and click Make primary.
  • To tell accounts apart, open the account menu (⋯) and click Rename.

Reconnect or disconnect

Reconnect when the connection has expired, or when you need to change what the account can reach on the GitHub side:
  1. Open the account menu (⋯) and click Reconnect.
  2. Click Reauthorize on GitHub.
  3. Sign in to GitHub and approve the request.
Reconnect signs in to the same account again. It does not add a second connection. Open the account menu (⋯) on the GitHub account and click Disconnect. Agents lose access to that account at once.
Disconnect acts at once, with no confirmation step. If it was the primary account, another connected GitHub account becomes primary.

Costs

GitHub actions do not use Squad credits. Connected apps never use credits. For what does use credits, see What Squad costs.

Troubleshooting

An agent reports that an action is not allowed on this account.
  • Cause: the action is outside the account’s access level, or outside the level you set for that agent.
  • Fix: choose a higher level in Manage scope, or change the agent’s row under Per-agent access.
An agent says it has no access to GitHub, or it does not see the account.
  • Cause: the agent is set to No access under Per-agent access, or the account is not connected.
  • Fix: open Manage scope and change the agent’s row. If the account is missing, connect it again.
Connecting or saving fails with “Your subscription isn’t active.” An agent says the GitHub connection has expired.
  • Cause: the sign-in for that account is no longer valid.
  • Fix: use Reconnect on the account.

Common questions

Each GitHub account has an access level: Read-only, Read + write code, and Full access. Squad refuses any agent action outside that level. You can also narrow or block single agents under Per-agent access.
Click + Account on the GitHub card to connect another account. Agents use the primary account unless they are asked to use a specific one.
Open the account menu (⋯) on the GitHub account and click Disconnect. Agents lose access to that account at once.

Connect apps

Add an MCP server or an API key

Use this when an action you need is not in this app.