GitHub is where most Coders do their work. Connect it and your assistants can read your repositories, issues, and pull requests, then turn finished work into a pull request you can review.
The Coder clones your repository into its own workspace, never onto your computer, and does the work there.
In GitHub, create a personal access token (classic or fine-grained) with the permissions listed below, limited to the repositories you want the Coder to use.
Give the token only what the Coder needs, in plain words:
Read your repository contents and its metadata.
Write to repository contents, so the Coder can push a branch.
Read and write issues.
Read and write pull requests.
Read check results and commit statuses, so it can tell whether your tests passed.
With a classic token, the repository scope covers all of these. With a fine-grained token, choose the specific repositories and grant the permissions above. Nothing needs access to your account settings, other organisations, or deleting a repository.
Pushing and merging follow your house rules. The work becomes a pull request for review. A draft is the default for a first run. If your house rules allow it, the Coder can also merge and ship. Pushing a branch waits for your Approve unless your house rules allow it. See house rules and approvals.
Your token stays with your StellarFirm workspace and is never shown back to you. The page shows only that it is connected.
Your token is passed to a single command at a time. It is never written into the repository settings.
If the Coder cannot clone, the job stops as Blocked before any coding and says what to fix, usually that the token cannot read that repository.
Pick the smallest set of repositories you can. You can always widen the token later.