
GitHub AppToken
CertifiedIssue a GitHub App installation access token
GitHub AppToken
Issue a GitHub App installation access token
Signs an RS256 JWT with a GitHub App's RSA private key and exchanges it at the GitHub Apps API for a 1-hour installation token. Use the returned token as the appInstallationToken input on downstream io.kestra.plugin.github.* tasks, or as the Authorization: Bearer ... value on raw HTTP requests.
type: io.kestra.plugin.github.auth.AppTokenExamples
Issue an installation token and reuse it for an issue comment.
id: github_app_token_flow
namespace: company.team
tasks:
- id: token
type: io.kestra.plugin.github.auth.AppToken
clientId: "{{ secret('GITHUB_APP_CLIENT_ID') }}"
installationId: "52068731"
privateKey: "{{ secret('GITHUB_APP_PRIVATE_KEY') }}"
- id: comment
type: io.kestra.plugin.github.issues.Comment
appInstallationToken: "{{ outputs.token.token }}"
repository: kestra-io/kestra
issueNumber: 1347
body: "Triaged automatically. Execution: {{ execution.id }}"
Properties
clientId *string
GitHub App client ID
The fine-grained client identifier (Iv23...) or the numeric App ID. Used as the JWT iss claim when signing.
installationId *string
GitHub App installation ID
Numeric installation identifier under the target user or organization. Find it under Settings → Integrations → Applications → Installed GitHub Apps → Configure (the number at the end of the URL).
privateKey *string
GitHub App private key
PEM-encoded RSA private key for the GitHub App. Both PKCS#1 (-----BEGIN RSA PRIVATE KEY-----, the default GitHub emits when you generate a key) and PKCS#8 (-----BEGIN PRIVATE KEY-----) formats are accepted.
assets
Assets this task consumes as inputs or produces as outputs, for lineage tracking and the asset graph (Enterprise Edition). A flow declaring this property on a task is rejected in the open-source edition.
io.kestra.core.models.assets.AssetsDeclaration
IGNOREFAILWARNAsset failure behavior
Behavior applied to the task state when a declared asset fails to render, emit, or be persisted (e.g. a lock conflict): FAIL escalates it to FAILED, WARN (default) warns it if it would otherwise succeed, IGNORE leaves the state untouched.
Whether to auto-register assets referenced dynamically at runtime that are not statically declared in inputs or outputs.
The assets consumed as inputs.
io.kestra.core.models.assets.AssetIdentifier
1The assets produced as outputs.
io.kestra.plugin.ee.assets.Dataset
1150{}1150io.kestra.plugin.ee.assets.File
1150{}1150io.kestra.plugin.ee.assets.Table
1150{}1150io.kestra.plugin.ee.assets.VM
1150{}1150io.kestra.core.models.assets.External
1150{}1150io.kestra.core.models.assets.Custom
11501Custom asset type
{}1150endpoint string
https://api.github.comGitHub API endpoint
GitHub or GitHub Enterprise API base URL such as https://api.github.com or https://ghe.acme.com/api/v3. Defaults to https://api.github.com when unset.
Outputs
expiresAt string
date-timeExpiration timestamp
Instant at which GitHub will reject the token, parsed from the API response.
token string
Installation access token
Bearer token valid for one hour from issuance. Pass as appInstallationToken to downstream io.kestra.plugin.github.* tasks, or as Authorization: Bearer ... for raw HTTP requests.