OAUTH 2.0
DEVELOPER TOOLS
Pull requests, issues, and your entire codebase live in GitHub. Your agent can read code, comment on PRs, and triage issues, scoped to the repos the user can access.
For more tools, view docs.
import { ScalekitClient } from "@scalekit-sdk/node";
import { DynamicStructuredTool } from "@langchain/core/tools";
import { createReactAgent } from "@langchain/langgraph/prebuilt";
import { z } from "zod";
const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["github"], toolNames: ["github_issues_list", "github_pull_requests_list", "github_code_search"] },
pageSize: 100,
});
const lcTools = tools.map((t) => new DynamicStructuredTool({
name: t.tool.definition.name,
description: t.tool.definition.description,
schema: z.object({}).passthrough(),
func: async (args) => {
const { data } = await sk.tools.executeTool({
toolName: t.tool.definition.name,
identifier: "user_123",
params: args,
});
return JSON.stringify(data);
},
}));
const agent = createReactAgent({ llm, tools: lcTools });import { ScalekitClient } from "@scalekit-sdk/node";
import OpenAI from "openai";
const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const openai = new OpenAI();
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["github"], toolNames: ["github_issues_list", "github_pull_requests_list", "github_code_search"] },
pageSize: 100,
});
const llmTools = tools.map((t) => ({
type: "function",
function: {
name: t.tool.definition.name,
description: t.tool.definition.description,
parameters: t.tool.definition.input_schema,
},
}));
const resp = await openai.responses.create({
model: "gpt-4o", input: prompt, tools: llmTools,
});import { ScalekitClient } from "@scalekit-sdk/node";
import Anthropic from "@anthropic-ai/sdk";
const sk = new ScalekitClient(envUrl, clientId, clientSecret);
const anthropic = new Anthropic();
const { tools } = await sk.tools.listScopedTools("user_123", {
filter: { connectionNames: ["github"], toolNames: ["github_issues_list", "github_pull_requests_list", "github_code_search"] },
pageSize: 100,
});
const llmTools = tools.map((t) => ({
name: t.tool.definition.name,
description: t.tool.definition.description,
input_schema: t.tool.definition.input_schema,
}));
const msg = await anthropic.messages.create({
model: "claude-sonnet-4-6", max_tokens: 1024,
tools: llmTools,
messages: [{ role: "user", content: prompt }],
});import { Agent } from "@google/adk/agents";
import {
MCPToolset, StreamableHTTPConnectionParams,
} from "@google/adk/tools/mcp";
const toolset = new MCPToolset({
connectionParams: new StreamableHTTPConnectionParams({
url: "https://mcp.scalekit.com/github",
headers: { Authorization: `Bearer ${userScopedToken}` },
}),
});
const agent = new Agent({
name: "agent", model: "gemini-2.0-flash",
tools: await toolset.getTools(),
});// shared bot token
token = "sk_github_shared_xxx"
audit → bot_service_account
engineer_filter → broken
// scalekit · per-user
token = resolve(user_id)
audit → user_abc
scope → enforced ✓Does the agent access GitHub as the user or as a shared key?
As the user. Each workspace member authorizes once and Scalekit resolves their credential at request time. Audit logs attribute every action to that user, not a shared service account.
Where is the GitHub oauth 2.0 stored?
In Scalekit's managed AES-256 token vault, namespaced per tenant. Refresh is automatic. Revocation is a single dashboard action. Tokens never appear in prompts, logs, or LLM context.
Can I limit what the agent is allowed to do in GitHub?
Yes. Pass a tool name filter to listScopedTools so the DevOps agent only sees the subset you authorize. Pre-API-call scope checks block out-of-policy actions before the request reaches GitHub.
What happens when a user revokes GitHub access?
The connection is invalidated on the next tool call. Subsequent requests for that user fail closed with a clear error. Other users in the tenant remain unaffected. The event is logged for audit.
Org repos or personal repos? Which does the agent reach?
Both, scoped to the authorizing user. Org repos the user has access to, personal repos, and forks. Private repos stay private unless the user has read or write rights at the GitHub level.
What other MCP connectors does Scalekit support?
Scalekit runs the GitLab MCP server, Jira MCP server, and Vercel MCP server on the same per-user auth, token vault, and audit trail. Browse 500+ connectors in the MCP connector directory.
How do I build a GitHub agent?
Follow a step-by-step tutorial: Automate GitHub PR release notes with Notion & Slack integration; DevOps AI agent assistant for GitHub, Linear, Slack; The Right Way to GitHub OAuth in a LangChain Agent Built for Multiple Users. Each one covers per-user auth, tool scoping, and working agent code for GitHub.