Mojo UpDocs
Administration

Source control

Connect GitHub and Azure DevOps so people, and the agents working for them, act with their own accounts.

Every person works with their own source-control account, and agents working for a person commit as that person and see only what that person may see. Nobody pastes a token: your organisation registers a GitHub App, people connect through it, and the platform refreshes their sign-in itself. In self-hosted AIOE, Azure DevOps works the same way through Entra ID.

Administrators set up connections under Settings, Source connections. Each person links their own account under Settings, Source control.

Connect GitHub with a GitHub App

Once per GitHub organisation, by an owner of that organisation and an administrator of yours.

Create the app

In GitHub, open your organisation's Settings, Developer settings, GitHub Apps, New GitHub App:

  • Callback URL: your platform's API address followed by /source/v1/github/callback. In Mojo Up AI Cloud that is https://ai.mojoup.com.au/source/v1/github/callback; in self-hosted AIOE, https://<your API host>/source/v1/github/callback.
  • Tick Expire user authorization tokens (people's tokens then live eight hours, and the platform refreshes them) and Request user authorization (OAuth) during installation.
  • No setup URL; leave the webhook inactive.
  • Repository permissions: Contents read and write, Pull requests read, Issues read (Metadata read is automatic).
  • Installable only on this account.

Collect its details

On the app's page, note the App ID and Client ID, generate a client secret, and generate a private key (a .pem file downloads).

Install it

Choose Install App, then your organisation, and either all repositories or the ones the platform may reach.

Add the connection

In the console, open Settings, Source connections. Choose GitHub, enter your GitHub organisation's name, the App ID, the app slug (from the app's address, github.com/apps/<slug>), the Client ID, the client secret and the private key's full text, and choose Add connection. The platform finds the installation and says the GitHub App is installed on your organisation.

People connect

Each person opens Settings, Source control and chooses Connect with GitHub.

Connect Azure DevOps through Entra (self-hosted)

People choose Connect through Entra under Settings, Source control, and the platform obtains an Azure DevOps token on their behalf from their sign-in and refreshes it silently. This needs a one-off setup of your API registration and the AIOE_ENTRA_CLIENT_SECRET setting: see Let AIOE act for people in Azure DevOps. It is not offered in Mojo Up AI Cloud.

Without it, people link Azure DevOps by pasting a personal access token (Code read and write, Work items read).

A project's source

A project's owners choose, on the project's Source tab, which connection the project uses, its organisation (or Azure DevOps project), and its repositories. Repositories that nodes open are matched to it by their remote. Open issues, pull requests and work items then show on the project's Work tab, read with each person's own account where they have linked one, else the organisation's.

Credentials for agents

When an agent needs to push or pull, its machine asks the platform for a git credential for the person it works for. The answer is that person's own token, valid for an hour at most. If the person has not linked an account, the request is refused and says who needs to link. Every grant and refusal is recorded in the audit trail with the person and the machine.

The organisation's own credential

Two options exist for cases with nobody attached, and both are off unless you turn them on:

  • An organisation token (under "Or an organisation token (not recommended)") for reads by people who have not linked, mainly for GitHub Enterprise Server without an app.
  • Let nodes fall back to the organisation's credential, ticked when you add a connection, lets nodes use the organisation's credential (the GitHub App's installation, or that token) for work with nobody attached, or for people who have not linked. The connection then shows "shared fallback allowed".

Your organisation's credential is never used to make a commit look like the organisation's unless you turn the fallback on.

On this page