⚠ use a dedicated bot account, not a human's —
and a minimally-scoped personal access token (only
the repos/scopes the agent actually needs, e.g. repo +
workflow). the container boundary is the enforcement:
anything within the token's scopes is reachable if the agent is ever
compromised. the token is injected into the agent's state dir and is
never displayed back on this page.
◇ status
select an agent to see its github credential status.
◇ provision
generate a token at
github.com/settings/tokens
and paste it below. one account per agent — pasting a new token
replaces the stored one.