Skip to content

GitHub OAuth

The github-oauth lease backend creates GitHub App user access tokens with OAuth device flow. It is useful for local automation where you want GITHUB_TOKEN or GH_TOKEN to be short-lived and tied to the signed-in GitHub user, without storing a personal access token in fnox.toml.

Unlike github-app, this backend only needs the GitHub App client ID. It does not require an app private key or app client secret, so the config can be shared safely across a team.

Tokens are cached in the OS keyring by default and refreshed when GitHub returns a refresh token.

Configuration

toml
[leases.github]
type = "github-oauth"
client_id = "Iv1.yourgithubappclientid"
scope = "repo read:org workflow"
duration = "8h"
FieldRequiredDescription
client_idYesGitHub App client ID; no app secret or private key is required
scopeNoOAuth scopes to request (default: "repo read:org workflow")
env_varNoEnvironment variable name for the token (default: "GITHUB_TOKEN")
keyring_serviceNoOS keyring service for cached tokens (default: "fnox-github-oauth")
keyring_cacheNoCache access/refresh tokens in the OS keyring (default: true)
open_browserNoTry to open the device verification URL in a browser (default: true)
auth_baseNoOAuth token endpoint base URL (default: "https://github.com/login/oauth")
api_baseNoGitHub API base URL (default: "https://api.github.com")
durationNoRequested duration; GitHub controls the actual token lifetime

Prerequisites

Create a GitHub App with device flow enabled and use its client ID. On first use, fnox prints a GitHub device verification URL and user code:

bash
fnox exec -- gh pr list

Approve the device prompt in your browser. Subsequent runs reuse the cached token while it remains valid. In non-interactive mode (--non-interactive or FNOX_NON_INTERACTIVE), fnox fails instead of starting the device flow, so authorize once from an interactive terminal first.

Expiry and revocation

GitHub controls the returned token lifetime. Inspect the tracked lease rather than assuming the requested duration is enforced. This backend relies on expiry; revoking its fnox ledger entry does not provide immediate remote token revocation.

Credentials produced

Environment VariableDescription
GITHUB_TOKENGitHub user access token

The env var name is configurable via the env_var field.

Examples

GitHub CLI

toml
[leases.github]
type = "github-oauth"
client_id = "Iv1.yourgithubappclientid"
env_var = "GH_TOKEN"
bash
fnox exec -- gh pr checkout 123

Disable OS keyring cache

toml
[leases.github]
type = "github-oauth"
client_id = "Iv1.yourgithubappclientid"
keyring_cache = false

With keyring caching disabled, fnox still caches active lease credentials in its lease ledger for the current project.

See also

MIT LicenseCopyright © 2026jdx.dev