Docs · 06
GitHub access products
Sell read access to a private repository. Token requirements and the buyer flow.
The idea#
GitHub has no shareable invite link for private repositories; access is granted per account. So instead of selling a link, you let EVERYNTH send the invitation: the buyer types their GitHub username after paying and is added as a read-only collaborator. Buyers always get the current version, and you can revoke access from GitHub whenever you like.
Creator setup#
- Create a fine-grained personal access token at GitHub → Settings → Developer settings → Personal access tokens. Limit it to the one repository you are selling.
- Give it the repository permission Administration: Read and write. Adding collaborators requires admin rights; a token with only Contents or Metadata is rejected at launch.
- On Launch, choose Access to a private GitHub repository, enter
owner/repositoryand paste the token.
At launch the server checks the token against GitHub:
GET https://api.github.com/repos/{owner}/{repo}
→ must be 200 and permissions.admin == trueThe token is then stored wrapped with the master key, exactly like a content key. It is never shown to buyers or in any API response.
Buyer flow#
- Buy the product like any other.
- Press Unlock & open. Instead of a download you see a field for your GitHub username.
- Press Invite me. EVERYNTH calls GitHub on the creator's behalf:
PUT https://api.github.com/repos/{owner}/{repo}/collaborators/{username}
{ "permission": "pull" }
→ 201 invitation sent · 204 already a collaborator- Accept the invitation at
github.com/{owner}/{repo}/invitationsor from the GitHub notification.
Limits and rules#
- One GitHub account per purchase. You can resend to the same username (typo in the email, expired invitation) but not move the purchase to a different account.
- Invitations expire after seven days on GitHub's side; resend from Purchases if that happens.
- GitHub limits the number of collaborators on private repositories depending on the owner's plan. That limit is the creator's to manage.
- The creator can revoke access on GitHub at any time. EVERYNTH does not police that; the product description should say what the buyer is getting (for example "read access for 12 months").