Docs · 06

GitHub access products

Sell read access to a private repository. Token requirements and the buyer flow.

The idea#

GitHub has no shareable invite link for private repositories; access is granted per account. So instead of selling a link, you let EVERYNTH send the invitation: the buyer types their GitHub username after paying and is added as a read-only collaborator. Buyers always get the current version, and you can revoke access from GitHub whenever you like.

Creator setup#

  1. Create a fine-grained personal access token at GitHub → Settings → Developer settings → Personal access tokens. Limit it to the one repository you are selling.
  2. Give it the repository permission Administration: Read and write. Adding collaborators requires admin rights; a token with only Contents or Metadata is rejected at launch.
  3. On Launch, choose Access to a private GitHub repository, enter owner/repository and paste the token.

At launch the server checks the token against GitHub:

GET https://api.github.com/repos/{owner}/{repo}
→ must be 200 and permissions.admin == true

The token is then stored wrapped with the master key, exactly like a content key. It is never shown to buyers or in any API response.

Buyer flow#

  1. Buy the product like any other.
  2. Press Unlock & open. Instead of a download you see a field for your GitHub username.
  3. Press Invite me. EVERYNTH calls GitHub on the creator's behalf:
PUT https://api.github.com/repos/{owner}/{repo}/collaborators/{username}
{ "permission": "pull" }
→ 201 invitation sent · 204 already a collaborator
  1. Accept the invitation at github.com/{owner}/{repo}/invitations or from the GitHub notification.

Limits and rules#

  • One GitHub account per purchase. You can resend to the same username (typo in the email, expired invitation) but not move the purchase to a different account.
  • Invitations expire after seven days on GitHub's side; resend from Purchases if that happens.
  • GitHub limits the number of collaborators on private repositories depending on the owner's plan. That limit is the creator's to manage.
  • The creator can revoke access on GitHub at any time. EVERYNTH does not police that; the product description should say what the buyer is getting (for example "read access for 12 months").
NextModeration and safety →