Trust

What RepoWerk can do on your GitHub

RepoWerk works through a GitHub App. This page lists every permission it asks for, why, and what it never touches. It is kept in sync with the App's configuration.

Last updated September 29, 2026

Repository permissions

Granted only on the repositories you choose when installing the App, on your account or your organization.

  • AdministrationRead & write

    Create the new repository on your account or organization.

    Also sets the repowerk topics and, if generation fails halfway, deletes the incomplete repository it has just created.

  • ContentsRead & write

    Write the template files as the repository's first commit.

    Used only on repositories RepoWerk creates. It never reads or changes the contents of your other repositories.

  • WorkflowsRead & write

    Include the GitHub Actions workflows (CI, store distribution) that ship with the templates.

    GitHub requires this permission for any file under .github/workflows/. RepoWerk doesn't run or edit workflows afterwards.

  • ChecksRead

    Show the build status of your projects in the dashboard.

    Reads check results on the default branch. RepoWerk never creates or changes checks.

  • DeploymentsRead

    Show the latest deployment status of your projects.

    Reads deployment statuses. RepoWerk never creates deployments.

  • MetadataRead

    Required by GitHub for every App.

    Basic, read-only information such as a repository's name, visibility and default branch.

Webhook events

GitHub notifies RepoWerk of these events so the dashboard stays current. Every notification is verified with a signature.

Repository
A repository is renamed, archived, made private or public, transferred or deleted.
Check run
A build finishes on the default branch.
Deployment status
A deployment changes state.

What we never ask for

  • No account permissions: not your email, followers, SSH or GPG keys.
  • No organization permissions: not members, teams, billing or settings.
  • No access to issues, pull requests, secrets or Actions variables.
  • No changes to repositories RepoWerk didn't create.

When GitHub asks you to approve new permissions

If you install the App today, you grant everything listed above in one step. If we ever add a permission, GitHub doesn't extend existing installations on its own: the owner of the account or organization has to approve it. Until then, the features that need it fail with a message pointing here.

Personal account

Open GitHub → Settings → Applications → Installed GitHub Apps.

Organization

Open the organization → Settings → GitHub Apps. You need to be an owner.

  1. Next to RepoWerk, choose Review request and accept the new permissions.
  2. Go back to RepoWerk and try again. You don't need to reconnect.
Your installations

Revoking access

You can remove RepoWerk at any time from the same GitHub page: choose Configure, then Uninstall. Repositories already created stay yours and aren't changed. To also sign out of RepoWerk, disconnect GitHub from the platform settings.

Change history

  • Complete permission set published: Administration, Contents and Workflows (read & write), Checks, Deployments and Metadata (read), with the Repository, Check run and Deployment status events.