How to Configure GitHub Token for Private Repos in Agent-Reach
Store your GitHub Personal Access Token using agent-reach configure github-token <TOKEN> to enable authenticated access to private repositories.
Agent-Reach stores user-specific settings in a YAML configuration file located at ~/.agent-reach/config.yaml. The github_token key within this file controls access to private GitHub repositories. This guide explains how to set up this token using the CLI or manual configuration, based on the actual source code implementation in the Panniantong/Agent-Reach repository.
Storing the GitHub Token
You have two methods for configuring your GitHub token: using the interactive CLI (recommended) or editing the configuration file directly.
Using the CLI (Recommended)
The configure subcommand in agent_reach/cli.py (lines 1101-1103) handles token storage securely. Run the following command and replace <YOUR_TOKEN> with your GitHub Personal Access Token:
agent-reach configure github-token ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
The CLI calls config.set("github_token", value) internally, which writes the token to ~/.agent-reach/config.yaml. After execution, you will see the confirmation: "✅ GitHub token configured!"
Manual Configuration (Advanced)
You can directly edit the configuration file at ~/.agent-reach/config.yaml. The file uses YAML format with the github_token key:
github_token: ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
According to the Config.save method in agent_reach/config.py (lines 49-66), this file is created with permissions 0600 (read/write for owner only), ensuring your token remains private.
How the Configuration Works Internally
Understanding the internal mechanics helps with troubleshooting and advanced use cases.
The Config Class
The Config class in agent_reach/config.py manages the github_token key. When you run the configure command, the Config.set method (lines 27-33) updates the in-memory configuration and triggers a save to disk.
Environment Variable Fallback
If the token is not found in the configuration file, Config.get (lines 69-77) automatically checks for an environment variable named GITHUB_TOKEN (uppercase). This allows temporary overrides without modifying the config file:
export GITHUB_TOKEN=ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
agent-reach doctor
GitHub Channel Integration
The GitHubChannel class in agent_reach/channels/github.py (lines 19-43) uses this token for authentication. During the health check (GitHubChannel.check), the channel validates the token against the GitHub API, either through the authenticated gh CLI or direct API calls using the stored token.
Verifying Private Repository Access
After configuration, verify that Agent-Reach can communicate with private repositories.
Using the Doctor Command
Run the built-in diagnostic tool to confirm your token works:
agent-reach doctor
The output includes a GitHub section. A valid token shows ok, while a missing gh CLI but valid token shows warn (since the API remains accessible).
Programmatic Validation
You can verify token access programmatically using the Config class:
from agent_reach.config import Config
cfg = Config()
token = cfg.get("github_token")
if token:
print(f"GitHub token configured: {token[:8]}...")
else:
print("No GitHub token found")
This reads the token from the configuration file or environment variable, following the fallback logic defined in agent_reach/config.py.
Security and File Permissions
Agent-Reach prioritizes token security through filesystem permissions. The Config.save method explicitly sets file permissions to 0600 (owner read/write only) when writing ~/.agent-reach/config.yaml. This prevents other users on the system from reading your GitHub credentials.
For additional security, use a fine-grained Personal Access Token with minimal scopes. Agent-Reach only requires read access to repositories; the default "no scope" token works for basic private repo access, though you may need repo scope for specific operations.
Summary
- Store tokens using
agent-reach configure github-token <TOKEN>which writes to~/.agent-reach/config.yamlviaConfig.set. - File location is
~/.agent-reach/config.yamlwith the keygithub_token, secured with0600permissions. - Fallback support allows using the
GITHUB_TOKENenvironment variable if the config file lacks the key. - Verification occurs through
agent-reach doctoror theGitHubChannel.checkmethod inagent_reach/channels/github.py.
Frequently Asked Questions
Where does Agent-Reach store the GitHub token?
Agent-Reach stores the token in ~/.agent-reach/config.yaml under the github_token key. The Config.save method in agent_reach/config.py creates this file with strict 0600 permissions, ensuring only your user account can read the sensitive credential.
Can I use an environment variable instead of the config file?
Yes. The Config.get method in agent_reach/config.py (lines 69-77) checks for the GITHUB_TOKEN environment variable (uppercase) as a fallback. If github_token is not set in the YAML file, Agent-Reach automatically uses the environment variable value.
What GitHub token scopes does Agent-Reach require?
Agent-Reach works with a default "no scope" token for basic private repository access. However, if you encounter permission errors, generate a token with the repo scope at https://github.com/settings/tokens to ensure full read access to private repositories.
How do I verify my token is working correctly?
Run agent-reach doctor to execute the health check implemented in agent_reach/channels/github.py. This validates the token against the GitHub API. Alternatively, check ~/.agent-reach/config.yaml directly to confirm the github_token key exists and contains your token value.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →