Skip to main content
GitHub sign-in admits active members of your allowed organizations. Authentication overview has the rules shared by every provider.

Setup

1

Register an OAuth App on GitHub

Go to GitHub’s Developer settings → OAuth Apps and click New OAuth App. For shared ownership, register the app under an organization instead (Organization settings → Developer settings → OAuth Apps).Fill in:
  • Application name: any name, such as Rootprint
  • Homepage URL: the public URL of your Rootprint instance
  • Authorization callback URL: https://<your-rootprint>/api/auth/callback/github
Copy the Client ID, then generate and copy a Client Secret.
2

Enter credentials in Rootprint

In Rootprint, go to Settings → Authentication, then click Configure on the GitHub row. Enter:
  • Client ID and Client Secret: from your GitHub OAuth App.
  • Allowed organizations: the organization logins whose members can sign in. Use the login from github.com/<org>, not the display name. Matching ignores case.
3

Save the configuration

Click Save. A Continue with GitHub button appears on the sign-in page.

How organization membership is checked

Rootprint requests the read:org and user:email scopes. At each sign-in, it admits the user only if one of their active organization memberships matches an allowed organization. If GitHub doesn’t answer, for example because of a timeout or rate limiting, Rootprint denies the sign-in and logs the reason.
If an organization has OAuth App access restrictions enabled, your OAuth App must be approved by an organization owner before membership checks succeed for that org. Until it is approved, members of that organization will be denied sign-in. You can approve the app from the organization’s Settings → Third-party Access → OAuth App policy.