> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ohmyho.st/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> For account actions, read https://ohmyho.st/skills/ohmyhost-get-started/SKILL.md and use the authenticated ohmyho.st CLI or local product MCP. Mintlify search only reads documentation. Preserve the customer’s selected project, environment and authentication provider.

# Connect GitHub

> Connect a GitHub installation once per workspace, then link its repositories.

Push your application, lockfile and configuration to the repository you want to host. Use the selected workspace and the GitHub account that has access to this repository.

## Connect the workspace once

```sh theme={null}
ohmyhost github status --organization "$ORGANIZATION_ID" --json
ohmyhost github connect --organization "$ORGANIZATION_ID" --idempotency-key "$GITHUB_CONNECT_KEY" --json
```

If status is already connected, reuse it. Otherwise an Owner or Admin opens the one `authorization_url` returned by connect. It handles the required installation/user authorization. After the browser completes, repeat the same connect request/key until its status is `connected`; do not replay callback codes or assemble separate installation and OAuth links.

In CLI JSON, the browser URL is `authorization.authorization_url`; the status command returns `github.connection.settings_url`. MCP and REST return the authorization/status objects directly. The link lasts thirty minutes. While pending, `last_failure` provider\_unavailable or authorization\_code\_rejected means open the same authorization link again and retain the same key. Failed/expired is final: account\_admin\_required needs the account owner or organization admin, denied means consent was declined, installation\_access\_required means the App lacks that account installation, and session\_inactive needs fresh login. Resolve that cause and use a new connect key for the same workspace.

## Link a covered repository

Select the existing or newly created `PROJECT_ID`, then run:

```sh theme={null}
ohmyhost link --project "$PROJECT_ID" --repository-owner "$GITHUB_OWNER" --repository-name "$GITHUB_REPOSITORY" --idempotency-key "$SOURCE_REQUEST_KEY" --json
```

Observe the returned source-link operation before planning a deployment. A covered repository needs no further browser consent. If access is missing, read GitHub status, open `connection.settings_url`, add the repository to that installation and repeat the original link arguments/key. Do not create another project or request a provider token. From the repository root, link records `.ohmyhost/` and adds `/.ohmyhost/` to `.gitignore`; later commands may omit `--project`. With links for several organizations, name the project or saved profile.

## Deploy the intended revision

```sh theme={null}
ohmyhost plan --project "$PROJECT_ID" --commit "$COMMIT_SHA" --json
```

`COMMIT_SHA` is the full SHA of the pushed revision. The plan inspects that source, returns requirements and lasts twenty-four hours. Once ready, [execute it](/cli#connect-and-deploy), or plan/deploy in one step with `ohmyhost deploy --project "$PROJECT_ID" --commit "$COMMIT_SHA" --idempotency-key "$DEPLOY_REQUEST_KEY" --yes --json`.

GitHub authorization alone does not start a build. Direct local archive uploads are not a deployment source. Private runtime secrets travel through the separate [secret workflow](/secrets), not through the source archive.

## Automatic deployment

Where the returned source capability is available, explicitly choose a branch:

```sh theme={null}
ohmyhost source auto-deploy set --project "$PROJECT_ID" --branch "$BRANCH" --enabled true --idempotency-key "$AUTO_DEPLOY_KEY" --json
ohmyhost source auto-deploy status --project "$PROJECT_ID" --json
```

Read back branch/status. Every push to that branch plans and builds its commit into Dev at ordinary rates; Prod still needs a [deployment or promotion](/environments). The status read exposes `latest_operation_id`, including a plan rejection: explicitly plan that SHA for its exact source error, then fix/push again. Automatic deployment is a CLI feature. Use the set command with `--enabled false` and a new intentional-change key to turn it off. [Troubleshooting](/troubleshooting).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.