https://docs.jacobpevans.com/github/apps.
Every App inherits the shared settings. The Apps table
lists only what an App changes. Any other page that needs an App setting links to this
page. It never copies a value.
Shared settings
The table follows the order of GitHub’s “Create GitHub App” form.
Installing on all repositories is safe. Breadth is not the security boundary.
Each minted token is short-lived and scoped to one repository. The App’s permission list
caps what a token can do. Branch protection still applies.
Installing in each organization
The Enterprise owns the App definition, so one edit changes it for every organization. Each organization still needs its own installation.- An Enterprise-owned App installs on the Enterprise or on organizations inside it. It cannot install on a personal account.
- A permission change made by an Enterprise owner is accepted automatically in every organization. A change made by an App manager waits for an organization owner.
- An App manager can edit settings and keys but cannot install the App.
Apps
Each row lists only overrides of the shared settings. Permissions is always an override: read the live list athttps://api.github.com/apps/<slug> instead of a copy
here. GitHub owns that fact.
An App without an ID is not yet published on GitHub. Its row gains the IDs when GitHub
publishes the App. Read any published App live at
https://api.github.com/apps/<slug>.
Identifiers are publicAn App ID and client ID are public: the GitHub API returns them for any public App. The
private key, client secret, and webhook secret are never written in these docs.