---
sidebar_label: fullsend github
---

# fullsend github

Configure fullsend on GitHub organizations and repositories without requiring GCP credentials. All GCP infrastructure values (mint URL, WIF provider) are passed as flags.

## Commands

| Command | Description |
|---------|-------------|
| `fullsend github setup <org\|owner/repo>` | Configure fullsend for an org or repo |
| `fullsend github enroll <org> [repo...]` | Enable repositories for agent workflows |
| `fullsend github unenroll <org> [repo...]` | Disable repositories from agent workflows |
| `fullsend github set <target> <key> <value>` | Update a single config value (secret or variable) |
| `fullsend github status <org>` | Analyze GitHub-side installation state |
| `fullsend github sync-scaffold <org>` | Update workflow templates to current CLI version |
| `fullsend github uninstall <org>` | Remove fullsend GitHub configuration |

## `github setup`

Configures a GitHub organization or repository with fullsend. Creates the `.fullsend` config repo (per-org mode), installs GitHub Apps, and sets variables and secrets.

**Per-org mode** requires GitHub organization owner access:

```bash
fullsend github setup <org> \
  --mint-url="<MINT_URL>" \
  --inference-project "<GCP_PROJECT>" \
  --inference-wif-provider "<WIF_PROVIDER>"
```

**Per-repo mode** requires repo admin access only:

```bash
fullsend github setup <owner/repo> \
  --mint-url="<MINT_URL>" \
  --inference-project "<GCP_PROJECT>" \
  --inference-wif-provider "<WIF_PROVIDER>"
```

**Re-running per-repo setup** (for example after a fullsend upgrade) refreshes the managed
workflow files but never rewrites an existing `.fullsend/config.yaml` on its own: `agents:` entries and
their per-agent settings, allowlists and hand-written comments stay as they are, the runtime prompt is skipped,
and the setup PR reports the runtime the file already selects. Passing a flag that targets a
config key — `--runtime`, `--agents`, `--mint-url`, `--inference-*` — changes that key on the
existing file and keeps the rest (the file is re-serialized, so comments are not preserved in
that case). `--config` rewrites `config.base.yaml` from the preset (byte-for-byte) and keeps
the existing overlay unless a persistent setup flag is also passed, in which case that flag is
written into the overlay. Persistent setup flags may be combined with `--config`; they override
the corresponding preset values. A `config.yaml` that no longer parses fails the re-run rather
than being regenerated.

### Flags

| Flag | Default | Description |
|------|---------|-------------|
| `--mint-url` | | HTTPS endpoint of the token mint service |
| `--inference-provider` | | Inference provider; resolved to `vertex` if unset |
| `--inference-project` | | GCP project ID for Vertex inference; optional for per-repo setup |
| `--inference-wif-provider` | | Full WIF provider resource name; optional for per-repo setup |
| `--openai-audience` | | OpenAI Workload Identity audience for GPT on pi or codex; with the two flags below, written to `inference.openai` in `config.yaml` (all three or none) |
| `--openai-identity-provider-id` | | OpenAI Workload Identity provider ID |
| `--openai-service-account-id` | | OpenAI service account ID the provider maps this repository to |
| `--inference-region` | | GCP region for inference; resolved to `global` if unset |
| `--skip-app-setup` | `false` | Skip GitHub App creation/installation |
| `--app-set` | `fullsend-ai` | App set name prefix for GitHub Apps. For per-repo setup it is persisted as the `FULLSEND_APP_SET` repository variable; reruns that omit `--app-set` preserve an existing custom value rather than overwriting it with the default. `repos install` accepts the same option and the `app_set` manifest field. |
| `--agents` | `fullsend,triage,coder,review,retro,prioritize` | Agent roles to provision |
| `--direct` | `false` | Push scaffold directly instead of creating a PR |
| `--runtime` | `claude` | Agent runtime backend (`claude`, `pi`, `codex`, `dummy` or `dummy-playback`; `dummy` and `dummy-playback` are for behaviour test orgs only — see [runtimes.md](../runtimes.md)) |
| `--fullsend-ref` | | Per-repo fullsend workflow ref override (conflicts with `--vendor`; per-repo only) |
| `--config` | | Local file path or HTTPS URL to a vendor preset (committed as `.fullsend/config.base.yaml`; per-repo only). Persistent setup flags override matching preset values in `.fullsend/config.yaml`. Fleet installs declare the same source in `repos.yaml` (`defaults.config_base` / per-repo `config_base`) |
| `--config-hash` | | SHA-256 hex digest to validate the preset content (requires `--config`). Same semantics as `repos.yaml` `config_base.sha256` |

**Fetching an HTTPS `--config` preset** rejects URLs containing userinfo (e.g.
`https://user:pass@host/...`) and validates every resolved address — on the initial
request and on every redirect — against loopback, link-local, private, and cloud
metadata IP ranges. `HTTP_PROXY`/`HTTPS_PROXY` are ignored for preset fetches. This
applies to any HTTPS preset source, whether passed via `--config` or declared in
`repos.yaml` (`defaults.config_base` / per-repo `config_base`).

### Required OAuth scopes

| Scope | Per-org | Per-repo |
|-------|:-------:|:--------:|
| `repo` | x | x |
| `workflow` | x | x |
| `admin:org` | x | |

## `github enroll`

Enables agent workflows on repositories by updating `config.yaml` in the `.fullsend` repo and triggering enrollment PRs.

```bash
fullsend github enroll <org> <repo-name> [repo-name...]
fullsend github enroll <org> --all
```

## `github unenroll`

Disables agent workflows on repositories.

```bash
fullsend github unenroll <org> <repo-name> [repo-name...]
fullsend github unenroll <org> --all [--yolo]
```

The `--all` flag prompts for confirmation. Pass `--yolo` to skip the prompt.

## `github set`

Updates a single configuration value (secret or variable) on a GitHub org or repo.

```bash
fullsend github set <org|owner/repo> <key> <value>
```

| Key | Storage | Description |
|-----|---------|-------------|
| `FULLSEND_GCP_REGION` | Repo variable | GCP region for inference |
| `FULLSEND_REVIEW_CLIENT_ID` | Repo variable | Review app OAuth client ID |
| `FULLSEND_PER_REPO_INSTALL` | Repo variable | Per-repo install marker |
| `FULLSEND_GCP_PROJECT_ID` | Repo secret | GCP project for inference |
| `FULLSEND_GCP_WIF_PROVIDER` | Repo secret | WIF provider resource name |
| `FULLSEND_OPENAI_API_KEY` | Repo secret | Opt-in OpenAI API key used only when the WIF trio is unset. Do not add this via `github setup`; set it only when you cannot enrol OpenAI WIF. |

## `github status`

Analyzes the GitHub-side installation state. Read-only.

```bash
fullsend github status <org>
```

## `github sync-scaffold`

Updates workflow templates in enrolled repositories to match the current CLI version.

```bash
fullsend github sync-scaffold <org>
```

## `github uninstall`

Removes fullsend GitHub configuration for an organization. Deletes the `.fullsend` config repo and associated resources.

```bash
fullsend github uninstall <org> [--yolo] [--app-set <name>]
```

## See also

- [Configuring GitHub for fullsend](../guides/getting-started/configuring-github.md) — getting started guide
- [Advanced setup](../guides/infrastructure/advanced-setup.md) — non-standard installation paths and setup flags
- [Operations](../guides/getting-started/operations.md) — day-2 administration (enrollment, status, uninstall)
