Install
Two ways in, and they differ on where your code goes.
The Action runs in your CI on your own token. The app runs on ours, on every push, with no workflow file.
Credda never merges. A person merges a pull request, or does not. On both paths, asserted by a committed engine test that fails on a merge call.
01Where your code goes
One path receives a copy of your source. The other does not.
For whoever signs off third party access.
- The Action
- The Action runs in your own CI on your own token. The engine is fetched into your runner, and Credda receives no copy of your code.
- The app
- The app clones the repositories you select onto Credda’s own infrastructure to read them. On this path Credda does receive a copy of your code.
- Both
- Credda never merges. A person merges a pull request, or does not. When a fix is proven, the reproduction and the test arrive with the diff.
02The Action
Two things you paste, and nothing leaves your runner.
A workflow file you commit, on the runner you already pay for, on your own GITHUB_TOKEN.
# .github/workflows/credda.yml
name: Credda on labeled issues
on:
issues:
types: [labeled]
permissions:
contents: read # checkout of the repository under test
issues: write # the one report comment
id-token: write # mint the OIDC token that fetches the engine
jobs:
investigate:
if: github.event.label.name == 'credda'
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- uses: Credda-io/action@v1
with:
# @v1 defaults this to `credda,codereef`, so the run works without
# the line. Pin it anyway: the second name is there to carry old
# installs through the rename and is documented as temporary.
label: credda
# REQUIRED on a private repository: uncomment it. POST /v1/engine
# answers one with no licence 402 Payment Required, and the fetch
# fails before `Run Credda`. Public repos are never asked for a key.
# license: ${{ secrets.CREDDA_LICENSE }}
# Optional. Without it the heuristic provider reproduces, diagnoses and
# reports but writes no patch: the fix stage needs a model-backed one.
# with:
# anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}
gh label create credda --description 'Credda reproduces this bug in a sandbox and comments what it established.'
The permissions: block is the whole grant; contents: write is not in it. Pin Credda-io/action@v1, not a branch. Full instructions.
03The app
One click, then every push.
No workflow file, no token to paste, no CI minutes of yours.
What you are agreeing to
Credda clones the repositories you select onto its own infrastructure, reads them, and opens a pull request for each fix it has proven. A run that proves nothing opens nothing. Unlike the Action above, this path means Credda receives a copy of your code.
| Permission | Level | Used for |
|---|---|---|
| Metadata | read | Resolve a repository id to its default branch. GitHub requires it. |
| Contents | write | Read the code, and create the branch the fix is committed on. |
| Pull requests | write | Open the pull request. Nothing merges it. |
And what it does not ask for
Workflows, Checks, Issues, Actions, Administration, Members and Secrets are absent. One event is subscribed to: Push. Widening it later re-prompts every existing installation.
There is no install button on this deployment. There is no app to install on this deployment yet. The Action above is the path that works today, and it is the one that receives no copy of your code.
For whoever runs this deployment: GITHUB_APP_SLUG is not set in this build, so there is no GitHub App to send anybody to.
04Forges
GitHub is the one that runs. The other two are recorded and stop.
The webhook ingress verifies and records a delivery from all three. Only GitHub is wired from a push through to a run.
The GitHub row is what the product does, not this deployment. The band above has the state of this one.
- GitHub · One click
- Install the app on the repositories you choose. A push to the default branch starts a run, and the fix arrives as a pull request. GitHub is the only forge with an installation primitive: one app, one installation per organisation, and a credential that is not a person.
- GitLab · Recorded, not run
- Nothing to install. A GitLab webhook is verified and recorded, and no run starts from it. GitLab has no installation primitive, no marketplace and no app identity, so a connection is an OAuth grant from a person plus a webhook Credda creates. The push to run wiring is not built, and three half finished forges is how none of them get finished.
- Bitbucket · Recorded, not run
- Nothing to install. A Bitbucket webhook is verified and recorded, and no run starts from it. One click on Bitbucket means a Forge app, which is a separate build on Atlassian’s own runtime rather than a setting. Atlassian Connect closed to new apps on 2026-02-02, so it is not the shortcut it used to be.
Only GitHub gives this product a credential that is not a person’s. On GitLab it is somebody’s OAuth grant: every merge request carries their name and stops working the day they leave the group.
05What ships
Two things you can install. No desktop or mobile app.
Versions read from registry.npmjs.org dist-tags.latest on 2026-09-08, not from our manifest.
- GitHub Action
- Credda-io/action@v1 · pinned by ref
- CLI
- npm install -g credda · 1.1.0
macOS, Windows, Linux, iOS and Android: no application, not started. Write and we will say when that changes.