How Acrosite uses GitHub access
Acrosite connects through a scoped GitHub App, commits only to the repositories and paths you choose, and keeps installation tokens server-side — never in your browser.
Acrosite publishes by committing to your GitHub repository, so it needs repository access. It is designed to keep that access scoped, server-side, and revocable. This page explains how Acrosite uses GitHub access and what it does not do.
Who this is for
Workspace Owners and Developers who want to understand Acrosite's GitHub access before connecting a repository.
A scoped GitHub App, not a token
Acrosite connects through the Acrosite GitHub App, not a personal access token. When you install it, you choose exactly which repositories it can access. The connection is managed from your GitHub installation settings, where you can change or remove it at any time. See Connect GitHub.
What the access is used for
The GitHub access lets Acrosite:
- Read your repository list and verify the repository and branch you choose.
- Commit content and media to the managed paths when you publish.
It writes only to the managed content paths — it does not install a CMS runtime, package, or app folder into your repository.
Tokens stay server-side
You can revoke access
Because access is a GitHub App installation, you stay in control: open your GitHub installation settings to adjust which repositories Acrosite can reach, or remove the installation entirely.