Registration is coming soon. Acrosite is not open for sign-up yet.Contact us
On this page
Security & Data

How Acrosite uses GitHub access

Acrosite connects through a scoped GitHub App, commits only to the repositories and paths you choose, and keeps installation tokens server-side — never in your browser.

OverviewFor Owners and DevelopersUpdated June 8, 2026

Acrosite publishes by committing to your GitHub repository, so it needs repository access. It is designed to keep that access scoped, server-side, and revocable. This page explains how Acrosite uses GitHub access and what it does not do.

Who this is for

Workspace Owners and Developers who want to understand Acrosite's GitHub access before connecting a repository.

A scoped GitHub App, not a token

Acrosite connects through the Acrosite GitHub App, not a personal access token. When you install it, you choose exactly which repositories it can access. The connection is managed from your GitHub installation settings, where you can change or remove it at any time. See Connect GitHub.

What the access is used for

The GitHub access lets Acrosite:

  • Read your repository list and verify the repository and branch you choose.
  • Commit content and media to the managed paths when you publish.

It writes only to the managed content paths — it does not install a CMS runtime, package, or app folder into your repository.

Tokens stay server-side

Important
Acrosite's GitHub App keys and the short-lived installation tokens it uses stay server-side. They are not exposed to your browser, and they are never shown in the dashboard or in logs.

You can revoke access

Because access is a GitHub App installation, you stay in control: open your GitHub installation settings to adjust which repositories Acrosite can reach, or remove the installation entirely.

Next steps

Frequently asked questions

No. Acrosite uses a GitHub App, so you never paste a personal access token. Installing the App scopes access to the repositories you select.
Only the repositories you grant during installation. You choose them when you install the App, and you can change the selection in your GitHub installation settings.
No. The GitHub App keys and installation tokens stay server-side and are never exposed to the browser, the dashboard, or logs.