What gets indexed
You pick any combination of three content types:- Pull requests: the title and description of every pull request, open and closed. Onyx also stores the author, assignees, labels, state, merge status, commit and changed-file counts, and timestamps as metadata.
- Issues: the title and description of every issue, open and closed, with the author, assignees, labels, state, and timestamps as metadata.
- Documents: documentation files from each repository.
That means
.md,.mdx,.markdown,.rst, and.txtfiles, plus extensionless files that are docs by convention, such asREADME,LICENSE,CHANGELOG,CONTRIBUTING, andCODEOWNERS.
What is not indexed
- Comments on issues and pull requests, review comments, diffs, and commits
- Source code, and data or config files such as
.json,.yaml, and.csv - Files larger than 1 MB, binary files,
and anything under
.git,node_modules,vendor,dist,build,.venv, or__pycache__ - Wikis, discussions, releases, and projects
Before you begin
You need:- An Onyx administrator account.
- A GitHub personal access token, either fine-grained or classic. Onyx authenticates only with a token; GitHub App and OAuth sign-in are not supported.
- For permission sync, a paid Onyx tier: Business or Enterprise on Onyx Cloud, or the Enterprise Edition when self-hosted.
Create the token
Create the token as a user who can see every repository you want indexed; for permission sync, the token’s user also needs push access to every private repository. Fine-grained tokens are the least-privilege choice. Use a classic token when your organization does not allow fine-grained tokens, or when one token must cover repositories of several owners. Pick the expiration deliberately: when the token expires or is revoked, indexing stops until you save a new one in Onyx. After generating the token, copy it right away - GitHub shows it only once.- Fine-grained token
- Classic token
- Resource owner: the user or organization that owns the repositories. Permission sync needs an organization permission, so for permission sync pick the organization, not your personal account. An organization must allow fine-grained tokens, and may require an approval step, before a token for it works.
- Repository access: the repositories to index, or All repositories.
- Repository permissions: set Contents, Issues, and Pull requests to Read-only. GitHub adds Metadata on its own.
- Organization permissions, only if you use permission sync: set Members to Read-only.
Configure the connector in Onyx
Open the GitHub connector
Create a credential
Name the connector and the owner
https://github.com/onyx-dot-app/onyx,
that is onyx-dot-app.Choose the repositories
- Specific Repository: enter one repository name in Repository Name(s), such as
onyx, or several separated by commas, such asonyx,docs. Wildcards do not work. - Everything: index every repository of that owner the token can see.
Choose the content types
Choose the access type
Set the branch (optional)
gh-pages;
blank means each repository’s default branch. It only affects indexing when Include Documents? is on,
though with a single repository Onyx still checks at setup that the branch exists.
After changing it on an existing connector, select Re-Index on the connector’s page to pick up the new branch.Create and verify
GitHub Enterprise Server
To index a GitHub Enterprise Server instance, set GitHub Enterprise Server URL on the credential to your server’s address. Both the web host,https://github.example.com, and the API root, https://github.example.com/api/v3, work.
Create the personal access token on the Enterprise Server instance itself, under the same Settings path;
whether fine-grained tokens are available there depends on the server’s version and configuration.
The URL must use HTTPS.
At the default SSRF protection level,
Onyx also rejects private-network addresses; an administrator can relax that level to reach an internal server.
The URL lives on the credential,
so one Onyx deployment can index github.com and an Enterprise Server side by side under different credentials.
Self-hosted deployments can instead set the GITHUB_CONNECTOR_BASE_URL environment variable as a deployment-wide
default for credentials that leave the field blank; see Configuration.
Permission sync
Set the access type to Auto Sync Permissions when you create the connector, and an Onyx user sees only the GitHub content they can read on GitHub. For an administrator the selector defaults to Public, so pick this option deliberately; the access type cannot be changed later in the admin UI, so switching means recreating the connector.- Documents from public repositories are visible to every Onyx user.
- Documents from private repositories are visible to the repository’s collaborators, including people who have access through a team.
- Documents from internal repositories (GitHub Enterprise) are visible to the organization’s members, matched by email as described below.
Matching GitHub users to Onyx users
Onyx matches by email: the public email on a user’s GitHub profile must equal their Onyx sign-in email, ignoring case. A user whose GitHub email is private, unset, or different from their Onyx email sees no private- or internal-repository content. To set a public email in GitHub, open Settings -> Emails, clear Keep my email addresses private, then pick the address under Public profile -> Public email.Requirements for the token
- The token’s user needs push access to every private repository the connector indexes, because GitHub only reveals a repository’s collaborator list to users with push access.
- If any repository in the connector cannot be synced, the permission update run stops and the remaining repositories are skipped. Permission sync fails closed: while runs keep failing, users can lose access to private- and internal-repository documents, so fix a failing sync promptly.
- For internal repositories, the token’s user must be a member of the organization. A non-member gets only the organization’s public members, which silently leaves out most users.
- GitHub teams are not synced as Onyx groups. Team members still get access to private repositories through the collaborator list.
Troubleshooting
None of the specified repositories could be accessed
None of the specified repositories could be accessed
Found no repos for organization or user
Found no repos for organization or user
repo scope or a fine-grained token access to the owner’s repositories.Private repositories are missing from the index
Private repositories are missing from the index
repo scope,
a fine-grained token does not include those repositories, or the owner is a personal account in Everything mode,
which only finds public repositories.Branch not found
Branch not found
A user sees no GitHub results under permission sync
A user sees no GitHub results under permission sync
Validation failed due to GitHub rate-limits being exceeded
Validation failed due to GitHub rate-limits being exceeded
GitHub credential appears to be invalid or expired
GitHub credential appears to be invalid or expired