Onboard GitHub Co-Pilot to CloudHiro with a read-only GitHub App

Create a GitHub App owned by your organization so CloudHiro can read billing, Copilot, and optional Actions usage signals without access to source code, issues, pull requests, or write permissions.

Before you start

You need to be an organization owner on GitHub. A GitHub App belongs to an installation, not a person, so there is no user token to rotate and access keeps working when staff change.

Organization name, for example my-org
App ID
Installation ID
Private key (.pem file)

Send these details through the secure channel agreed with your CloudHiro contact. Never email the .pem file in plain text.

Permissions at a glance
PermissionLevelRequiredData it unlocksEndpoint
Organization: AdministrationRead-onlyYesPlatform spend, spend budgets, Actions cache usageGET /organizations/{org}/settings/billing/usage
Organization: GitHub Copilot BusinessRead-onlyOnly if you use CopilotCopilot seats and last activityGET /orgs/{org}/copilot/billing/seats
Organization: Organization Copilot MetricsRead-onlyOnly if you use CopilotPer-user daily Copilot usageGET /orgs/{org}/copilot/metrics/reports/users-1-day
Repository: ActionsRead-onlyOptionalWorkflow run durations and long-running workflowsGET /repos/{org}/{repo}/actions/runs

CloudHiro does not request other repository permissions, account permissions, write access, webhooks, or event subscriptions.

Step 1 - Create the GitHub App
  1. Go to your organization settings, then Developer settings, GitHub Apps, New GitHub App.
  2. Use a clear app name, for example CloudHiro.
  3. Set the Homepage URL to https://cloudhiro.com.
  4. Uncheck Active under Webhook. The app only makes outbound calls.
  5. Leave callback URL and Request user authorization empty or unchecked.
Step 2 - Set the permissions

Under Organization permissions, set exactly these permissions:

  • Administration - Read-only
  • GitHub Copilot Business - Read-only, skip if you do not use Copilot
  • Organization Copilot Metrics - Read-only, skip if you do not use Copilot

Optional: for the long-running workflow report, set Repository permissions, Actions to Read-only. Metadata read-only is added automatically. Leave every other permission at No access.

Administration is the only permission GitHub exposes for billing data, and read-only grants no write access.

Copilot must be enabled on the organization, otherwise Copilot calls return 404 regardless of permissions.

The Copilot usage report also requires the Copilot usage metrics policy to be enabled under Settings, Copilot, Policies.

Step 3 - Install the App and generate credentials
  1. Under Where can this GitHub App be installed, choose Only on this account, then create the app.
  2. Copy the App ID from the app settings page.
  3. Scroll to Private keys and generate a private key. A .pem file downloads; treat it like a password.
  4. In the app's left menu, choose Install App, then Install next to your organization.
  5. Choose Only select repositories and select none, or choose All repositories. CloudHiro never reads repository contents.
  6. Click Install. The page URL ends with /installations/<number>; that number is the Installation ID.
Step 4 - Send CloudHiro the details

Send these four items to your CloudHiro contact through the agreed secure channel:

  • Organization name
  • App ID
  • Installation ID
  • Private key (.pem file)
Quick checklist
GitHub App created with webhook inactive
Organization permissions set to read-only: Administration, GitHub Copilot Business, Organization Copilot Metrics
Optional Repository permission: Actions read-only
App installed on the organization
Organization name, App ID, Installation ID, and .pem file sent through a secure channel

What CloudHiro can and cannot do

CloudHiro can read billing and spend data, budgets, workflow run durations, Copilot seat assignments and usage, and Actions cache usage.

CloudHiro cannot read source code, issues, pull requests, logs, or artifacts; cannot change settings, budgets, billing configuration, or seats; and cannot create or delete anything in your organization.

To revoke access, uninstall or delete the GitHub App from GitHub. Access stops immediately with no coordination required.

Azure Onboarding

Get Started

Datadog Onboarding

Get Started

MongoDB Atlas Onboarding

Get Started