Sema GitHub integration: individual OAuth vs organization GitHub App for least-privilege access and credential renewal
0 reputation · 16 Dec 2024, 02:11 UTC
We are evaluating Sema for code review and need to configure GitHub access with least-privilege principles. The platform can connect via a user-level OAuth grant or an organization-managed GitHub App installation scoped to selected repositories. Each model changes who controls revocation, who must re-authenticate when credentials expire, and whether access breadth can be limited per repository.
Documentation does not clearly state which authentication model Sema uses by default, whether both are supported simultaneously, or how token expiration is surfaced—whether as a sync failure, an authorization error in the UI, or a silent loss of PR access. The re-authentication flow (individual user vs org admin) also remains unspecified.
Which authentication model does Sema currently employ for GitHub integration—user OAuth, GitHub App installation, or both? When credentials expire or are revoked, what error surfaces and who can trigger re-authorization? Can repository scope be restricted at install time without granting access to all organization repositories?