tai42-tools-github
GitHub provisioning tools for the TAI ecosystem — manifest-loaded repository-webhook
setup tools that create a repository webhook, list a repository's webhooks (following
Link-header pagination to exhaustion), and delete a repository webhook. They are the
provider-side setup counterpart to a runtime webhook-signature verifier: these tools
register the hook a verifier later authenticates.
All GitHub traffic is direct REST v3 through tai42-kit's curl client (no SDK); the
X-GitHub-Api-Version header is pinned in code. The package registers its tools through
the tai42_app handle from tai42_contract.app and never imports the skeleton.
The TAI ecosystem
TAI is an open-source runtime for MCP tools, agents, and workflows. A tool is a callable the host loads from a plugin manifest; this package supplies the GitHub repository-webhook provisioning tools. The ecosystem is open-ended, so this repo is these tools' own full doc home, and the documentation site covers the platform-level story:
- Tools concept: https://tai42.ai/concepts/tools
- Build a tool (author guide): https://tai42.ai/guides/authors/tool
- Ecosystem catalog: https://tai42.ai/reference/catalog
Install
Requires Python 3.13+. Install from PyPI into the environment that runs the server:
uv add tai42-tools-github
Or from source — clone this repo and add it as an editable dependency; the
tai42-* dependencies resolve in-tree from the workspace.
git clone https://github.com/tai42ai/tai42 # next to your app checkout
cd /path/to/your/app
uv add --editable ../tai42/plugins/tools-github
Catalog
| Tool | Description |
|---|---|
create_github_webhook |
Creates a repository webhook on owner/name and returns its id, delivery url, events and active flag. The caller supplies the signing secret; GitHub never returns it. |
list_github_webhooks |
Lists every webhook on owner/name, following the Link header to exhaustion, returning each hook's id, delivery url, events and active flag. |
delete_github_webhook |
Deletes the webhook hook_id from owner/name; succeeds only on GitHub's 204, otherwise raises. |
The signing secret is the caller's
GitHub does not mint the webhook secret — create_github_webhook sends the secret the
caller supplies, GitHub keys each delivery's X-Hub-Signature-256 with it, and the caller
keeps its own copy for the verifier that authenticates inbound deliveries. GitHub never
returns the secret on create or list, and these tools never echo it: it appears in no
return value and in no raised message.
Error model
Every non-2xx GitHub response raises loudly with the status and body — create and list
require a 2xx, delete requires exactly 204. Nothing is caught or remapped to success,
and no raised message ever contains the token or the caller's secret. Redirects are not
followed: a 3xx off the pinned host would replay the Authorization header to another
origin, so it surfaces as its own status instead.
Configuration
| Setting | Env var | Default | Purpose |
|---|---|---|---|
| Token | TOOLS_GITHUB_TOKEN |
— | The GitHub token (Authorization: Bearer). Required. |
| API base | TOOLS_GITHUB_API_BASE |
https://api.github.com |
GitHub REST base. Privileged — receives the Authorization header. |
| Request timeout | TOOLS_GITHUB_REQUEST_TIMEOUT_SECONDS |
20 |
Per-request timeout. |
The token needs the scope GitHub requires to administer repository webhooks
(admin:repo_hook on a classic token, or repository Webhooks read/write on a
fine-grained token). Secrets live only in the environment. A missing or empty token raises
loudly (fails closed) — never a silently-unauthenticated request.
Development
uv venv --python 3.13
uv pip install --no-sources --extra dev --editable .
uv run --no-sync pytest --cov --cov-report=term-missing
uv run --no-sync ruff check .
uv run --no-sync ruff format --check .
uv run --no-sync pyright
License
Apache-2.0. See LICENSE and NOTICE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file tai42_tools_github-0.1.0.tar.gz.
File metadata
- Download URL: tai42_tools_github-0.1.0.tar.gz
- Upload date:
- Size: 16.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
13ea372c8d1261058635a6fc9432823cfed50aac969d9776cb07e2fa23f73b27
|
|
| MD5 |
459dc05a49cf095c72539db01632c39d
|
|
| BLAKE2b-256 |
a1a2121de73f42cf319684d422cf04ae0be2478b13cc6677567ae3ec94b0ac9f
|
File details
Details for the file tai42_tools_github-0.1.0-py3-none-any.whl.
File metadata
- Download URL: tai42_tools_github-0.1.0-py3-none-any.whl
- Upload date:
- Size: 18.4 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c778c8d86068a3a10915b60a9e23c0fbac469f8867b5813e4003a1261540fc10
|
|
| MD5 |
e603383bba151facb74de6437ef33255
|
|
| BLAKE2b-256 |
c2bc7523e7451a0633a8b80d9655b2ecfc0e7663d70fc7f8a3c1ef9f18c2ad3a
|