Skip to content

DL-305

The forge GitHub credential topology is TWO Apps: the primary App (the existing ForgeConfig.App) serves everything — all reads (board ingest + notify, unified per RIG-2991), all author writes, board, and webhooks — and a second reviewer App DEFINITION (own AppID + key, one installation, no webhook) serves only the submit_review arm, the F1 author-can’t-approve 422 workaround; a second install of one App is rejected (same bot login fails F1), as is a third write App. Enabling writes therefore requires the primary App and force-enables board ingestion — an accepted amendment to Matt’s 2026-08-19 independent-gates ruling (serve.go:150-151); reads and interactive writes knowingly share the one installation budget + client-side resetAt gate

Status: Active (Matt, 2026-08-31)

Record: ../../server/compass-forge-app-credentials/design.md