Authentication & GitHub · Contents
Authentication & GitHub

Signing in with GitHub

Breaklytix uses GitHub OAuth for authentication. No passwords, no tokens stored in our database.

Breaklytix authenticates exclusively through GitHub OAuth. When you sign in: GitHub returns your public profile, email, and a short-lived token. Breaklytix encrypts that token (Fernet) and stores it so background scans can read your repositories.

  • Scopes requested: read:user, user:email, public_repo. All are read-only.
  • Your GitHub access token is encrypted before storage; it is never returned to the browser.
  • You can disconnect GitHub from Settings -> General at any time.
TipIf your email is private or unverified on GitHub, sign-in will prompt you to verify it — a verified email is required so alerts can reach you.
Related articles
Connecting and disconnecting GitHubSecurity model & privacy