pull, push, triage, maintain, or admin). Dodo Payments sends the collaborator invitation and removes the collaborator when the grant is revoked.What Gets Delivered
- The customer connects their GitHub account from the Customer Portal. This links their GitHub account to the purchase.
- Dodo Payments invites that account to your repository at the configured permission level. The customer gets access after they accept the invitation on GitHub. If the customer owns the repository, no invitation is needed.
- Cancellation, refund, or a manual revoke removes the collaborator and cancels any pending invitation.
Connect GitHub
Open Entitlements
Pick GitHub

Connect GitHub prompt before the install handoff.

GitHub Install & Authorize page. Choose which repositories the app can manage.

Account connected. Return to the Dodo Payments dashboard to continue.
Pick a Repository and Permission

Creating a GitHub entitlement. Pick the repository and the permission you want customers to receive.
Attach It to a Product
Permission Levels
The entitlement uses GitHub’s standard repository permissions:Customer Flow
- The customer completes checkout.
- Dodo Payments creates a grant in
Pendingstatus. Dodo Payments tries to create a GitHub authorization URL right away and stores it inoauth_url. If that fails,oauth_urlstaysnulluntil the customer starts the accept flow. - The payment confirmation email lists the entitlement as Action Required and links to the Customer Portal. In the portal, the customer clicks Connect and authorizes with GitHub. An authorization link expires after 30 minutes, and the Customer Portal generates a new one when the customer returns.
- Dodo Payments invites the customer’s GitHub account to the repository at the configured permission. The grant moves to
Deliveredonce the invitation is created. If GitHub rejects the invitation, the grant isn’t delivered. - If the subscription is cancelled, the payment is refunded, or the grant is revoked, Dodo Payments removes the customer as a collaborator and cancels any pending invitation.
Required Configuration
Create via API
Webhooks
The standardentitlement_grant.* webhook events cover the GitHub flow:
entitlement_grant.createdfires withstatus: "Pending".oauth_urlmay already hold the GitHub authorization URL. If it isnull, it is populated once the customer starts the accept flow from the Customer Portal.entitlement_grant.deliveredfires once the collaborator invitation is created.entitlement_grant.revokedfires when access is withdrawn. If you uninstall the GitHub App, Dodo Payments revokes that installation’s pending and delivered grants withrevocation_reason: platform_external.entitlement_grant.failedfires witherror_code: "GRANT_ACCESS_FAILED"if Dodo Payments can’t add the customer to the repository, for example because the GitHub App lost access to it.
Troubleshooting
Repository picker is empty
Repository picker is empty
Grant fails with a permission error
Grant fails with a permission error
Customer hasn't accepted the invite
Customer hasn't accepted the invite
Delivered in Dodo Payments, because the invitation is what Dodo Payments issues.