Skip to main content
GitHub is a code-repository data source. Flint AI scans your repository’s source for AI agents and reports the models, tools, and MCP servers behind them, along with any security issues it finds. The scan runs as a GitHub Action inside your own workflow, so there is no credential to store in Flint AI. You authenticate the Action with a Flint AI API key. To open this page, go to Settings, then Data sources, select GitHub, and open the Setup tab.

Connect a repository

1

Get your credentials

You need two values: your Flint AI instance URL and a Flint AI API token.
  • Instance URL. The Setup tab shows the exact URL to use. Copy it from there.
  • API token. Use an existing token, or create one now if you don’t have one. Tokens are managed under Settings, then API Keys, and the Setup tab has a Create one now shortcut.
2

Install the GitHub Action

Install flintai-codescan-action from the GitHub Marketplace and add it to a workflow in your repository. A minimal job looks like this:
For a complete workflow file with triggers and checkout, see Discover your agents.
3

Store your token as a GitHub secret

In your repository or organization settings, go to Secrets and variables, then Actions, and add a secret named FLINTAI_TOKEN with the token from the first step.Scanning more than one repository? Define this secret at the organization level so it is shared across repositories. Only the token needs to be a secret. Your instance URL is not sensitive, so pass it to the action’s flintai_instance input as a plain value.
GitHub never passes a secret to an action on its own. In your workflow file, pass FLINTAI_TOKEN explicitly to the action’s flintai_token input.
4

Enable LLM-based scanning

The scanner calls an LLM from the action to analyze your code, so this step is required.
  • Add your LLM provider’s API key as a GitHub secret named LLM_API_KEY, then reference it from the action’s llm_api_key input.
  • Choose the model with the llm_model input, in provider:model form.
Supported providers are OpenAI, Google (Gemini), and Anthropic.
Once the workflow runs and reports its first scan, the GitHub card reads Connected.

The Scans tab

Open the Scans tab to see each connected repository with the time of its most recent scan. A fresh timestamp means results arrived.
Check the Scans tab, not the Connected status, to confirm results are landing. The card status does not yet reflect a live connection check, so it can read Connected before your first scan has run.

Next steps

Discover your agents

Set up a repository scan end to end, from workflow file to first results

Read your discovery results

Work out what needs attention first, whether a finding is real, and when it’s resolved