> ## Documentation Index
> Fetch the complete documentation index at: https://docs.switchagents.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs moved from docs.flintai.dev to docs.switchagents.ai. Use docs.switchagents.ai for every link and request.
> To search these docs from an AI tool, connect the MCP server at https://docs.switchagents.ai/mcp. The page index is at https://docs.switchagents.ai/llms.txt.

# GitHub

> Scan a GitHub repository for agents and add them to your inventory

GitHub is a code-repository data source. Switch Trust scans your repository's source for AI
agents and reports the models, tools, and MCP servers behind them, along with any security
issues it finds. The scan runs as a GitHub Action inside your own workflow, so there is no
credential to store in Switch Trust. You authenticate the Action with a Switch Trust API key.

To open this page, go to **Settings**, then **Data sources**, select **GitHub**, and open the
**Setup** tab.

## Connect a repository

<Steps>
  <Step title="Get your credentials">
    You need two values: your Switch Trust instance URL and a Switch Trust API token.

    * **Instance URL.** The **Setup** tab shows the exact URL to use. Copy it from there.
    * **API token.** Use an existing token, or create one now if you don't have one. Tokens are
      managed under **Settings**, then **API Keys**, and the **Setup** tab has a
      **Create one now** shortcut.
  </Step>

  <Step title="Install the GitHub Action">
    Install [`flintai-codescan-action`](https://github.com/sandbox-quantum/flintai-codescan-action)
    from the GitHub Marketplace and add it to a workflow in your repository. A minimal job looks
    like this:

    ```yaml theme={null}
    - name: Run Flint AI inventory scan
      uses: sandbox-quantum/flintai-codescan-action@v5
      with:
        flintai_instance: https://app.flintai.dev   # use the URL from your Setup tab
        flintai_token: ${{ secrets.FLINTAI_TOKEN }}
        llm_model: google:gemini-3.5-flash
        llm_api_key: ${{ secrets.LLM_API_KEY }}
    ```

    For a complete workflow file with triggers and checkout, see
    [Discover your agents](/switch-trust/getting-started/discover).
  </Step>

  <Step title="Store your token as a GitHub secret">
    In your repository or organization settings, go to **Secrets and variables**, then
    **Actions**, and add a secret named `FLINTAI_TOKEN` with the token from the first step.

    Scanning more than one repository? Define this secret at the organization level so it is
    shared across repositories. Only the token needs to be a secret. Your instance URL is not
    sensitive, so pass it to the action's `flintai_instance` input as a plain value.

    <Tip>
      GitHub never passes a secret to an action on its own. In your workflow file, pass
      `FLINTAI_TOKEN` explicitly to the action's `flintai_token` input.
    </Tip>
  </Step>

  <Step title="Enable LLM-based scanning">
    The scanner calls an LLM from the action to analyze your code, so this step is required.

    * Add your LLM provider's API key as a GitHub secret named `LLM_API_KEY`, then reference it
      from the action's `llm_api_key` input.
    * Choose the model with the `llm_model` input, in `provider:model` form.

    Supported providers are OpenAI, Google (Gemini), and Anthropic.
  </Step>
</Steps>

Once the workflow runs and reports its first scan, the **GitHub** card reads **Connected**.

## The Scans tab

Open the **Scans** tab to see each connected repository with the time of its most recent
scan. A fresh timestamp means results arrived.

<Warning>
  Check the **Scans** tab, not the **Connected** status, to confirm results are landing. The
  card status does not yet reflect a live connection check, so it can read **Connected** before
  your first scan has run.
</Warning>

## Next steps

<CardGroup cols={2}>
  <Card title="Discover your agents" icon="radar" href="/switch-trust/getting-started/discover">
    Set up a repository scan end to end, from workflow file to first results
  </Card>

  <Card title="Read your discovery results" icon="triangle-exclamation" href="/switch-trust/discovery/results">
    Work out what needs attention first, whether a finding is real, and when it's resolved
  </Card>
</CardGroup>
