your work, shown live.

Your founders page can show the repositories behind your work: their stars, the languages they are written in, a preview of each README and the latest release, updated every time someone visits. For that, your site needs permission to read your GitHub. You give it with a GitHub App: a small app that you create in your own GitHub account, that only reads the repositories you choose, and that you can remove at any time.

Your site shows
Stars, forks and watchers
Read from
Each repository you install the app on
  • It is your app — you create it, it lives in your GitHub account, and nobody else has its keys
  • It can only read — this step gives it no permission to change anything
  • It sees only what you pick — repositories you do not choose stay invisible to it
  • Without it, nothing breaks — your founders page still shows everything else

this is a work in progress

  1. Create.

    A read-only app of your own.

  • Success.your founders page shows live stars and languages.

  • Your GitHub account — from GitHub
  • Your GitHub name in your identity — the github line from Your identity must be the account or organization you install the app on. Your founders page only shows repositories it owns
  • Your site on Vercel — from Deploy

1️⃣ Create Your App

Create it where your repositories live. For your own account, click your picture in GitHub, then Settings → Developer settings → GitHub Apps → New GitHub App. For an organization, open the organization's Settings, then Developer settings → GitHub Apps → New GitHub App.

  1. GitHub App name: anything no one else on GitHub has used, like yourname-site
  2. Homepage URL: your site's address
  3. Under Webhook, uncheck Active. This step does not need one
  4. Under Permissions → Repository permissions, set Contents to Read-only. Metadata turns to Read-only by itself
  5. Under Where can this GitHub App be installed?, choose Only on this account
  6. Click Create GitHub App

You land on your app's settings page. Write down the App ID near the top. Then scroll to Private keys and click Generate a private key. Your browser downloads a file ending in .pem. It is the app's password: keep it safe, and never send it to anyone.

2️⃣ Install It on the Repos You Choose

  1. On your app's settings page, click Install App in the left menu
  2. Click Install next to your account or organization
  3. Choose Only select repositories and pick the ones you want on your founders page
  4. Click Install
  5. Look at the address bar. It ends in a number, like /installations/12345678. That number is your installation ID

To show another repository later, open the same installation page, add it, and save. You do not need new keys.

3️⃣ Add the Three Keys

On your computer, move the .pem file into your project folder. Git leaves every .pem file out, so it never reaches GitHub. Then add three lines to .env:

bash
# .env
GITHUB_APP_ID="123456"
GITHUB_APP_INSTALLATION_ID="12345678"
GITHUB_APP_PRIVATE_KEY_PATH="./yourname-site.2026-10-05.private-key.pem"

Your live site has no file, so on Vercel the key goes in as text. Open your project's Settings → Environment Variables and add GITHUB_APP_ID and GITHUB_APP_INSTALLATION_ID with the same numbers. Then add GITHUB_APP_PRIVATE_KEY: open the .pem file in your editor, copy everything in it, from the first dash to the last, and paste it as the value. Redeploy.

If you use the Vercel command line, it can read the key straight from the file, so nothing gets lost in copying:

bash
vercel env add GITHUB_APP_ID production
vercel env add GITHUB_APP_INSTALLATION_ID production
vercel env add GITHUB_APP_PRIVATE_KEY production < yourname-site.2026-10-05.private-key.pem

Open your founders page. Your repositories now show their stars, languages and README previews. The first visit takes a little longer while your site reads GitHub; after that it remembers what it read for an hour.

🐙 Later: More Your App Can Do

The same app can do two more things, each only if you give it one more permission. Change permissions on your app's settings page under Permissions & events, then accept the change on the installation page.

To
Review your waitlist in GitHub
Add
Discussions: Read and write
Then
Follow the GitHub part of Let people in

Daily snapshots are small data files your site saves to its own repository every morning, each as a pull request. Without write access, those daily jobs log an error and stop there. Nothing on your site changes.

⚠️ Good to Know

  • The private key is the app — anyone with the .pem file can act as your app. If you ever share it by mistake, delete it under Private keys, generate a new one and replace it in .env and Vercel
  • Private repositories stay private — the app reads them, and your founders page shows what you installed it on, so pick only what you are happy to show
  • You can switch it off any time — uninstall the app, or delete it, and your site goes back to how it was

🧯 If Something Is Off

  • Founders page shows no live numbers — check the github line in FoundersConfig.json matches the account you installed on
  • GitHub App not configured — one of the three keys is missing where you tested. Restart npm run dev, or redeploy after adding it on Vercel
  • No repositories found — the app is installed on no repositories, or the installation ID belongs to a different installation. Open the installation page and check both
  • A key error in your logs — the key lost its line breaks. On Vercel, paste the .pem contents again exactly, or use the command line above
  • A repository is missing — add it on the installation page. Your site remembers its list for an hour, so give it time

🤖 Ask Your LLM

prompt
I am creating a GitHub App so my website can read my repositories.
I am on this GitHub screen: [describe it or paste the text].
Walk me through what to fill in. It should only be able to read.

Which of my repositories should I show on my founders page? Here
is what each one is: [list them]. I want to show [say what].

✅ You Are Done When

  • A GitHub App of your own exists, with Contents set to Read-only
  • It is installed on the repositories you want to show
  • .env and Vercel both have GITHUB_APP_ID, GITHUB_APP_INSTALLATION_ID and the private key
  • Your founders page shows live stars and languages for those repositories

Your founders page now shows the real work, as it changes, from an app only you control. Next, a Slack message for every worksheet, with Slack.

“Show the work. Keep the keys.”

— unparty-app
#GitHub#GitHub App#Repositories#Setup#Non-Technical Founders#Software You Own

🧗🏾‍♂️ in progress

THOUGHTS.

…