approvedcompleteAGPL-3.0

Tenants: OAuth login + per-org GitHub App installation

004-tenants-github-app

The tenancy spine of milestone M2: a user authenticates against the control plane (embedded rauthy, chassis auth), creates a tenant, and installs the statecraft GitHub App into their own GitHub org; from then on everything the platform does for them keys off the installation_id and happens inside their org. Nobody joins our org; code sovereignty is the product's first-class property. This spec owns the tenants service: tenant + installation records on CoreLedger, the App installation handshake, webhook receipt, and an installation-token mint helper the factory (spec 005) consumes.

Establishes
  • backend/tenants/ (directory)
Sections
  • 004: Tenants + GitHub App
  • 1. Operator prerequisites (SATISFIED 2026-07-14: the App exists)
  • 2. Territory
  • 3. Behavior
  • 4. Acceptance
  • 5. Out of scope
Source
specs/004-tenants-github-app/spec.md @ f136bf323cecas of 2026-07-21 ยท shard bd78c752411a