Skip to main content
GitHub repository access is available on the Pro plan. See Billing and plans.
Sell source code, a private SDK or a paid template? A GitHub Repository Access benefit invites each buyer to the repositories you pick, at the role you pick, and withdraws access when they refund or cancel.

One-time setup: install the GitHub App

Keyplar needs permission on your GitHub organization or account before it can send invitations.
1

Start the install from Keyplar

BenefitsNew benefitGitHub Repository Access. The repository picker offers an Install the GitHub App link.Starting from here matters — the install is bound to your store, so the picker later shows only your own repositories.
2

Choose where to install it

On GitHub, pick the organization or personal account holding the repositories you sell, and grant it access to those repositories. You can grant all, or select individually.
3

Come back and refresh

Return to the benefit. The picker now lists the repositories the App can reach.
Granting access to selected repositories rather than all of them is the safer default. You can add more later from GitHub’s app settings.

Configure the benefit

Add one row per repository. Each row takes a repository and a Role:
Anything above Read lets customers change your repository. Unless you’re deliberately running a paid collaboration, Read is what you want.
You can list several repositories on one benefit, each with its own role — a paid bundle of a main repo plus example projects, say.

What the customer sees

After buying, the invitation appears on their order and under Git repos in their portal. It isn’t sent automatically, because Keyplar doesn’t know their GitHub username until they say so. They enter their username and claim it. Keyplar then invites that account to every repository on the benefit, and GitHub emails them the invitation to accept.
Claiming is one-shot. The customer enters one GitHub username and it cannot be changed afterwards — the form says so before they submit. If someone claims with the wrong account, they need your help: revoke the grant and re-issue it.

Revoking access

Access is withdrawn automatically when:
  • The order is refunded
  • The subscription behind it is cancelled
  • The customer deletes their account
  • You delete the grant
Revocation reaches GitHub itself — the collaborator is removed from every repository on the benefit, and any invitation they hadn’t accepted yet is cancelled. It isn’t just hidden in the portal.

Troubleshooting

The GitHub App isn’t installed yet, or it’s installed without access to any repositories. Use the install link in the picker, and check on GitHub that the repositories you want are included in the installation.
Find their order under Orders, remove the grant, and let the benefit be re-granted — they can then claim again with the right account. Revoking removes the wrong account from the repository as part of the same step.
GitHub sends the invitation, not Keyplar. Ask them to check github.com/notifications — pending repository invitations are listed there, and on the repository page itself, even if the email went missing.