At a glance
What other tools ask for
We read the public permission lists of 37 GitHub Apps in four categories. Each column shows how many apps in that category request the permission at the same access level as Peeps, or higher.
The last six rows are less common because few tools test deploys, run in merge queues or set up CI for you. Each is explained below.
Counts come from GitHub’s public app records for each tool, read in September 2026. They show what each app requests, which can differ from what a given installation has accepted.
Your code and pull requests
Your CI
Peeps does not request Secrets. Your CI keeps its own secrets, and Peeps runs authenticate with GitHub’s OIDC tokens, so no Peeps key is ever stored in your repository.
Your deploys
Your people
What Peeps does not request
- Secrets. Peeps can’t read, create or overwrite your repository or organization secrets.
- Administration. Peeps can’t change repository settings, branch protection or rulesets.
- Organization write. Peeps can’t add or remove members, teams or roles.
- Security alerts. Peeps doesn’t read code scanning, secret scanning or Dependabot alerts.
Questions about a permission? Get in touch.