> ## Documentation Index
> Fetch the complete documentation index at: https://docs.peepsai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# GitHub App permissions

> What each permission the Peeps GitHub App requests is for, when Peeps uses it, and how many other developer tools ask for the same thing.

When you install the Peeps GitHub App, GitHub shows a list of permissions. This page explains each one: what Peeps does with it, when, and how common it is among other GitHub Apps for coding, code review and testing.

Peeps asks for everything it needs at install time. GitHub makes every installation re-approve an app that adds a permission later, so asking once means Peeps doesn't interrupt your organization's owners each time it gains a capability.

## At a glance

| Permission | Access | Peeps uses it to |
| - | - | - |
| **Contents** | Read and write | Read your tests, and push fixes and new tests to `peeps/*` branches |
| **Pull requests** | Read and write | Open a pull request for every fix and new test, and report results on yours |
| **Issues** | Read and write | Answer `/peeps` commands, and file bugs that failing tests uncover |
| **Checks** | Read and write | Post Peeps results as checks on your pull requests |
| **Commit statuses** | Read and write | Read results from CI outside GitHub Actions, and post Peeps results where your rules expect a status |
| **Actions** | Read and write | Start Peeps runs in your CI, cancel superseded ones, and read logs for failure analysis |
| **Workflows** | Read and write | Add and update the Peeps workflow file through a pull request |
| **Variables** | Read and write | Keep the Peeps workflow's settings in Actions variables, so you don't copy them by hand |
| **Deployments** | Read and write | Test each deploy as it lands, and hold production deploys until Peeps passes |
| **Environments** | Read | Find each environment's URL, so runs target the right one |
| **Merge queues** | Read | Run Peeps as a check in your merge queue |
| **Webhooks** | Read and write | Set up and rotate the deploy trigger that starts runs |
| **Metadata** | Read | Required by GitHub for every app |
| **Members** | Read | Route failures to the owning team, and limit who can run `/peeps` commands |
| **Email addresses** | Read | Match your GitHub account to your Peeps account when you sign in with GitHub |

## What other tools ask for

We read the public permission lists of 37 GitHub Apps in four categories. Each column shows how many apps in that category request the permission at the same access level as Peeps, or higher.

| Permission | Coding agents (9) | AI code review (9) | AI testing (7) | Testing and CI tools (12) |
| - | - | - | - | - |
| **Contents** (write) | 9 | 7 | 4 | 2 |
| **Pull requests** (write) | 9 | 9 | 7 | 9 |
| **Issues** (write) | 9 | 9 | 5 | 5 |
| **Checks** (write) | 6 | 6 | 6 | 7 |
| **Commit statuses** (write) | 3 | 5 | 2 | 9 |
| **Actions** (write) | 7 | 2 | 2 | 3 |
| **Workflows** (write) | 9 | 4 | 2 | 1 |
| **Metadata** (read) | 9 | 9 | 7 | 12 |
| **Members** (read) | 6 | 8 | 0 | 7 |
| **Email addresses** (read) | 6 | 5 | 2 | 6 |
| **Deployments** (write) | 0 | 0 | 1 | 1 |
| **Merge queues** (read) | 1 | 1 | 1 | 0 |
| **Webhooks** (write) | 1 | 0 | 1 | 0 |
| **Environments** (read) | 1 | 0 | 0 | 0 |
| **Variables** (write) | 0 | 0 | 0 | 0 |
| **Secrets** | 0 | 0 | 0 | 0 |

The last six rows are less common because few tools test deploys, run in merge queues or set up CI for you. Each is explained below.

<Info>
  Counts come from GitHub's public app records for each tool, read in September 2026. They show what each app requests, which can differ from what a given installation has accepted.
</Info>

## Your code and pull requests

| Permission | What Peeps does with it | When |
| - | - | - |
| **Contents** | Reads your test files, page objects and config at a commit, so Peeps sees your suite as it is. Pushes each fix or new test to its own `peeps/*` branch. | Reads on every push to a branch Peeps tracks. Writes when a fix or a new test is ready, or when you ask Peeps to push a change. |
| **Pull requests** | Opens a pull request for each fix or new test, with the evidence behind it. Comments run results on your pull requests. | When Peeps has a change for you to review, or finishes a run on your branch. |
| **Issues** | Reacts to and answers `/peeps` comments on issues and pull requests. Files an issue when a test fails because of a bug in your app. | When someone writes a `/peeps` comment, or a failure is traced to your app. |
| **Checks** | Posts runs as checks such as **Peeps / fix verification**, so results sit next to your other CI results. | On every Peeps run tied to a commit. |
| **Commit statuses** | Reads the statuses that Jenkins, CircleCI, Buildkite and some preview hosts post, so Peeps knows when your build is green and where a preview lives. Posts a Peeps status for branch rules that require one. | When a commit Peeps tracks gets a new status, and when a Peeps run finishes. |

## Your CI

| Permission | What Peeps does with it | When |
| - | - | - |
| **Actions** | Starts the Peeps workflow in your own CI, so tests run on your runners with your secrets. Cancels runs a newer commit has replaced. Reads job logs and artifacts to analyze failures. | When you or a trigger starts a run, and after every failed run. |
| **Workflows** | Adds `.github/workflows/peeps.yml` through a pull request when you set up a repository, and updates it when Peeps changes how runs work. GitHub requires this permission to change any file in `.github/workflows`, even on a branch. | At setup, and when the workflow needs an update. Every change is a pull request. |
| **Variables** | Stores the Peeps workflow's settings, such as the project, test root and base URLs, as Actions variables that the workflow reads. | At setup, and when you change those settings in Peeps. |
| **Merge queues** | Runs Peeps as a check on each merge queue entry, so a change is tested against everything ahead of it. | When a pull request enters a merge queue that requires Peeps. |

<Note>
  Peeps does not request **Secrets**. Your CI keeps its own secrets, and Peeps runs authenticate with GitHub's OIDC tokens, so no Peeps key is ever stored in your repository.
</Note>

## Your deploys

| Permission | What Peeps does with it | When |
| - | - | - |
| **Deployments** | Starts a run when a preview or staging deploy finishes. Acts as a deployment protection rule, so a production deploy waits until Peeps passes. Marks each deployment with its Peeps result. | On every deploy to an environment you connect to Peeps. |
| **Environments** | Reads each environment's URL and protection settings, so runs target the right environment. | When you connect an environment and at the start of each run. |
| **Webhooks** | Creates the webhook that tells Peeps a deploy finished, rotates its secret, and removes it when you disconnect. | When you turn on deploy triggers, rotate them or disconnect. |

## Your people

| Permission | What Peeps does with it | When |
| - | - | - |
| **Members** | Reads organization members and teams, so Peeps can route a failure to the team that owns the code and limit `/peeps` commands to the people you choose. | When a failure needs an owner, and on each `/peeps` command. |
| **Email addresses** | Reads the email on your GitHub account, so signing in with GitHub connects you to the right Peeps account. This is granted by each person when they sign in, not by the installation. | When you sign in to Peeps with GitHub. |

## What Peeps does not request

* **Secrets.** Peeps can't read, create or overwrite your repository or organization secrets.
* **Administration.** Peeps can't change repository settings, branch protection or rulesets.
* **Organization write.** Peeps can't add or remove members, teams or roles.
* **Security alerts.** Peeps doesn't read code scanning, secret scanning or Dependabot alerts.

To limit Peeps to specific repositories, choose **Only select repositories** when you [install the app](/github-app).

***

Questions about a permission? [Get in touch](mailto:support@peepsai.com).
