> For the complete documentation index, see [llms.txt](https://docs.pullrequest.com/on-premise-server/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pullrequest.com/on-premise-server/configure-posting-user/configure-github-posting-user.md).

# Configure GitHub Posting User

The service interfaces with users in GitHub projects through a "HackerOne" member of your GitHub team. So a GitHub user must be created and configured as a Posting or Service user.

## Prerequisites

The GitHub posting user must be created by an individual on your team with the following administrative permissions:

* [ ] A HackerOne Code user account with an Owner role for the organization in question.
* [ ] An Owner role on your GitHub Enterprise Group.

### Create Posting User

Log in to your GitHub instance as an administrator and create a new user with the username **HackerOne** or **PullRequest**. HackerOne Code will use this user to post scan results and validated issues.

<mark style="background-color:yellow;">**\*\*\*We strongly recommend adding the following image as the posting user's avatar**</mark>. This provides a much better end-user experience; it allows the service to be easily identified in the GitHub interface:

{% file src="/files/OBk998HAFQRbqiafYMOH" %}

### Add Posting User to Projects

Add the posting or services user you created for HackerOne Code to all of the organizations/repositories you want code review on. Be sure to grant the user **WRITE** access so it's able to list repository collaborators and post comments.

{% hint style="success" %}
Read more about the permissions HackerOne Code requires and how we use them [**here**](https://docs.pullrequest.com/customer-documentation/cloud-integrations/adding-github-repositories#required-permissions)**.**
{% endhint %}

### Create GitHub Access Token

Log into GitHub as the HackerOne Code user you just created.

{% hint style="info" %}
This may be easier in another browser or in an incognito tab so you can remain logged in as the GitHub owner user.
{% endhint %}

Open **Settings** -> **Developer settings** -> **Personal access tokens**. This should be accessible from the following path using your own instance's domain instead of `our-github.internal`:

```
https://our-github.internal/settings/tokens
```

Click **Generate new token** and create a Personal Access Token with the following properties:

* [ ] **Note**: For your team's internal use. No functionality is associated with this property.
* [ ] **Scopes**: The **repo** (all of them), **read:org**, **read:user**, **user:email**, and **write:discussion** scopes should all be checked.

![](https://624363444-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-LNMKNsDv2KL9GI5L5YY%2F-Ltf0dkACURo8FTBtRSX%2F-Ltf5LmgLAIpGu_Zw3Ny%2Fimage.png?alt=media\&token=5142a3b4-10ff-4463-bacf-11eb83dc40b8)

Once generated, copy the personal access token to your clipboard so we can configure the connection to GitHub.

### Connecting PullRequest Proxy to GitHub

Now, it's time to return to that text file we're editing on the proxy server. Go ahead and set the following keys based on what was configured above.

```
PROVIDER_TYPE=github
PROVIDER_BASE_URL=https://our-github.internal/api/v3
PROVIDER_USERNAME=PullRequest
PROVIDER_ACCESS_TOKEN=<access_token>
```

{% hint style="warning" %}
Make sure the **GitHub URL** represents the path to the version 3 of the GitHub API
{% endhint %}

{% hint style="warning" %}
Make sure the **HackerOne Code Posting User's username** is spelled exactly as the username of the user that was created. We highly recommend "HackerOne" (all one word, PascalCase) to maintain communication consistency.
{% endhint %}
