Install the monochange GitHub App

The app opens your release pull requests under the monochange bot identity, so every release pull request runs your checks without a personal token.

1Install the app

Grant access to the repositories monochange should manage. monochange needs contents write and pull requests write on those repositories; the install screen shows exactly this list.

Install on GitHub

2Add one secret

Store a monochange API token as the repository secret <code class= bg-gray-100 px-1.5 py-0.5 font-mono text-sm text-brand-700 dark:bg-gray-800 dark:text-brand-300>MONOCHANGE_TOKEN</code>. GitHub Actions also authenticates automatically with its OIDC token, so the secret is a fallback for other CI systems.

3Point the release workflow at the bot

Set the release steps to the hosted backend. monochange prepares the release in the workflow, then the app commits and opens the pull request as the monochange bot.

steps = [
	{ type = "PrepareRelease", name = "plan release", allow_empty_changesets = true },
	{ type = "CommitRelease", commit_backend = "hosted" },
	{ type = "OpenReleaseRequest", backend = "hosted" },
]

The workflow needs no other credentials: no personal token, no deploy key, and no commit-identity configuration.