Choose how the data reaches us
CostGraph pulls it
You supply a read-only token and we call GitHub once a day. Nothing to run.
You push it
You send us FOCUS records over the API. Credentials never leave your infrastructure.
Before you begin
- Create a token that reads the organization’s billing. A fine-grained personal access
token needs the organization permission Administration: read, plus Copilot:
read for per-seat data. A classic token needs
repo,read:org, andcopilot. Create a classic token with the scopes prefilled. - If the organization enforces SAML single sign-on, authorize the token for that organization. An unauthorized token returns 403.
- Note the organization login.
Let CostGraph pull
- Open Settings > Integrations and pick GitHub.
- Name the connection, pick the tenant these charges belong to, and enter the organization login whose billing you want.
- Enter the token.
- Select Connect.
Credentials are encrypted at rest and used only to read billing data. Revoke the token
in GitHub at any time and the connection stops; nothing else is affected.
Push it yourself
Send the charges to CostGraph as FOCUS records instead. Push FOCUS data covers the connection id, thefocus:write key, and the request shape.
Run the exporter
Rather than build that request yourself, run our exporter. It reads GitHub on a schedule and pushes the records for you, wherever you want to run it: a container, a KubernetesCronJob, or a binary on a machine you already have.