GitHub
Connecting a GitHub repository wires a project to your repo. Deploys run in your own GitHub Actions, through prisma/cloud-deploy-action; the connection provides two things around them:
- Credentials. Workflow runs in the connected repository exchange their GitHub OIDC token for a short-lived Prisma workspace token, so the deploy workflow needs no secrets.
- Branch lifecycle. Branch events keep the matching platform branches in sync, including tearing a preview down when its Git branch is deleted.
For the full setup, from connection to a live preview per branch, follow Deploy on push.
The connection has two levels:
How deploy on push works: a GitHub connection plus a deploy workflowStep 1 of 3
The connection has two levels. First, your workspace installs the Prisma GitHub App once. That installation is what lets Prisma see your repositories.
The workspace owns the GitHub App installation; each project points at a single repository. Once connected, Prisma verifies the repository identity behind each credential exchange and listens for the repo's branch events.
You can connect through the Console or from the CLI. The Console also opens a pull request that adds the deploy workflow to the repository. The CLI sets up the connection only, and you add the workflow yourself.
From a linked project directory, connect your Git origin:
bunx prisma git connectpnpm prisma git connectyarn prisma git connectnpx prisma git connectTo name the repository explicitly:
bunx prisma git connect https://github.com/acme/shoppnpm prisma git connect https://github.com/acme/shopyarn prisma git connect https://github.com/acme/shopnpx prisma git connect https://github.com/acme/shopIf the GitHub App isn't installed yet, the CLI opens the browser to finish the install. The command needs an interactive terminal: it waits for the install to complete, and --no-interactive fails with CLI.INTERACTION_REQUIRED. For headless setups, connect through the Console instead.
Disconnect when you're done:
If the GitHub App isn't installed yet, the CLI opens the browser to finish the install. The command needs an interactive terminal: it waits for the install to complete, and --no-interactive fails with CLI.INTERACTION_REQUIRED. For headless setups, connect through the Console instead.
Disconnect when you're done:
bunx prisma git disconnectpnpm prisma git disconnectyarn prisma git disconnectnpx prisma git disconnectDisconnecting stops the credential exchange and the branch automation. It doesn't delete the project or tear down existing branches.
Disconnecting stops the credential exchange and the branch automation. It doesn't delete the project or tear down existing branches.
Once a project is connected:
- Actions runs can authenticate. A workflow job with
id-token: writegets a workspace token through the OIDC exchange. The token is valid for 30 minutes and is only issued for the connected repository; unconnected repositories and forks are refused, and the deploy action then skips with a green run. - Branch created → creates the matching platform branch.
- Branch deleted → tears down the matching platform branch and its resources. Your production and default branches are exempt from this cleanup.
Pushes are not handled by the platform. Your repository's own workflow deploys them, so a connected repo without a deploy workflow deploys nothing. Connecting also doesn't create branches retroactively: it aligns your default branch with the repo's default branch and wires up automation for future events.
GitHub is the only supported provider; others return REPO_PROVIDER_UNSUPPORTED. Pull-request comments and preview comments aren't currently supported.
- Deploy on push: the full walkthrough, from connection to per-branch previews.
- Branching: how platform branches map to Git.
- Environment variables: per-branch config for previews.