Auth monitoring is covered in [Authentication](/gateway/authentication). The scripts under `scripts/` are optional extras for systemd/Termux phone workflows.
Use `scripts/gh-read` when you want `gh` to use a GitHub App installation token for repo-scoped read calls while leaving normal `gh` on your personal login for write actions.
Required env:
-`OPENCLAW_GH_READ_APP_ID`
-`OPENCLAW_GH_READ_PRIVATE_KEY_FILE`
Optional env:
-`OPENCLAW_GH_READ_INSTALLATION_ID` when you want to skip repo-based installation lookup
-`OPENCLAW_GH_READ_PERMISSIONS` as a comma-separated override for the read permission subset to request
Repo resolution order:
-`gh ... -R owner/repo`
-`GH_REPO`
-`git remote origin`
Examples:
-`scripts/gh-read pr view 123`
-`scripts/gh-read run list -R openclaw/openclaw`
-`scripts/gh-read api repos/openclaw/openclaw/pulls/123`