GitHub
A GitHub organization that answers REST v3, GraphQL v4, Git smart HTTP reads and webhooks, plus the GitHub MCP server's tools.
Vendor reference: https://docs.github.com/rest ↗. Machine-readable: compat/github.json.
Surfaces
| Kind | Path | Notes |
|---|---|---|
| REST | / | REST API v3 (repos, contents, git data, issues, pulls, releases, search, Actions, checks) |
| GraphQL | /graphql | GraphQL API v4 |
| Git | /<owner>/<name>.git | smart HTTP clone and fetch, read-only |
| Webhooks | repository and organization hooks | event deliveries to your endpoint |
| MCP | /mcp | Streamable HTTP, the github-mcp-server tool set |
API versions: REST API v3, GraphQL API v4
Supported
- Repositories, contents, trees, blobs, refs, commits and statuses
- Issues, comments, labels, pull requests, reviews and merges
- Releases, tags, gists, notifications, starring, event feeds,
/emojisand/meta - GitHub's error envelopes (
{message, documentation_url, status}) andRetry-Afteron throttled calls - PyGithub and Octokit REST calls, per the consumer coverage matrix
- Security alerts, advisories and the Actions writes
Not supported
- Pushing over Git; change content through the Contents and Git Data APIs
- Classic REST projects, repository discussions over REST, and packages (GitHub's 404 envelope)
Known differences and test guidance
| Scenario | Difference from GitHub | In your tests |
|---|---|---|
| GitHub Actions | Workflows do not execute; runs, jobs, logs and artifacts are derived from commit history, and every fourth run fails. | Do not assert on what a workflow did; assert that your client reads runs, jobs and logs. |
| Merging a pull request | The merge flips state and mints a merge sha; there is no three-way merge or conflict detection, and mergeable is stored, not computed. | Do not test merge conflicts against the replica. |
| Checks | Checks are green unless the run is one of the seeded failures. | Do not expect checks to react to your commits. |
| Search | A qualifier parser over the stored data; relevance ordering, best-match scoring and code-search tokenization differ. | Assert that the expected item is found, not on rank. |
| Branch protection | The default branch reports a protection object, but nothing enforces it. | Do not assert that a push or merge to a protected branch is refused. |
| Rate limits | /rate_limit is static; real throttling only comes from fault injection. | Inject throttle or quota_limit to test backoff. |
Fault injection
| Key | What the client sees |
|---|---|
throttle | 403 "API rate limit exceeded" with Retry-After and X-RateLimit-Remaining 0, GitHub's primary limit |
fail_next | The next N calls fail as throttle does, then clear |
quota_limit | 429 with the secondary-rate-limit message and Retry-After |
error_rate | 500 "Server Error" for the given fraction of calls |
latency_ms | Fixed added latency on every data-plane request |
Applies to every system
- The hosted data plane is read-only: a write is refused with
403 writes_disabled. A SOQL, GraphQL or searchPOSTis a read and is answered. - Faults are injected through
POST /_admin/faultson a simulator you run yourself;POST /_admin/faults/resetclears them. - Rate limits do not happen on their own unless a page says so. Use fault injection to exercise a client's backoff.
- Distributions come from aggregated metadata sketches of data Eon backs up; no customer records; all Era data is simulated.