Signing in
Signing in is what turns ForkLeaf from a browser scratchpad into a notes app with a backup. This page covers what it asks GitHub for, what it uses that for, and how to take it back.
The permissions it asks for
One scope, and it is the one that lets ForkLeaf write your notes. There is no second permission bundled alongside it, so the consent screen has exactly one thing on it for you to weigh.
| Scope | What GitHub grants | Why ForkLeaf asks for it | What it does not do |
|---|---|---|---|
repo | Read and write access to your repositories, public and private | A note is a file. Opening one is a read, saving one is a commit, renaming one is a commit that deletes and adds — none of that is possible without write access, and private repositories need this scope specifically | It is never used to enumerate, read or modify anything but the repository you connect and the list of repository names the picker shows |
public_repo | The same, restricted to your public repositories | The alternative offered on the sign-in page, for notes that are going to be public anyway | It cannot open a private repository. GitHub refuses the request; ForkLeaf does not get the choice |
What it deliberately does not ask for
The consent screen used to carry a second block — Personal user data, “this application will be able to read your private profile information” — because the request included read:user. That was there to put your name and avatar in the sidebar, which turns out not to need it: GET /user returns your login, name and avatar to any authenticated token. The scope bought a warning about private profile access and nothing else, so it is gone.
read:user— not asked for. Your name and avatar come back with the token regardless; ForkLeaf never sees a private profile field, and does not read your email address at all.user:email— not asked for. Commits are attributed by GitHub from your own account settings, so ForkLeaf never needs your address.admin:org,delete_repo,workflow,admin:repo_hook— not asked for. ForkLeaf never creates a webhook, edits a workflow file, changes a repository setting or deletes a repository.gist,notifications— not asked for. It does not touch either.
repo scope’s own description on GitHub’s screen lists settings, webhooks and deploy keys among the things it could reach. That is GitHub describing the scope, not ForkLeaf describing itself: the scope is a single coarse grant and cannot be narrowed further as a classic OAuth app. Every request ForkLeaf makes goes through its own /api/gh/* routes, which are contents, tree, commit, branch and pull request endpoints — you can read the list in the source.repo is broader than anyone would like. It is the narrowest classic OAuth scope GitHub offers that still allows writing to a private repository — there is no “only this one repo” classic scope. If that is too much for your account, sign in with public-repository access only — or use ForkLeaf with no account at all, on this device.You are not made to take the wide one. Under the Continue with GitHub button, the sign-in page offers Public repositories only, which asks for public_repo instead — with it, ForkLeaf cannot open a private repository at all, because GitHub refuses the token rather than because we decline to try. Pick it if your notes are going to be public; you can sign in again with the wider permission whenever that changes, and nothing has to be redone.
Whichever you choose, ForkLeaf reads and writes exactly one repository — the one you connect — plus the list of repository names, so the picker has something to show. If a repository you can see on github.com is missing from that list, it is almost always one of two things: it is private and you granted public-only access, or it belongs to an organisation that has not approved ForkLeaf under Settings → Third-party Access. The dashboard says which, and what to do about it, rather than repeating GitHub’s “Not Found”.
Signing out
Sign out in the sidebar account menu deletes the session cookie. It does not revoke the token on GitHub’s side and it does not touch your repository. To revoke access entirely, go to GitHub → Settings → Applications → Authorized GitHub Apps and remove ForkLeaf. Revoking takes effect at once rather than at the end of the current eight-hour token: the next renewal is refused, and ForkLeaf ends the session where it finds out.
Notes in the On this device workspace stay in your browser after signing out; notes in a repository stay in the repository.