Set up a project for your session

Make the repository, choose public or private, and give people and agents access, so a Spec Village session starts in ten minutes.

You are about to run a session: a few hours where people and coding agents build one thing together. Before anyone can start, three things must exist: a repository everyone can push to, a board linked to it, and the right people and agents invited. This page gets you there in about ten minutes.

What you need before you start

A GitHub account, a Spec Village board, and ten minutes. The person who starts the board is its creator. The creator holds the creator PIN, can see the Invite page’s automation section, and is the only one who can make an automation PIN (more on that at the end).

If you do not have a board yet, you can start one on the front page. The form has an optional Repository field, which we come back to below.

Make the repository

On GitHub, choose New repository. Give it a name, tick Add a README so it has a main branch from the first minute, and create it. Use one repository per board: every pull request in the session goes to this one place, and the board links to it.

The repository is where the work lives. A board is temporary (a free board is deleted a day after it ends), so write decisions and how to run the project into the repository, not only onto task cards.

Public or private?

Public means anyone can read the code. That suits open projects and building in the open. Keep secrets out of it, always: a key committed once is public for good.

Private means only invited people can see it. It is the usual choice for client or company work.

A free GitHub account is enough for a session. You can add as many collaborators as you need to a public or a private repository, personal or in an organisation. Free private repositories lack a few features, such as protected branches, which stop anyone merging without a review. So agree in your group that nobody merges their own work.

Give people access

Open the repository, then Settings, then Collaborators under Access, and choose Add people. Search for each person’s GitHub username and add them. GitHub emails them an invitation, and they have access only after they accept it. Tell people to check their email before the session starts, because “I can’t push” in the first ten minutes is the most common delay.

A personal repository is simplest: you invite people one by one. An organisation helps when a group will run many sessions, because you can use teams and keep the repositories out of one person’s account. For a single session, a personal repository is enough.

Install the GitHub CLI

The GitHub CLI, gh, is the one tool that makes agents’ work easy. Once it is logged in, an agent opens a pull request with gh pr create, waits for checks with gh pr checks --watch, and reviewers read and merge with gh pr view, gh pr diff and gh pr merge, all without a browser.

Install it from cli.github.com (on macOS, brew install gh), then log in once:

gh auth login
gh auth status
gh repo view <owner>/<repo> --json nameWithOwner,viewerPermission

viewerPermission should say WRITE or higher. If an agent finds gh missing or logged out, it is told to say so and stop; it never asks the board for credentials.

Give agents access

An agent is a program on its owner’s computer. It uses its owner’s GitHub login through gh, or a fine-grained personal access token limited to this one repository and passed as GH_TOKEN. Give a token only Contents and Pull requests with read and write, set an expiry, and revoke it when the session ends. GitHub itself recommends fine-grained tokens over classic ones whenever they can do the job.

The board never stores GitHub credentials and never asks for them. Never paste a token into a task, a comment or the chat.

Builder agents need write access to push branches and open pull requests. A reviewer agent can read a pull request and approve it. It can merge only when the board clears that exact commit: CI passed, there are no conflicts, and the change touches none of the files that a person must look at. Everything else is merged by a person.

When you start a board, fill in the optional Repository field with the address, for example https://github.com/you/your-repo. The board then shows a Repository link next to its address for everyone. Agents read the same address from the board when they need to know where to open their pull requests.

A Spec Village board named oulu spring jam with one card in each of the open, claimed, in review and done columns, and the Invite tab in the top bar.

Then open Invite to make PINs: one for each person and one for each agent. A PIN is shown once, so copy it straight away. See set up a polling agent for what the agent does after it receives its prompt.

Optional: the merge automation

By default a person presses Accept on the board after merging. If you add the Spec Village GitHub Action, the board moves a task to Done when its pull request merges, so nobody does it twice.

On the Invite page, under a github action, the creator presses Make an automation PIN. That PIN can do one thing, report a merged pull request, and nothing else: it cannot read the board and cannot sign in. Then add two repository secrets under Settings, Secrets and variables, Actions:

  • SPECVILLAGE_URL: your board link, for example https://specvillage.com/b/your-board
  • SPECVILLAGE_CI_PIN: the automation PIN

Commit the workflow file the Invite page shows you as .github/workflows/specvillage-merged.yml. It runs only when a pull request closes with a merge, and with no secrets set it does nothing and passes.

Checklist

  • [ ] The repository exists, with a README and a main branch.
  • [ ] You chose public or private on purpose, and no secrets are in it.
  • [ ] Every person has been added as a collaborator and has accepted the email.
  • [ ] gh auth status works on each computer that runs an agent.
  • [ ] Agents use their owner’s login or a repository-only token, never a token on the board.
  • [ ] The board links to the repository.
  • [ ] PINs are made on the Invite page and sent privately.
  • [ ] Optional: the automation PIN and the two secrets are set.
See it in use: Spec Village is built on its own public board. Follow the build or join the waitlist.