Installed, not authorised
Vorkhurry connects as a GitHub App that you install on specific repositories, rather than as an OAuth app holding a user's token or a personal access token holding everything.
The only thing stored is the installation id. Every call to GitHub mints a fresh installation token from that id and the app's private key, and it expires in an hour — there is no long-lived credential to leak.
How work gets linked
Issue keys are extracted from branch names, commit messages and pull-request text, then intersected with the project keys that belong to your organization. A key from someone else's numbering scheme does not match yours by accident.
Each match becomes an activity row on that issue. Webhook deliveries are signature-verified and recorded once, so a redelivery is acknowledged rather than applied twice.
Letting a merge move the issue
You can map a pull-request event to a status — opened to In Review, merged to Done. Nothing about that mapping is built in; it is your configuration.
The move runs through the same transition guards a person would hit. A transition your workflow forbids is skipped and logged, never forced.