What are personal connections?
Personal connections store your own credentials for external integrations. When you connect an account, Pwnbook uses your token to act on your behalf — comments appear from your user, issue transitions are attributed to you, and PR reviews show your name. This is separate from org-level integrations, which use a shared credential configured by an admin. Personal connections are optional but required to have write actions attributed to you rather than the org service account.Configuring connections
Go to Profile → Connections. The page lists all integrations that support personal tokens. For each integration you want to connect:- Click Connect to open the configuration panel.
- Enter your personal API token (and any additional fields like username or instance URL).
- Click Save — Pwnbook stores the token securely and never exposes it again.
Available connections
GitHub
Write actions: post review comments, submit PR reviews, approve or request changes.
Create tokens at github.com/settings/tokens.
GitLab
Write actions: inline MR comments, submit MR reviews.
Create tokens at GitLab → Preferences → Access Tokens.
Linear
Write actions: transition issues, add comments, update assignees.
Create keys at Linear → Settings → API → Personal API keys.
Jira
Write actions: transition issues, add comments, link findings to tickets.
Create tokens at id.atlassian.com/manage-profile/security/api-tokens.
Bitbucket
Write actions: post inline comments, approve or decline PRs.
Create App Passwords at Bitbucket → Personal settings → App passwords.
Security
- Tokens are encrypted at rest and never returned in API responses after saving.
- Tokens are scoped to your user account — other team members cannot see or use them.
- You can disconnect an integration at any time from the Connections tab; this deletes the stored token immediately.