Library / SDK
octokit/octokit.js avatar
octokit/octokit.js

octokit.js: the all-batteries-included GitHub SDK for JavaScript, Node.js and Deno

The all-batteries-included GitHub SDK for Browsers, Node.js, and Deno.

7,856 stars1,286 forksTypeScriptMIT

At a glance

What is it?
octokit.js bundles GitHub's REST and GraphQL clients, GitHub App and OAuth support, and an Actions client into one package. It is a good fit for teams that need more than a thin REST wrapper, and the wrong choice if you only need one endpoint.
Who is it for?
Adopt octokit.js when you need GitHub App authentication, webhooks, OAuth or GraphQL alongside REST, because the package wires those pieces together and ships TypeScript declarations for each. Do not adopt it if you need one REST call in a browser bundle: @octokit/core is the smaller entry point the README itself names.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What octokit.js is for, and who should reach for it

GitHub exposes two APIs with different shapes: a REST API with hundreds of endpoints and a GraphQL API with a single query endpoint. A team building an integration usually ends up writing the same scaffolding twice, once for REST pagination and once for GraphQL cursors, plus token refresh logic for a GitHub App and signature verification for webhooks. octokit.js exists to remove that duplication. The README describes the package as integrating three libraries: an API client for REST requests, GraphQL queries and authentication; an App client for GitHub Apps, installations, webhooks and OAuth; and an Action client that is pre-authenticated for a single repository. The intended audience is anyone writing a GitHub integration in JavaScript or TypeScript, whether that runs in a browser, on Node.js, or on Deno. It is not aimed at someone who wants a raw HTTP wrapper. If you only need to call one endpoint once, the package brings in far more than you use.

How the SDK is assembled: three clients over one request layer

The architecture is visible in package.json. The published package depends on @octokit/core as the request engine, @octokit/app for GitHub App authentication, @octokit/oauth-app for OAuth flows, @octokit/webhooks for webhook handling, and a set of plugins: plugin-rest-endpoint-methods generates the octokit.rest.* methods, plugin-paginate-rest and plugin-paginate-graphql handle pagination for the two APIs, plugin-retry retries failed requests, and plugin-throttling limits request rates. The README's own framing is that the package is decomposable: you can build your own Octokit in a few lines or use the underlying static methods, trading functionality against bundle size. That is the real design decision. The octokit package is the assembled default, and each dependency is separately installable when you want less. When you construct a client, the request layer picks up your options and every plugin hooks into that lifecycle, which is why constructor options such as auth, baseUrl and userAgent apply uniformly across REST, GraphQL and App calls.

Installing octokit.js and making a first authenticated request

Installation differs by runtime. Node.js uses a package manager; browsers and Deno load the module directly from esm.sh, which the README shows in its usage table. For Node.js, the README gives `npm/pnpm install octokit` or `yarn add octokit`.

bash
npm install octokit

After installing, the README warns that because the package uses conditional exports you must adapt tsconfig.json by setting `"moduleResolution": "node16"` and `"module": "node16"`. Skipping that step is a common source of resolution errors in TypeScript projects. The first real request is a personal access token call to fetch the authenticated user:

js
import { Octokit } from "octokit";

const octokit = new Octokit({ auth: "personal-access-token123" });

const {
  data: { login },
} = await octokit.rest.users.getAuthenticated();
console.log("Hello, %s", login);

The README points readers to https://github.com/settings/tokens/new?scopes=repo to create the token. The response is the authenticated user object, and login holds the username. For GitHub Enterprise Server, the same constructor takes baseUrl set to the API root, for example `https://github.acme-inc.com/api/v3`.

Pagination, retries and throttling are defaults, not extras

In a hand-rolled client these three concerns are usually the last thing added and the first thing to break. Here they arrive as plugins. The README's table of contents lists Pagination under both the REST and GraphQL sections, and package.json shows plugin-paginate-rest and plugin-paginate-graphql as dependencies, so pagination is part of the default build rather than an opt-in. plugin-retry and plugin-throttling are dependencies too, which means a default Octokit instance already retries failed requests and applies rate limiting. That matters most for long-running jobs that walk a large repository or an organization's members, where a single 403 or a transient network failure would otherwise abort the run. The trade-off is control: because these behaviours are baked into the default client, changing retry or throttle behaviour means working with the plugin layer, not with a single options object. The README points extenders at the request and webhook lifecycle for exactly that reason.

Where octokit.js is the wrong tool

The package is explicitly the all-batteries-included option, and that framing is also its limitation. If your code needs one REST call, you are paying for the App client, the OAuth client, the webhooks library and four plugins. The README names the escape hatch directly: @octokit/core is described as the standalone minimal Octokit. Choosing the assembled package for a small script is a bundle and dependency decision you can avoid. A second constraint is the module setup. The README's important note requires `"moduleResolution": "node16"` and `"module": "node16"` in tsconfig.json because the package uses conditional exports. A project on an older TypeScript module configuration cannot simply drop the import in. Third, the request layer relies on fetch, and the README documents `request.fetch` as a replacement for the built-in fetch method, with `request.timeout` defaulting to 0 on Node. A default timeout of 0 means no timeout, which is a real failure mode for scripts that call GitHub from a CI job with a wall-clock limit. The README does not document a default timeout value other than 0, so set one yourself if your environment kills long requests.

How octokit.js compares with a plain REST wrapper

The alternative most teams weigh is not another SDK but a thin HTTP client: fetch or axios plus your own token handling. The difference is where the GitHub-specific logic lives. A thin wrapper keeps your dependency tree small and your control total, but you write pagination, retry, throttling, webhook signature verification and App installation token refresh yourself. octokit.js moves that logic into the package and exposes it through the same constructor. The README's decomposeable claim is what makes the comparison fair: you can take @octokit/core alone, or @octokit/app alone, and get one piece without the rest. The decision is therefore not octokit.js against fetch, but which layer of the Octokit stack matches the problem. If your integration touches GitHub Apps, OAuth or webhooks, the assembled package saves real work. If it touches one endpoint with a static token, it does not.

Maintenance, licensing and upgrade cost

The repository is not archived, and the last push was on 2026-09-18, which the release history supports: v5.0.5 was published on 2025-10-31, v5.0.4 on 2025-10-17, and v5.0.3 on 2025-05-27. The package is published to npm as octokit with a development version placeholder in package.json, and the release configuration in that file targets version branches of the form `+([0-9]).x`, which is the standard semantic-release branch pattern. Upgrade cost is concentrated in the dependency chain rather than the top-level API. Major bumps of @octokit/core, @octokit/app or the plugin packages can change plugin behaviour even when your own calls are unchanged, so reading the release notes for those packages is part of any upgrade. The licence is MIT, which permits commercial and private use; the repository ships a LICENSE file and a SECURITY.md and CONTRIBUTING.md at the top level. This is a description of the licence identifier, not legal advice.

Editorial conclusion

Adopt octokit.js when you need GitHub App authentication, webhooks, OAuth or GraphQL alongside REST, because the package wires those pieces together and ships TypeScript declarations for each. Do not adopt it if you need one REST call in a browser bundle: @octokit/core is the smaller entry point the README itself names. Before committing, verify that your tsconfig.json uses "moduleResolution": "node16" and "module": "node16" as the README requires for conditional exports, and confirm your Node version supports the built-in fetch the client relies on.

Frequently asked questions

What is octokit.js used for?

It is a GitHub SDK that combines a REST and GraphQL API client, a GitHub App client with webhooks and OAuth, and a pre-authenticated Action client for a single repository. The README describes it as the all-batteries-included SDK for browsers, Node.js and Deno.

How do I use the GitHub API in JavaScript with octokit.js?

Install the package, create an Octokit instance with an auth token, then call a REST method such as octokit.rest.users.getAuthenticated(). The README shows creating a personal access token at https://github.com/settings/tokens/new?scopes=repo and reading the login field from the response.

How do I install octokit.js from npm?

The README gives npm/pnpm install octokit or yarn add octokit for Node.js. Browsers and Deno import the module directly from esm.sh instead of installing it.

Does octokit.js work with TypeScript?

The README states that all libraries have extensive TypeScript declarations, and the repository includes a test:typescript script. The README also requires setting "moduleResolution": "node16" and "module": "node16" in tsconfig.json because the package uses conditional exports.

Can octokit.js talk to GitHub Enterprise Server?

Yes. The README documents the baseUrl constructor option for GitHub Enterprise Server, set to the API root such as https://github.acme-inc.com/api/v3.

Official sources

  1. Issues
  2. License: MIT
  3. octokit/octokit.js on GitHub
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/octokit-octokit-js.svg)](https://hysenlabs.com/projects/octokit-octokit-js)