Selling Private GitHub Repo Access: Why Revocation Protects Future Code, Not Past
A developer's deep-dive into tools for selling private GitHub repository access reveals a critical limitation: once a buyer clones a repo locally, no API or revocation system can delete that copy. GitHub's own documentation confirms that removing a collaborator does not erase local clones, meaning access revocation only prevents future updates, bug fixes, and community access — not existing code. This distinction reshapes how refund policies should be structured, with some major boilerplate sellers already treating redeemed access as non-refundable. Practical issues compound the problem, including GitHub invitation expiry after seven days, billing per pending seat in paid organizations, and invite emails sent to a buyer's primary address rather than their payment email. Payment infrastructure adds further friction, as Stripe supports only 44 countries without caveats, leaving sellers outside that list dependent on merchant-of-record services to handle transactions and tax compliance.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in