HonestHook

RankingsSign in

Tutorials

GitHub profile in JavaScript

One authenticated call to /api/v1/github/profile?handle=torvalds, the response it returned, and the line that reads one field out of it.

What you need

Node 18 or later, where fetch is global. No package to install. The same code runs in a browser, except that a browser would expose your key — call this from your server.

The call

const url = "https://honesthook.com/api/v1/github/profile?handle=torvalds";

const response = await fetch(url, {
  headers: { Authorization: `Bearer ${process.env.HH_KEY}` },
});

if (!response.ok) {
  throw new Error(`HTTP ${response.status}`);
}

const envelope = await response.json();
console.log(envelope.success, envelope.platform, envelope.endpoint);

What came back

{
  "success": true,
  "platform": "github",
  "endpoint": "github/profile",
  "data": {
    "author": {
      "id": "1024025",
      "handle": "torvalds",
      "name": "Linus Torvalds",
      "followers": 325402,
      "following": 0,
      "posts_count": null,
      "verified": null,
      "is_private": null
    }
  },
  "error": null,
  "cached": false
}

Recorded response, captured 27 Sep 2026. A live call returns the value at the moment you ask, not this one.

Every field in that capture

In JavaScriptType in this capture
envelope.successboolean
envelope.platformstring
envelope.endpointstring
envelope.data.author.idstring
envelope.data.author.handlestring
envelope.data.author.namestring
envelope.data.author.followersnumber
envelope.data.author.followingnumber
envelope.data.author.posts_countnull
envelope.data.author.verifiednull
envelope.data.author.is_privatenull
envelope.errornull
envelope.cachedboolean

A field we cannot read comes back null, never 0. A zero would be a claim about the account; null is a fact about our collection. The full list of what this route does not return is on github-api/profile.

Reading one field

console.log(envelope.data.author.followers);

envelope is the object from the block above. Keep the key on the server: a key shipped to a browser is a key anyone can read.

GitHub is the easy one. It runs an official public API, it needs no token for a public user, and the shape it returns is stable. So the honest question about this endpoint is what you are getting that you could not get by calling api.github.com yourself.

The answer is the normalisation, and it is narrower than a sales page would claim.

What you are calling

You are calling our endpoint, with your key in an Authorization header. Behind it, GitHub's official API. What comes back is the same eight-field envelope that Instagram, TikTok, Bluesky and every other profile route here return — Hacker News is the exception, because it answers a search, and its author block carries three fields rather than eight. So a client you write once reads all of them, and adding a platform does not mean adding a parser.

Where GitHub has nothing to give, the field is null instead of being filled from a neighbouring number that means something else. That decision is the product here.

Before you copy the block

Keep the key in an environment variable — all three examples read HH_KEY.

If GitHub is the only platform you need, call GitHub directly; that is a real answer and this page is not going to pretend otherwise. The envelope earns its keep at the second platform.

The endpoint itself

Parameters, the handle format, what the route does not return and what a call costs: github-api/profile.

The same call in curl · Python.

Free key, 1,000 credits a month

Every example above runs against the real endpoint as soon as you have a key. No card, and the key arrives in seconds.

Get a key →

← Tutorials · github-api · Pricing