> Source: https://www.gitdash.info/docs/core-concepts · GitDash v4.7.1

# Data sources

## Live GitHub data

Almost every screen reads GitHub live through GitDash's API, with the signed-in person's own token and the cache described in Caching & rate limits. Nothing is copied into a database to draw these screens, so what you see always matches what your token can see on GitHub.

## Historical data (organization mode)

With a database, GitDash also keeps its own history. It powers Reports and the alert engine, and it outlives GitHub's run retention.

| Source | When | Needs |
| --- | --- | --- |
| `/api/cron/sync` | Daily at 03:17 UTC (Vercel Cron): workflow runs, then alert evaluation | `GITHUB_TOKEN`, `CRON_SECRET` |
| `/api/cron/sync-pr-facts` | Daily at 04:17 UTC: pull-request facts for the people-metric alerts | `GITHUB_TOKEN`, `CRON_SECRET` |
| `/api/cron/sync-commit-facts` | Daily at 04:47 UTC: commits of merged pull requests for working habits, then the oversized-commit alert | `GITHUB_TOKEN`, `CRON_SECRET` |
| `/api/webhooks/github` | Instantly, for each `workflow_run` event | `GITHUB_WEBHOOK_SECRET` |
| Reports → Sync now | On demand (admins in organization mode) | A signed-in session |

The sync uses the server's `GITHUB_TOKEN`, which usually sees more than any one person. Before serving synced data, GitDash checks that the viewer's own token can see the repository or organization.
