## TL;DR
Grant the GitHub App the Checks "Read and write" permission (plus Pull requests read and write if the workflow also posts review comments), then accept the new permissions by reinstalling the app on the repo and re-run the job. Annotations post through the Checks API, so an installation token without that scope gets a 403 every time.

## The error
```text
reviewdog: annotation failed to post: resource not accessible by integration
```

## Steps to fix
1. Confirm the token type: open the workflow and check how reviewdog authenticates - if the step mints an installation token for a GitHub App (rather than using a personal access token), this skill applies.
   - Expected: a token-minting step or an app-based credential, not a PAT secret.
2. Open the GitHub App's settings page, go to Permissions, and check what Checks is set to.
   - Expected: Checks is set to No access or Read-only, which explains the 403.
3. Set Checks to Read and write (and Pull requests to Read and write if reviewdog also posts review comments), save, then accept the updated permissions on each repo where the app is installed.
   - Expected: the installation shows the new permission set.
4. Re-run the failed workflow.
   - Expected: reviewdog posts annotations with no 403.

## Use this when
- reviewdog fails in CI with "resource not accessible by integration" when posting annotations.
- The workflow authenticates reviewdog with a GitHub App installation token.
- Annotations worked with a PAT but break after switching to an app token.

## Not for this skill when
- reviewdog fails to parse the diff or find the config (that's a different error, not permissions).
- The 403 happens posting PR reviews rather than annotations (check the Pull requests permission instead).
- The token is a fine-grained PAT (fix the PAT's permission set, not an app's).

## Variant phrasings
- reviewdog 403 resource not accessible by integration
- reviewdog cannot post annotations github app permissions
- annotation failed to post checks permission reviewdog
- reviewdog action 403 in github actions

## Why it happens
reviewdog posts lint results as check-run annotations through the Checks API. GitHub Apps start with zero permissions, and an installation token carries exactly the permission set granted on the app's settings page. "Resource not accessible by integration" is GitHub's way of saying the token's permission set doesn't include the endpoint being called - the app simply was never granted Checks write.

## Edge cases
- Organization-installed apps need an org admin to accept the new permissions; repo admins can't do it alone.
- Tokens minted before the reinstall may be cached in a long-running job - re-run the job after reinstalling.
- Fork PRs from private repos have extra restrictions on what checks can post; same-repo PRs first to isolate.
- If reviewdog also posts review comments, it needs Pull requests write too, or you'll fix annotations and hit the same 403 on comments.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_V4EfkiGwqRgjYrWLF7fmlA
