diff --git a/doc/connections/GITHUB-REVIEW-BOT.md b/doc/connections/GITHUB-REVIEW-BOT.md
index bc12883319..3c4cfbd80b 100644
--- a/doc/connections/GITHUB-REVIEW-BOT.md
+++ b/doc/connections/GITHUB-REVIEW-BOT.md
@@ -40,6 +40,23 @@ behavior, and narrower saved repository restrictions remain intact. Later
repository additions require enablement in Access. Advanced review rules and
prompts live in Settings.
+The App belongs to the selected account or organization and uses its own bot
+identity. The editable App name determines GitHub's slug and `@mention`; there
+is no separate editable bot username. Paperclip shows and copies the verified
+mention in the connected bot's header. Type `@app-slug`, without the `[bot]`
+suffix shown on GitHub's API author records.
+
+**GitHub App name and logo** is optional on the connected page and in Settings.
+Download the agent's avatar as a PNG, then follow the link to this App's GitHub
+settings to upload it under **Display information**. GitHub's
+[manifest parameters](https://docs.github.com/en/apps/sharing-github-apps/registering-a-github-app-from-a-manifest)
+do not include an avatar; the
+[logo upload](https://docs.github.com/en/apps/creating-github-apps/registering-a-github-app/creating-a-custom-badge-for-your-github-app)
+remains a GitHub settings action. After renaming the App on GitHub, use the
+existing **reconnect this App** flow to refresh its verified identity using its
+stored credentials. Legacy manual connections without recorded ownership link
+to the App settings list instead of assuming an owner.
+
Local instances receive public callbacks and signed events through an enrolled
Paperclip Cloud connector, using outbound requests instead of a public tunnel.
The Cloud gateway capability must be deployed before localhost onboarding.
diff --git a/doc/plans/2026-10-07-github-app-live-test-drive.md b/doc/plans/2026-10-07-github-app-live-test-drive.md
index 9c47090cb6..a45d303bd9 100644
--- a/doc/plans/2026-10-07-github-app-live-test-drive.md
+++ b/doc/plans/2026-10-07-github-app-live-test-drive.md
@@ -325,3 +325,34 @@ copy edit and passes. Repository typecheck/build, production Storybook build,
and token gates pass; the final discovery change also received focused server
typecheck/build. These checks do not qualify a new provider or model run. The
earlier full-suite failure and outstanding current-head CI/review still apply.
+
+### Custom App identity and branding qualification
+
+The live bot is the dedicated **Animal Bot E2E 20261007** App owned by
+`paperclipai`, not the shared Paperclip App. Its verified GitHub author is
+`animal-bot-e2e-20261007[bot]`; the human mention is
+`@animal-bot-e2e-20261007`. The published review's GitHub author and App fields
+agree with the saved endpoint identity.
+
+The setup name field now explains GitHub's derived mention. Connected bots show
+the verified, copyable mention in the header. Settings and wizard completion
+share an optional App name/logo disclosure, the agent's PNG download, and the
+owning App's GitHub settings link. Personal accounts use their corresponding App
+settings path. Unknown legacy ownership uses the settings list, never an assumed
+organization or the installation settings page. A renamed App can refresh its
+identity through existing-App reconnect with stored credentials.
+
+The preserved test drive was restarted after an interruption. The live header
+showed the correct mention; copying and pasting it into an unsaved field proved
+the exact text, then the original field was restored without saving. Downloaded
+avatar is a 512×512 PNG, 30,616 bytes. Desktop and 390px branding layouts were
+inspected. GitHub's App settings link reached its signed-in re-authentication
+gate; no name or logo was changed, and App rename/reconnect was not tested live.
+GitHub's manifest has no logo field, so provider upload remains an optional
+GitHub settings action. No configuration, credentials or permissions changed in
+this walkthrough.
+
+All 59 focused management, setup, avatar-download and clipboard tests pass,
+including Slack's existing download/error/retry coverage for the shared
+downloader. UI typecheck/build, production Storybook build and token gates pass.
+The earlier full-suite failure and current-head CI/review limits still apply.
diff --git a/ui/src/components/AgentAvatarDownload.tsx b/ui/src/components/AgentAvatarDownload.tsx
new file mode 100644
index 0000000000..acc0b93b0a
--- /dev/null
+++ b/ui/src/components/AgentAvatarDownload.tsx
@@ -0,0 +1,71 @@
+import { useState } from "react";
+import { Download, Loader2 } from "lucide-react";
+import { Button } from "@/components/ui/button";
+
+export function agentAvatarFilename(name: string) {
+ return `${name.replace(/[^a-zA-Z0-9_-]+/g, "-") || "agent"}-avatar.png`;
+}
+
+/** Downloads the instance's generated PNG; provider upload remains explicit. */
+export function AgentAvatarDownload({
+ avatarUrl,
+ name,
+}: {
+ avatarUrl: string;
+ name: string;
+}) {
+ const [downloading, setDownloading] = useState(false);
+ const [failed, setFailed] = useState(false);
+ const download = async () => {
+ if (downloading) return;
+ setDownloading(true);
+ setFailed(false);
+ try {
+ const response = await fetch(avatarUrl);
+ if (
+ !response.ok ||
+ !response.headers.get("content-type")?.startsWith("image/png")
+ )
+ throw new Error("Avatar unavailable");
+ const url = URL.createObjectURL(await response.blob());
+ const link = document.createElement("a");
+ link.href = url;
+ link.download = agentAvatarFilename(name);
+ document.body.append(link);
+ link.click();
+ link.remove();
+ setTimeout(() => URL.revokeObjectURL(url), 1_000);
+ } catch {
+ setFailed(true);
+ } finally {
+ setDownloading(false);
+ }
+ };
+ return (
+
+
+ {failed && (
+
+ Couldn’t download the avatar. Try downloading it again.
+
+ )}
+
+ );
+}
diff --git a/ui/src/pages/apps/chat/ChatEndpointDetail.tsx b/ui/src/pages/apps/chat/ChatEndpointDetail.tsx
index 651d1e77da..8f2f318bbb 100644
--- a/ui/src/pages/apps/chat/ChatEndpointDetail.tsx
+++ b/ui/src/pages/apps/chat/ChatEndpointDetail.tsx
@@ -8,6 +8,7 @@ import { resolveAgentAppearance } from "@paperclipai/shared";
import { AgentAvatar } from "@/components/AgentAvatar";
import { ChatConversationList } from "./ChatConversationList";
import { GitHubBotManagement, GitHubReviews } from "./GitHubBotManagement";
+import { GitHubBotMention } from "./GitHubAppIdentity";
import { EmailEndpointSettings } from "./EmailEndpointSetup";
import { EmailConnectionAccess } from "@/components/EmailConnectionAccess";
import { emailApi } from "@/api/email";
@@ -309,6 +310,7 @@ export function ChatEndpointDetail() {