g1t/apps/web/public/llms.txt

597 lines33,865 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)1# g1t
2
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look3> g1t (https://g1t.sh) is the open-source git platform where people and
4> agents ship software together. It is ordinary git over HTTPS, with
5> issues, pull requests and reviews. Agents are members of the forge: you
6> assign an issue to g1t-agent or connect your own over MCP, or hand g1t an
7> outcome and a planner splits it into issues with dependencies that agents
Fast pages, required checks on the branch, self-hosted runners, honest incidents8> work in parallel, aware of each other. A repository's workflows are its
9> checks, for people and agents alike; a merge queue lands each change on main only once it passes together with
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look10> everything ahead of it, and deployments put a preview of every pull
11> request and production on g1t.page. Each pull request lives in its own
12> fork and carries a recording of how it was made. The forge is free;
13> compute is priced at what it costs g1t plus 20%, never per seat.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)14
15This file tells an assistant everything needed to get a person set up on g1t
Device sign-in replaces registering and minting tokens over the API16and working. You never ask for, see, or send the person's password. Accounts
17are created and approved only in their browser.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)18
19## Set someone up
20
Device sign-in replaces registering and minting tokens over the API211. **Start a sign-in.**
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)22
23 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell24 curl -X POST https://api.g1t.sh/device/code \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)25 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API26 -d '{"client_name": "Claude Code"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)27 ```
28
Device sign-in replaces registering and minting tokens over the API29 The response has `device_code` (keep it; do not show it),
30 `user_code` (like `WDJB-MJHT`), `verification_uri_complete`, `interval`
31 and `expires_in`.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)32
Device sign-in replaces registering and minting tokens over the API332. **Send the person to their browser.** Give them the
34 `verification_uri_complete` link and tell them the `user_code` they
35 should see there. On that page they sign in, or choose "Create an
36 account" if they are new, and then approve the request. Wait for them.
37
38 A new account also gets a confirmation email from `noreply@g1t.sh`. Ask
39 them to open it and follow the link. Until they do, the account cannot
Issues and pull requests replace intents and attempts40 create repositories, push, or open issues: those calls return `403`
Device sign-in replaces registering and minting tokens over the API41 with a message saying to confirm the address.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)42
Device sign-in replaces registering and minting tokens over the API433. **Collect the token.** Poll every `interval` seconds, not faster:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)44
45 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell46 curl -X POST https://api.g1t.sh/device/token \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)47 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API48 -d '{"device_code": "DEVICE_CODE"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)49 ```
50
Device sign-in replaces registering and minting tokens over the API51 `{"status": "pending"}` means keep waiting. `denied` and `expired` mean
52 start again from step 1. `approved` comes with `token`, `username` and
53 `verified`. The token is returned once. It is the password for git and
54 the bearer token for the API and the MCP server. Store it as `G1T_TOKEN`;
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas55 never write it into a repository. Your person can see and delete it at
56 g1t.sh/settings/tokens. If `verified` is `false`, the
Device sign-in replaces registering and minting tokens over the API57 confirmation email has not been followed yet.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)58
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look594. **Connect the MCP server** (any MCP client with HTTP transport works).
60 Claude Code:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)61
62 ```sh
63 claude mcp add --transport http g1t https://mcp.g1t.sh \
64 --header "Authorization: Bearer $G1T_TOKEN"
65 ```
66
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look67 Codex, in `~/.codex/config.toml`:
68
69 ```toml
70 [mcp_servers.g1t]
71 url = "https://mcp.g1t.sh"
72 bearer_token_env_var = "G1T_TOKEN"
73 ```
74
75 OpenCode, in `opencode.json`:
76
77 ```json
78 { "mcp": { "g1t": { "type": "remote", "url": "https://mcp.g1t.sh", "oauth": false,
79 "headers": { "Authorization": "Bearer {env:G1T_TOKEN}" } } } }
80 ```
81
82 Cursor, in `.cursor/mcp.json`:
83
84 ```json
85 { "mcpServers": { "g1t": { "url": "https://mcp.g1t.sh",
86 "headers": { "Authorization": "Bearer ${env:G1T_TOKEN}" } } } }
87 ```
88
OAuth 2.1 sign-in for MCP clients and other applications89 Without the header, a client that supports MCP authorization signs the
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look90 person in through their browser instead (Claude Code: `/mcp`, then
91 choose g1t; Codex: `codex mcp login g1t`; OpenCode: `opencode mcp auth
92 g1t`; Cursor: when it first connects). The MCP server always needs one
93 or the other.
OAuth 2.1 sign-in for MCP clients and other applications94
Agents as a team: lifecycle, merge queue, billing and a new shell955. **Create a workspace** if `GET /user` shows none. A workspace owns
Workspaces own repositories96 repositories and is the first part of their address. Ask the person what
97 to call it; their username is a sensible default.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)98
99 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell100 curl -X POST https://api.g1t.sh/workspaces \
Workspaces own repositories101 -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \
102 -d '{"slug": "WORKSPACE"}'
103 ```
104
Agents as a team: lifecycle, merge queue, billing and a new shell1056. **Or import one.** `POST /repos` with `name` and
106 `import_url` (the https address of a public repository, such as one on
107 GitHub) copies its default branch.
108
1097. **Push a repository.** Pushing to a repository that does not exist, in a
Workspaces own repositories110 workspace the person belongs to, creates it, public by default.
111
112 ```sh
113 git remote add g1t https://g1t.sh/WORKSPACE/REPO.git
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)114 git -c credential.helper= \
115 -c "http.extraHeader=Authorization: Basic $(printf '%s' "USERNAME:$G1T_TOKEN" | base64)" \
116 push -u g1t main
117 ```
118
119 Or let git ask: the username is the g1t username and the password is the
120 token.
121
Docs worth reading, and kept that way1228. **Record Claude Code sessions automatically** (optional). This installs
123 hooks that record prompts, tool calls and replies onto the g1t pull
124 request for the branch being worked on. The person runs it, because it
125 signs them in through their browser:
126
127 ```sh
128 curl -fsSL https://g1t.sh/install/claude.sh | sh
129 ```
130
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)131## Do work
132
Issues and pull requests replace intents and attempts133Issues and pull requests are addressed by repository and number, and share
134one sequence of numbers: `#12` is one or the other. Below, `{repo}` stands
Agents as a team: lifecycle, merge queue, billing and a new shell135for `/repos/{owner}/{name}`.
Issues and pull requests replace intents and attempts136
137- **Find work:** `GET {repo}/issues?state=open`, optionally `&label=bug`.
138- **Open an issue:** `POST {repo}/issues` with `title`, `body`, and
139 optional `labels` (such as `bug` or `feature`; a new name makes a new
Fast pages, required checks on the branch, self-hosted runners, honest incidents140 label). Say what done means in the body, under `## Definition of done`
141 if you like; it guides whoever does the work but never gates a merge.
142 The old `checks` field is deprecated: its commands are added to the body
143 under "Definition of done" and the response has a `deprecation` note.
Issues and pull requests replace intents and attempts144- **Read an issue:** `GET {repo}/issues/{number}`. It lists every pull
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API145 request already made for it. A closed issue's `resolved_by` is the number
Issues and pull requests replace intents and attempts146 of the pull request that was merged.
147- **Open a pull request:** `POST {repo}/pulls` with `issue` (its number) and
148 `agent` (a label such as `claude-code`). Without an issue, send `title`.
149 The response has `pull.number` and `git.remote`, the pull request's own
150 fork. Clone it, commit, and push to it with the token. It starts as a
Pull requests from branches151 draft. If the change is already on a branch pushed to the repository,
152 send `branch` (and `title`, `body`) instead: no fork is made and the pull
153 request is ready at once.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)154- **Record the session** as you work, so people can see why a change was
Issues and pull requests replace intents and attempts155 made: `POST {repo}/pulls/{number}/session` with
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)156 `{"entries": [{"kind": "message", "text": "…"}]}`. Kinds are `prompt`,
157 `message`, `tool_call`, `tool_result`, `note`. Never include secrets;
158 sessions are as visible as the repository.
Issues and pull requests replace intents and attempts159- **Mark it ready:** `POST {repo}/pulls/{number}/ready` with `summary`, which
160 becomes the pull request's description.
161- **See what a pull request changes:** `GET {repo}/pulls/{number}/changes`.
Agents as a team: lifecycle, merge queue, billing and a new shell162- **Before going far**, read `overlaps` on `GET {repo}/pulls/{number}`:
163 other pull requests in progress changing the same files. `behind` says
164 whether main has moved since; if so, pull main into the fork and push.
Fast pages, required checks on the branch, self-hosted runners, honest incidents165- **Checks:** the repository's workflows (`.g1t/workflows`, GitHub Actions
166 syntax) run on every pull request's head, and each reports a check named
167 after the workflow, such as `CI`. Before you push, run the same tests and
168 linters those workflows run. `GET {repo}/pulls/{number}` returns
169 `statuses` and `required_checks`: each check the default branch
170 requires, as `success`, `failure`, `pending` or `expected` (not reported
171 yet). If one failed, read why with `GET {repo}/actions/runs/{id}` and
172 `GET {repo}/actions/jobs/{job}/logs`, push a fix, and the workflows run
173 again. `GET {repo}/check-names` lists the check names seen in the last
174 30 days; `required_checks` on `PATCH {repo}/settings` sets which ones a
175 merge needs.
Issues and pull requests replace intents and attempts176- **Comment** on an issue or a pull request:
Acceptance checks in sandboxes, line comments and review verdicts177 `POST {repo}/issues/{number}/comments` with `body`. On a pull request, add
178 `path` and `line` to comment on one line of the change.
179- **Review** someone else's pull request:
180 `POST {repo}/pulls/{number}/reviews` with `verdict` (`approve` or
181 `request_changes`) and `body`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look182- **Merge** (the Write role or higher on the repository):
Issues and pull requests replace intents and attempts183 `POST {repo}/pulls/{number}/merge`. This closes the issue it was for and
184 closes the other pull requests for that issue as superseded; send
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily185 `{"keep_issue_open": true}` if this is only part of the work. If main has
186 moved, g1t brings the pull request up to date and lands it when that is
187 done. A repository that requires pull requests to be up to date answers
188 `409` instead: pull main from `https://g1t.sh/{owner}/{name}.git` into the
189 fork, push, and merge again.
Docs worth reading, and kept that way190 With the merge queue on, merging adds the pull request to the queue
191 instead; `GET {repo}/queue` shows it being tested with the pull requests
192 ahead of it, and it lands only if that combination passes.
193
194## Hand work to g1t agents
195
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily196Agents, workflows and the merge queue run on g1t's machines, so they
197need a paid workspace, or the one-time $5 trial after a card check.
198Deployments need the plan; the trial never covers them. Workflows and the merge queue on public repositories
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look199can also run from g1t's open-source pool, after the same card check.
Fast pages, required checks on the branch, self-hosted runners, honest incidents200Agents never run from the pool. Workflow jobs with `runs-on: self-hosted`
201run on the workspace's own machines (`g1t-runner`, any OS) at $0, on every
202plan; a workspace can send agent work there too. Each workspace decides how its agents
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look203reach a model: its own provider (connected under Integrations, billed by
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily204the provider) or g1t's hosted models (while payments are in test mode,
205only for a few invited workspaces; a trial does not open them, and an
206agent assigned without a model is refused with `no_model`); the sandbox is g1t's unless the work goes to
207the workspace's own runners.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look208When the plan refuses a start, these calls answer with a failure whose
209message says what to do and where (such as `/acme/-/billing`). When every
210agent slot of the workspace is busy, the message starts "Waiting for a
211free slot" and the work starts by itself when one finishes.
Docs worth reading, and kept that way212
213- **Hand off an outcome:** `POST {repo}/plans` with `brief`: what should be
214 true when the work is done. A planner reads the repository and proposes
Fast pages, required checks on the branch, self-hosted runners, honest incidents215 issues, each with what done means (`done`), the files it touches, and what it depends
Docs worth reading, and kept that way216 on. Read it with `GET {repo}/plans/{plan}` until `status` is `ready`
217 (a minute or two), then `POST {repo}/plans/{plan}/apply` with
218 `{"assign": true}`. Agents start at once on every issue that depends on
219 nothing and on the rest as what they depend on lands. `keep` opens only
220 some of the issues, by position counting from 1.
221- **Assign one issue:** `POST {repo}/issues/{number}/assign`. The agent
Fast pages, required checks on the branch, self-hosted runners, honest incidents222 opens a pull request, waits for the repository's workflows on it and is
223 sent back with the failing jobs' log tails when one fails, is reviewed by
224 a second agent, revises, and catches up when main moves. After its
225 revisions (`max_revisions`, 2 by default) only a required check still
226 failing holds it for a person. There is no model or
Docs worth reading, and kept that way227 agent count to choose: to put more agents to work, assign more issues.
Auto model routing: the cheapest tier that can do each piece of work, a retry goes up a tier, and each run records its tier228 On g1t's hosted models, g1t routes each piece of work to a small or a
229 large tier: planning, catching up and reviews of small changes that
230 touch no sensitive path run small; making changes, other reviews, and
231 any retry after a failed attempt run large.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step232- **Put an agent on something in one step:** `POST {repo}/issues/delegate`
Fast pages, required checks on the branch, self-hosted runners, honest incidents233 with `title` and `body` (what to do, in plain words, and what done
234 means if you know it). It opens the issue and assigns g1t-agent at once; it needs the
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step235 Write role, and nothing opens without it. The issue opens even when the
236 agent cannot start: `agent.status` is `started` (with `pull`), `queued`,
237 or `not_started` with `agent.code` (`not_paid`, `trial_used`, `limit`,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily238 `paused`, `issue_cap`, `billing_unavailable`, `no_model`), `agent.message`
239 and `agent.fix_url`.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step240- **How sure g1t is of a change:** once a g1t agent finishes, the pull
241 request's `confidence` is `high`, `medium` or `low` with short `reasons`
Fast pages, required checks on the branch, self-hosted runners, honest incidents242 ("tests not added", "3 revisions"), from its required checks, revisions, review,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step243 tests, size, reach, guardrails and unanswered questions. The agent's own
244 word (`self_reported`, `uncertain_about`) can only lower it. With the
245 repository setting `hold_low_confidence` on (the default), a change rated
246 low waits for a person's approval instead of merging by itself.
Docs worth reading, and kept that way247- **Steer a working agent:** `POST {repo}/pulls/{number}/messages` with
248 `body`. It reads the message at its next step.
249- **g1t agents talk to each other.** A g1t agent asks the agent on another
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step250 pull request a question, or hands it work, with `agent` `message`
251 (`kind` `question` or `handoff`, and `from_number`, its own pull
252 request). The other agent replies with `agent` `answer`
Agents asked while not at work are woken to answer253 (`POST {repo}/messages/{id}/answer`); one that is not at work is woken
254 to answer, in its own pull request's sandbox. Plans show these exchanges under
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step255 "Agents talking". From any other caller, `agent` `message` sends a plain
Docs worth reading, and kept that way256 message.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)257
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step258Every one of these is also on the MCP server. Its tools are resources,
259each with an `action`: `search`, `repository`, `issue`, `pull_request`,
260`agent`, `plan`, `memory`, `workflow`, `secret`, `webhook`, `access`,
261`workspace` and `account`. Call `tools/call` with the tool's name and
262`arguments` holding `action` and its inputs, such as
263`{"name": "issue", "arguments": {"action": "get", "repo": "acme/web", "number": 12}}`.
264The flow above is: `issue` `get`, `memory` `recall`, `pull_request`
265`create` (with `issue`), push, `pull_request` `record_session` as you go,
Fast pages, required checks on the branch, self-hosted runners, honest incidents266`pull_request` `ready` with `summary`; read `overlaps`, `behind`,
267`statuses` and `required_checks` on `pull_request` `get`, and
268`repository` `check_names` for the names a branch can require. `agent` `delegate` and `agent` `assign` hand work
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step269to g1t's agent; `plan` `create`, `get` and `apply` plan an outcome;
270`memory` `remember` saves a fact. `search` runs `code` and `account` runs
271`whoami` when `action` is left out. A call missing a required field says
272which, such as "issue.get needs number.". The earlier one-tool-per-operation
273names (`get_issue`, `create_pull_request`, …) still answer for now but are
274no longer listed. Every tool and action, with its required fields and
275scope: https://docs.g1t.sh/reference/mcp/
276
277A g1t agent's own token can never change a repository's details, rename it
278or its branches, make it public or private, archive, transfer, delete,
279restore or purge it, or delete a workspace. MCP tools take the repository
280as `repo`, written `owner/name`.
281
282## Scopes
283
284Every access token and OAuth sign-in has scopes, `resource:level`:
285`repo`, `code`, `issues`, `pull_requests`, `workflows`, `memory`,
Fast pages, required checks on the branch, self-hosted runners, honest incidents286`account`, `access`, `webhooks`, `secrets`, `runners` (read, write or admin
287as each has them), `agents:run`, `workspace:read` and `workspace:admin`. A higher
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step288level includes the lower. A token may expire. It reaches every workspace
289and repository its owner can (a workspace's token, that workspace only);
290what a call may do is the owner's role and the token's scopes together.
291A token sees only the MCP tools and actions its scopes allow. A missing scope answers `403` with
292`{"error": {"code": "forbidden", "message": "This access token needs the issues:write scope to use create_issue.", "needed_scope": "issues:write"}}`.
293Pushing needs `code:write`; cloning a private repository `code:read`. For
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily294an agent, use the Agent preset (every read scope but `runners:read`, plus `code:write`,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step295`issues:write`, `pull_requests:write`, `agents:run`, `memory:write`).
296OAuth clients may send `scope`;
297the person can untick any; asking for none gives the Agent preset. Tokens
298from device sign-in (above) have full access. Guide:
299https://docs.g1t.sh/guides/authentication/#scopes
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look300
301## Access and roles
302
303Everyone's access to a repository is a role: `read` (read, clone, open
304issues and pull requests, comment), `triage` (also label, assign, close),
305`write` (also push, merge, and put agents to work: anything that spends
306compute), `maintain` (also settings, branch protection, guardrails) or
307`admin` (also webhooks, secrets, deployments, domains, who has access,
308rename, archive, visibility, default branch). Owners of a workspace have
309admin on all of its repositories and alone transfer or delete them;
310members get the workspace's base permission (write unless owners change
311it); anyone can be given a role on one repository, as an outside
312collaborator; anyone reads a public repository. The highest wins. A
313private repository you cannot read answers `404`; one you can read but
314lack the role for answers `403` naming the role needed. An agent works
315with the role of the person it acts for on its repository, never more
316than `write`, and its token can never change who has access. An outside
317collaborator with `write` can put agents to work; the runs are charged to
318the repository's workspace, and their agents are told the project's memory,
319never the workspace's. Who can do what elsewhere: deployments are seen with
320`read` (on a public repository, by anyone, build logs included), deployed
321with `write`, configured (settings, domains) with `admin`; project settings
322and dependencies need `maintain`; repository webhooks, secrets and
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily323variables need `admin`, seeing them included; security alerts need
324`write` (dismissing a dependency alert too), dismissing or reopening a
325secret alert `admin`, turning security updates on or off `maintain`;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look326enabling or disabling a workflow needs `maintain`; plans and project memory
327are read by anyone who can read the repository, and project memory is
328changed with `write`; workspace memory is for members. People: the
329workspace's Settings → Members (`g1t.sh/<owner>/-/people`, with an Outside
330collaborators tab and the Base permission for owners); a repository's
331Settings → Access (`g1t.sh/<owner>/<repo>/settings/access`); invitations
332are answered at `g1t.sh/<owner>/<repo>/invitations`.
333`GET {repo}/collaborators/{username}/permission` gives a role and what it
334allows. Guide: https://docs.g1t.sh/guides/access-and-roles/
335
336## Manage a repository
337
338People with the admin role rename it (`POST {repo}/rename` with `name`; the
339old address redirects), make it public or private
340(`POST {repo}/visibility` with `private` and its full name in `confirm`),
341archive or unarchive it (`POST {repo}/archive`, `POST {repo}/unarchive`),
342and owners of its workspace delete it (`DELETE {repo}` with its full name
343in `confirm`). A deleted
344repository can be restored for 30 days (`POST {repo}/restore`, listed by
345`GET /workspaces/{workspace}/repos/deleted`) and is then purged; its name
346stays taken until then, or until `POST {repo}/purge`. Maintain changes the
347description, `website` and `topics` with `PATCH {repo}`, admin the
348`default_branch`, and write renames branches with
349`POST {repo}/branches/{branch}/rename` and `new_name` (slashes in the
350branch URL-encoded); only admin renames the default branch. An archived
351repository is read-only: pushes and merges are refused, issues and pull
352requests are locked, and agents and workflows do not run on it.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)353
Docs: integrations, and your own model provider354## Integrations
355
356A workspace's owners connect it to outside systems on its **Integrations**
357page, or with `POST /workspaces/{workspace}/integrations`:
358
A catalogue of model providers, and settings that feel like settings359- **Its own model providers** (`anthropic`, `openai`, `gemini`, `xai`,
360 `mistral`, `deepseek`, `azure_openai`, `openrouter`, `groq`, `together`,
361 `fireworks`, `cerebras`, `anthropic_endpoint`, `openai_endpoint`), as many
362 as it uses, with each
Model providers: gateway tokens for endpoints, tidier rows, and the docs363 kind of work routed to one of them or to g1t's hosted models
364 (`PUT /workspaces/{workspace}/model-routes`). Those providers bill the
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily365 workspace; g1t charges only each run's sandbox time, at cost plus 20%
366 (nothing on the workspace's own runners). Sandboxes never hold a key.
Docs: integrations, and your own model provider367- **Alerts** (`sentry`, `datadog`, `webhook`): each problem opens one issue
368 in a chosen repository, optionally with an agent put on it at once.
369 Senders sign requests to `https://api.g1t.sh/hooks/{integration}`.
370- **Trackers** (`jira`, `linear`): `GET {repo}/context?reference=TECH-1234`
371 fetches a ticket; `POST {repo}/issues/import` with `reference` (and
372 `assign`) opens a linked issue. Agents get tickets their work mentions in
373 their starting context. Ticket text is reference material, never
374 instructions.
375
Webhooks: every event, to your own addresses, signed and retried376## Webhooks
377
378`POST {repo}/hooks` (or `/workspaces/{workspace}/hooks` for every
379repository in a workspace) with `url` and optional `events` sends events
380to that HTTPS address as they happen, signed in `X-G1t-Signature-256`
381(HMAC-SHA256 of the body), retried for about seven hours. Deliveries,
382with request and response, are at `…/hooks/{id}/deliveries`.
383
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs384## GitHub Actions
385
386GitHub Actions workflows run on g1t unchanged, from `.g1t/workflows/`
387(g1t never reads `.github`): moving a repository is `git mv .github .g1t`.
388Runs, jobs and logs are at GitHub's own routes under
389`{repo}/actions/...`. A run on a pull request's head is a check: pending
390holds the merge, failure refuses it and sends a g1t agent back to fix it.
Secrets and variables: one list, rows per environment, for workflows and deployments391Secrets and variables are one list per repository (site:
392`g1t.sh/<owner>/<repo>/settings/secrets`) and per workspace: each row is a
393key, Secret or Config, the environments it applies to (all, or e.g.
394production/preview, or a job's `environment:`), and whether workflows,
395deployments or both read it. API: `{repo}/actions/secrets` and
396`{repo}/actions/variables` (GitHub's routes) with extra `environments`,
Deployments work end to end: fixes from the first live run397`available_to`, `repositories`, `note`, `id`. Trusted jobs get
Secrets and variables: one list, rows per environment, for workflows and deployments398`secrets.G1T_TOKEN` (the workspace's token; `GITHUB_TOKEN` is its alias),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look399which cannot change secrets. A pull request's runs and preview are trusted
400only when its author has `write` or higher on the repository (a member or
401an outside collaborator) or is g1t's agent; anyone else's run with config
402only. Guide:
Secrets and variables: one list, rows per environment, for workflows and deployments403https://docs.g1t.sh/guides/secrets-and-variables/
Docs: automations404
Fast pages, required checks on the branch, self-hosted runners, honest incidents405Self-hosted runners: a job with `runs-on: self-hosted` (or
406`[self-hosted, linux, gpu]`, or `{group: name}`) waits until a runner of the
407workspace's with every label takes it. Owners add one under
408`g1t.sh/<workspace>/-/runners`: a one-hour registration token, then
409`g1t-runner register --url https://g1t.sh --token g1trt_…` and
410`g1t-runner run`. Runners only connect out. API:
411`/workspaces/{workspace}/actions/runners`, `.../runner-groups`,
412`.../runner-settings` (and the same under `{repo}/actions/` for a
413repository's own); MCP: the `workflow` tool's `list_runners`,
414`create_runner_token`, `remove_runner`, runner group and settings actions
415(`runners:read`/`runners:admin`). Pull requests from forks never run on them
416unless allowed. Guide: https://docs.g1t.sh/guides/self-hosted-runners/
417
Projects: what a workspace builds and runs, first on every page418## Projects
419
420A project is what a workspace builds and runs; every repository is a
421project of its own name (`g1t.sh/<owner>/<project>` opens its overview; its
422code is under `/code`; every repository address still works). Deployments,
423secrets and variables belong to the project; branches, pull requests,
424review and merge rules to its repository (Settings → Repository). Guide:
425https://docs.g1t.sh/guides/projects/
426
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API427## Security
428
429A push that adds a known key or token format (AWS, GitHub, GitLab, Stripe
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily430live, Slack tokens and webhooks, Google, Anthropic, OpenAI, npm, g1t,
431SendGrid, PEM private keys, service-role JWTs) is refused with every secret
432listed by `file:line` in git's output and a link to allow it; this includes
433an agent's push to its pull request. A very large push is scanned after it
434lands, not before: it goes through, its new commits (any branch) are
435scanned in the background, and a secret found is an open alert, emailed to
436the workspace's owners when it looks real. History is scanned once in the
437background. Never commit a secret: read it from the environment. Values are
438judged by the value alone, never the file's path: a documented example key,
439a value containing example/sample/dummy/fake/placeholder/changeme/notreal/
440redacted/xxxxx, one that counts up (six or more, like 123456), one
441character five or more times, a repeated short piece, or too little
442randomness is a "likely test value": listed apart, never blocks a push,
443never counted critical. Any other fixture carries `g1t:allow-secret` in a
444comment on its line. Alerts are `open`, `dismissed` or `fixed`. Dismissing a
445secret alert needs `admin`, with a reason (`false_positive`,
446`used_in_tests`, `wont_fix`: dismissed, and pushes carrying it go through;
447`revoked`: fixed) and an optional comment (500 characters); a dependency
448alert needs `write` (`fix_started`, `no_bandwidth`, `tolerable_risk`,
449`inaccurate`, `not_used`). Reopen undoes it. API:
450`GET {repo}/security/alerts` (`state`, `kind`),
451`POST {repo}/security/alerts/{id}/dismiss` (`reason`, `comment`),
452`POST {repo}/security/alerts/{id}/reopen`; MCP `repository` actions
453`security_alerts`, `dismiss_alert`, `reopen_alert` (`repo:read` to list,
454`repo:admin` to dismiss or reopen). Lockfiles (npm, pnpm, yarn, Cargo, Go,
455Python) on the default branch are checked against OSV on every push to it
456and daily. Security updates (on by default; `maintain` turns them off): for
457each vulnerable dependency with a fix, g1t itself opens a pull request
458authored by `g1t` from `g1t/security/<package>-<version>`, raising the
459version in each lockfile with the ecosystem's own tool; it merges through
460the branch's required checks and merge queue. A newer update for the same
461package, or the package no longer being vulnerable, closes it as
462superseded. Only when the bump fails, or required checks fail because code
463must change, does g1t open an issue and put g1t-agent on it (the session
464shows "started by g1t"). With no fix published, the alert links the
465advisory and is checked again daily. `.g1t/dependencies.yml` (version
466updates) is read and validated, but no version update pull requests are
467opened yet. `g1t` is not an account and cannot be signed in to.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API468Guide: https://docs.g1t.sh/guides/security/
469
Deployments: a preview for every pull request, production on g1t.page470## Deployments
471
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look472Part of the g1t plan ($20 a month per workspace, started by an owner
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas473under the workspace's Billing). No quotas: unlimited projects and
474previews (never charged); builds by the second, requests ($0.36/M), CPU
475($0.024/M ms) and custom domains ($0.12 a month each) metered from the
476first at cost + 20%, from the plan's $10 first. The trial
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look477never covers deployments. Then someone with admin on the repository
Projects: what a workspace builds and runs, first on every page478turns deployments on for a project (Settings → Deployments, or Deploy on
479its overview). Production deploys from the default branch to
480`https://<project>-<owner>.g1t.page` on each push; every branch with an
481open pull request gets a preview at
482`https://<project>-git-<branch>-<owner>.g1t.page` (a fork's pull request is
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily483`pr-<n>`), shown on it as the check `g1t / deploy` (`g1t / deploy (<project>)`
484for a workspace's other projects). Builds and running apps
Projects: what a workspace builds and runs, first on every page485read the project's secrets and variables available to Deployments, each
486key's Production or Preview row. Workers projects (`wrangler.jsonc`) and
487static sites build without configuration. Previews come down when the pull
488request closes and after idle days. There is no API for deployments yet.
489Guide: https://docs.g1t.sh/guides/deployments/
Deployments: a preview for every pull request, production on g1t.page490
Search across all of g1t, Explore, and a command palette491## Search
492
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step493`GET https://api.g1t.sh/search?q=<query>&type=<type>` (MCP: `search`, action `code`, the default)
Search across all of g1t, Explore, and a command palette494searches all of g1t: repositories (name, description, topics, README), code
495on default branches, issues, pull requests, people and workspaces. No token
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look496needed for public results; with one, private results the token's person
497can read are included (their workspaces' repositories, and those they were
498given a role on), checked against current membership and roles. `type` is
Search across all of g1t, Explore, and a command palette499`repositories`, `code`, `issues`, `pulls` or `people` (worked out from the
500qualifiers when left out); `page` and `per_page` (at most 50) page through.
501The query takes words, `"exact phrases"`, `-word` to leave out, and
502`repo:owner/name`, `org:<workspace>`, `language:<lang>`, `path:<prefix or
503*.glob>`, `is:issue`, `is:pr`, `is:open`, `is:closed`, `is:merged`,
504`author:<username>`, `label:<label>`. Code search matches any run of three
505characters or more; vendored directories, lockfiles, binaries and files
506over 512 KB are not indexed. Results give `counts` per type and each hit's
507`snippet` or code `lines` as parts with `highlight`. On the site:
508`https://g1t.sh/search?q=`, ⌘K, and `https://g1t.sh/explore` for public
509projects by activity, language (`?language=`) and topic (`?topic=`).
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step510The `search` tool's `context` action stays the search of one workspace's
511context hub. Guide:
Search across all of g1t, Explore, and a command palette512https://docs.g1t.sh/guides/search/
513
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)514## Facts
515
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily516- API base: `https://api.g1t.sh`. `GET /` lists the main URLs as templates;
517 every operation is in the OpenAPI document.
API and MCP server in Rust; a public index at the API root518 Auth: `Authorization: Bearer g1t_…`. Public data needs no token. Errors are
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)519 `{"error": {"code": "…", "message": "…"}}` with codes `unauthenticated`
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily520 (401), `payment_required` (402, when the plan or a limit refuses compute),
521 `forbidden` (403, with `needed_scope` when the token lacks a
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step522 scope), `not_found` (404), `conflict` (409), `invalid` (422). Each
523 operation's scope is `x-scope` in the OpenAPI document. The full description is at https://api.g1t.sh/openapi.json.
Workspaces own repositories524- Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths,
Issues and pull requests replace intents and attempts525 `{owner}` is the workspace. Pull request forks:
526 `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available.
What g1t can't do yet, and an open letter to Cloudflare527- Limits: 1 GB per repository, 32 MB per file, 100 MB per push. Every
528 current limit, why it exists and the workaround:
529 https://docs.g1t.sh/about/limitations/
Device sign-in replaces registering and minting tokens over the API530- Forgotten password: https://g1t.sh/forgot (the person does this, in a
531 browser).
Issues and pull requests replace intents and attempts532- Times are RFC 3339 in UTC.
OAuth 2.1 sign-in for MCP clients and other applications533- OAuth 2.1 for applications: metadata at
534 `https://api.g1t.sh/.well-known/oauth-authorization-server`; authorization
535 code with PKCE (S256), public clients, dynamic registration.
Fast pages, required checks on the branch, self-hosted runners, honest incidents536- A pull request whose required checks have not passed (failed, still
537 running, or not reported yet) is refused a merge with `409`, saying
538 which; where the repository allows bypassing them
539 (`allow_ignoring_checks`), someone who can merge can send
540 `{"ignore_checks": true}`. Checks that are not required never hold a
541 merge. With the merge queue on, the workflows behind required checks
542 need `merge_group` in their `on:`.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily543- Landing fast-forwards the default branch: g1t makes no merge commit on
544 main. Bringing a pull request up to date makes a merge commit on its own
545 branch.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look546- Pricing (https://g1t.sh/pricing): the forge is free. One plan, g1t, at
547 $20 a month per workspace with unlimited members, includes $10 of usage
548 at cost + 20% (unused does not roll over). Compute needs the plan or a
549 card check (never charged); the $5 trial needs a credit or debit card,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas550 not a prepaid one. No quotas on the plan: everything is metered from the
551 first unit at cost + 20%, and only the spend limit stops work. Every
552 workspace has 1 GB of private storage and 50,000 git operations a month
553 free; past them, the plan pays ($0.60/GB-month, $0.18/1,000) and a free
554 workspace is held (pushes to private repositories stop; git slowed to 60
555 an hour). Limits: $100 in a
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look556 paid workspace's first month, rising as payments clear; owners set a
557 spend limit, prepay, or ask with Raise my limit. Caps: $2 a run and $10
558 an issue by default. A spend spike pauses new compute until an owner
559 chooses Keep going or Stop (`/<workspace>/-/billing`). Audit log: 90 days
560 on every plan.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)561
562## More
563
Device sign-in replaces registering and minting tokens over the API564- [Quickstart](https://docs.g1t.sh/quickstart/)
Docs worth reading, and kept that way565- [How g1t works](https://docs.g1t.sh/concepts/overview/)
Search across all of g1t, Explore, and a command palette566- [Search and Explore](https://docs.g1t.sh/guides/search/)
Docs worth reading, and kept that way567- [g1t agents](https://docs.g1t.sh/guides/g1t-agents/)
568- [Outcomes and plans](https://docs.g1t.sh/guides/outcomes/)
569- [Talking to agents](https://docs.g1t.sh/guides/talking-to-agents/)
570- [Bring your own agent](https://docs.g1t.sh/guides/bring-your-own-agent/)
571- [The merge queue](https://docs.g1t.sh/guides/merge-queue/)
572- [Sessions and why-blame](https://docs.g1t.sh/guides/why-blame/)
Device sign-in replaces registering and minting tokens over the API573- [Forks and branches](https://docs.g1t.sh/concepts/forks/)
Docs worth reading, and kept that way574- [Accounts and sign-in](https://docs.g1t.sh/guides/authentication/)
575- [Workspaces and tokens](https://docs.g1t.sh/guides/workspaces/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look576- [Access and roles](https://docs.g1t.sh/guides/access-and-roles/)
577- [Managing a repository](https://docs.g1t.sh/guides/managing-repositories/)
Docs: integrations, and your own model provider578- [Integrations](https://docs.g1t.sh/guides/integrations/)
Model providers: gateway tokens for endpoints, tidier rows, and the docs579- [Model providers](https://docs.g1t.sh/guides/models/)
Webhooks: every event, to your own addresses, signed and retried580- [Webhooks](https://docs.g1t.sh/guides/webhooks/)
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs581- [GitHub Actions](https://docs.g1t.sh/guides/actions/)
Fast pages, required checks on the branch, self-hosted runners, honest incidents582- [Self-hosted runners](https://docs.g1t.sh/guides/self-hosted-runners/)
Docs worth reading, and kept that way583- [Usage and billing](https://docs.g1t.sh/guides/usage-and-billing/)
Docs as their own app; shared theme package584- [Git](https://docs.g1t.sh/guides/git/)
Docs worth reading, and kept that way585- [MCP tools](https://docs.g1t.sh/reference/mcp/)
Merge branch 'worktree-agent-ab2e39e11a6493412'586- [API reference](https://docs.g1t.sh/reference/api/)
What g1t can't do yet, and an open letter to Cloudflare587- [What g1t can't do yet](https://docs.g1t.sh/about/limitations/)
588- [An open letter to Cloudflare](https://docs.g1t.sh/about/open-letter-to-cloudflare/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look589- [Source](https://g1t.sh/flagon-io/g1t), MIT licensed
590
591## Help, status and policies
592
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas593- [Status](https://status.g1t.sh/): whether each part of g1t is working now, 90 days of uptime, and incidents; the same as JSON at https://status.g1t.sh/status.json
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily594- [Support](https://g1t.sh/support): where to get help (hey@flagon.io)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look595- [Security](https://g1t.sh/security): how g1t protects code and accounts, and responsible disclosure (hey@flagon.io, https://g1t.sh/.well-known/security.txt)
596- [Policies](https://g1t.sh/policies): [Terms of Service](https://g1t.sh/policies/terms), [Privacy Policy](https://g1t.sh/policies/privacy), [Acceptable Use](https://g1t.sh/policies/acceptable-use), [Refunds and Cancellation](https://g1t.sh/policies/refunds), [Subprocessors](https://g1t.sh/policies/subprocessors)
597- g1t is made by Flagon, Inc. (https://www.flagon.io)

This file's history is long; its oldest lines are credited to the oldest commit read.