flagon-io/g1t

public

Git for AI scale: a forge for thousands of agents working on the same code at once.

g1t/apps/web/public/llms.txt

479 lines25,803 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)1# g1t
2
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look3> g1t (https://g1t.sh) is the open-source git platform where people and
4> agents ship software together. It is ordinary git over HTTPS, with
5> issues, pull requests and reviews. Agents are members of the forge: you
6> assign an issue to g1t-agent or connect your own over MCP, or hand g1t an
7> outcome and a planner splits it into issues with dependencies that agents
8> work in parallel, aware of each other. Checks run in clean sandboxes, a
9> merge queue lands each change on main only once it passes together with
10> everything ahead of it, and deployments put a preview of every pull
11> request and production on g1t.page. Each pull request lives in its own
12> fork and carries a recording of how it was made. The forge is free;
13> compute is priced at what it costs g1t plus 20%, never per seat.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)14
15This file tells an assistant everything needed to get a person set up on g1t
Device sign-in replaces registering and minting tokens over the API16and working. You never ask for, see, or send the person's password. Accounts
17are created and approved only in their browser.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)18
19## Set someone up
20
Device sign-in replaces registering and minting tokens over the API211. **Start a sign-in.**
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)22
23 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell24 curl -X POST https://api.g1t.sh/device/code \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)25 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API26 -d '{"client_name": "Claude Code"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)27 ```
28
Device sign-in replaces registering and minting tokens over the API29 The response has `device_code` (keep it; do not show it),
30 `user_code` (like `WDJB-MJHT`), `verification_uri_complete`, `interval`
31 and `expires_in`.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)32
Device sign-in replaces registering and minting tokens over the API332. **Send the person to their browser.** Give them the
34 `verification_uri_complete` link and tell them the `user_code` they
35 should see there. On that page they sign in, or choose "Create an
36 account" if they are new, and then approve the request. Wait for them.
37
38 A new account also gets a confirmation email from `noreply@g1t.sh`. Ask
39 them to open it and follow the link. Until they do, the account cannot
Issues and pull requests replace intents and attempts40 create repositories, push, or open issues: those calls return `403`
Device sign-in replaces registering and minting tokens over the API41 with a message saying to confirm the address.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)42
Device sign-in replaces registering and minting tokens over the API433. **Collect the token.** Poll every `interval` seconds, not faster:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)44
45 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell46 curl -X POST https://api.g1t.sh/device/token \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)47 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API48 -d '{"device_code": "DEVICE_CODE"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)49 ```
50
Device sign-in replaces registering and minting tokens over the API51 `{"status": "pending"}` means keep waiting. `denied` and `expired` mean
52 start again from step 1. `approved` comes with `token`, `username` and
53 `verified`. The token is returned once. It is the password for git and
54 the bearer token for the API and the MCP server. Store it as `G1T_TOKEN`;
55 never write it into a repository. If `verified` is `false`, the
56 confirmation email has not been followed yet.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)57
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look584. **Connect the MCP server** (any MCP client with HTTP transport works).
59 Claude Code:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)60
61 ```sh
62 claude mcp add --transport http g1t https://mcp.g1t.sh \
63 --header "Authorization: Bearer $G1T_TOKEN"
64 ```
65
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look66 Codex, in `~/.codex/config.toml`:
67
68 ```toml
69 [mcp_servers.g1t]
70 url = "https://mcp.g1t.sh"
71 bearer_token_env_var = "G1T_TOKEN"
72 ```
73
74 OpenCode, in `opencode.json`:
75
76 ```json
77 { "mcp": { "g1t": { "type": "remote", "url": "https://mcp.g1t.sh", "oauth": false,
78 "headers": { "Authorization": "Bearer {env:G1T_TOKEN}" } } } }
79 ```
80
81 Cursor, in `.cursor/mcp.json`:
82
83 ```json
84 { "mcpServers": { "g1t": { "url": "https://mcp.g1t.sh",
85 "headers": { "Authorization": "Bearer ${env:G1T_TOKEN}" } } } }
86 ```
87
OAuth 2.1 sign-in for MCP clients and other applications88 Without the header, a client that supports MCP authorization signs the
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look89 person in through their browser instead (Claude Code: `/mcp`, then
90 choose g1t; Codex: `codex mcp login g1t`; OpenCode: `opencode mcp auth
91 g1t`; Cursor: when it first connects). The MCP server always needs one
92 or the other.
OAuth 2.1 sign-in for MCP clients and other applications93
Agents as a team: lifecycle, merge queue, billing and a new shell945. **Create a workspace** if `GET /user` shows none. A workspace owns
Workspaces own repositories95 repositories and is the first part of their address. Ask the person what
96 to call it; their username is a sensible default.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)97
98 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell99 curl -X POST https://api.g1t.sh/workspaces \
Workspaces own repositories100 -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \
101 -d '{"slug": "WORKSPACE"}'
102 ```
103
Agents as a team: lifecycle, merge queue, billing and a new shell1046. **Or import one.** `POST /repos` with `name` and
105 `import_url` (the https address of a public repository, such as one on
106 GitHub) copies its default branch.
107
1087. **Push a repository.** Pushing to a repository that does not exist, in a
Workspaces own repositories109 workspace the person belongs to, creates it, public by default.
110
111 ```sh
112 git remote add g1t https://g1t.sh/WORKSPACE/REPO.git
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)113 git -c credential.helper= \
114 -c "http.extraHeader=Authorization: Basic $(printf '%s' "USERNAME:$G1T_TOKEN" | base64)" \
115 push -u g1t main
116 ```
117
118 Or let git ask: the username is the g1t username and the password is the
119 token.
120
Docs worth reading, and kept that way1218. **Record Claude Code sessions automatically** (optional). This installs
122 hooks that record prompts, tool calls and replies onto the g1t pull
123 request for the branch being worked on. The person runs it, because it
124 signs them in through their browser:
125
126 ```sh
127 curl -fsSL https://g1t.sh/install/claude.sh | sh
128 ```
129
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)130## Do work
131
Issues and pull requests replace intents and attempts132Issues and pull requests are addressed by repository and number, and share
133one sequence of numbers: `#12` is one or the other. Below, `{repo}` stands
Agents as a team: lifecycle, merge queue, billing and a new shell134for `/repos/{owner}/{name}`.
Issues and pull requests replace intents and attempts135
136- **Find work:** `GET {repo}/issues?state=open`, optionally `&label=bug`.
137- **Open an issue:** `POST {repo}/issues` with `title`, `body`, and
138 optional `labels` (such as `bug` or `feature`; a new name makes a new
139 label) and `checks` (commands that should pass).
140- **Read an issue:** `GET {repo}/issues/{number}`. It lists every pull
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API141 request already made for it. A closed issue's `resolved_by` is the number
Issues and pull requests replace intents and attempts142 of the pull request that was merged.
143- **Open a pull request:** `POST {repo}/pulls` with `issue` (its number) and
144 `agent` (a label such as `claude-code`). Without an issue, send `title`.
145 The response has `pull.number` and `git.remote`, the pull request's own
146 fork. Clone it, commit, and push to it with the token. It starts as a
Pull requests from branches147 draft. If the change is already on a branch pushed to the repository,
148 send `branch` (and `title`, `body`) instead: no fork is made and the pull
149 request is ready at once.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)150- **Record the session** as you work, so people can see why a change was
Issues and pull requests replace intents and attempts151 made: `POST {repo}/pulls/{number}/session` with
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)152 `{"entries": [{"kind": "message", "text": "…"}]}`. Kinds are `prompt`,
153 `message`, `tool_call`, `tool_result`, `note`. Never include secrets;
154 sessions are as visible as the repository.
Issues and pull requests replace intents and attempts155- **Mark it ready:** `POST {repo}/pulls/{number}/ready` with `summary`, which
156 becomes the pull request's description.
157- **See what a pull request changes:** `GET {repo}/pulls/{number}/changes`.
Agents as a team: lifecycle, merge queue, billing and a new shell158- **Before going far**, read `overlaps` on `GET {repo}/pulls/{number}`:
159 other pull requests in progress changing the same files. `behind` says
160 whether main has moved since; if so, pull main into the fork and push.
Acceptance checks in sandboxes, line comments and review verdicts161- **Checks:** once a pull request is ready, g1t runs the issue's `checks`
162 against it in a clean sandbox. `GET {repo}/pulls/{number}` returns
163 `checks.results`, each with `passed` and `output`. If they failed, push a
164 fix and they run again.
Issues and pull requests replace intents and attempts165- **Comment** on an issue or a pull request:
Acceptance checks in sandboxes, line comments and review verdicts166 `POST {repo}/issues/{number}/comments` with `body`. On a pull request, add
167 `path` and `line` to comment on one line of the change.
168- **Review** someone else's pull request:
169 `POST {repo}/pulls/{number}/reviews` with `verdict` (`approve` or
170 `request_changes`) and `body`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look171- **Merge** (the Write role or higher on the repository):
Issues and pull requests replace intents and attempts172 `POST {repo}/pulls/{number}/merge`. This closes the issue it was for and
173 closes the other pull requests for that issue as superseded; send
174 `{"keep_issue_open": true}` if this is only part of the work. A `409`
175 saying main has moved means the fork is behind: pull main from
176 `https://g1t.sh/{owner}/{name}.git` into the fork, push, and merge again.
Docs worth reading, and kept that way177 With the merge queue on, merging adds the pull request to the queue
178 instead; `GET {repo}/queue` shows it being tested with the pull requests
179 ahead of it, and it lands only if that combination passes.
180
181## Hand work to g1t agents
182
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look183Agents, checks, workflows, the merge queue and deployments run on g1t's
184machines, so they need a paid workspace, or the one-time $5 trial after a
185card check. Checks, workflows and the merge queue on public repositories
186can also run from g1t's open-source pool, after the same card check.
187Agents never run from the pool. Each workspace decides how its agents
188reach a model: its own provider (connected under Integrations, billed by
189the provider) or g1t's hosted models; the sandbox is g1t's either way.
190When the plan refuses a start, these calls answer with a failure whose
191message says what to do and where (such as `/acme/-/billing`). When every
192agent slot of the workspace is busy, the message starts "Waiting for a
193free slot" and the work starts by itself when one finishes.
Docs worth reading, and kept that way194
195- **Hand off an outcome:** `POST {repo}/plans` with `brief`: what should be
196 true when the work is done. A planner reads the repository and proposes
197 issues, each with its checks, the files it touches, and what it depends
198 on. Read it with `GET {repo}/plans/{plan}` until `status` is `ready`
199 (a minute or two), then `POST {repo}/plans/{plan}/apply` with
200 `{"assign": true}`. Agents start at once on every issue that depends on
201 nothing and on the rest as what they depend on lands. `keep` opens only
202 some of the issues, by position counting from 1.
203- **Assign one issue:** `POST {repo}/issues/{number}/assign`. The agent
204 opens a pull request, meets the issue's checks, is reviewed by a second
205 agent, revises, and catches up when main moves. There is no model or
206 agent count to choose: to put more agents to work, assign more issues.
207- **Steer a working agent:** `POST {repo}/pulls/{number}/messages` with
208 `body`. It reads the message at its next step.
209- **g1t agents talk to each other.** A g1t agent asks the agent on another
210 pull request a question, or hands it work, with `message_agent` (`kind`
211 `question` or `handoff`, and `from_number`, its own pull request). The
212 other agent replies with `answer_message`
Agents asked while not at work are woken to answer213 (`POST {repo}/messages/{id}/answer`); one that is not at work is woken
214 to answer, in its own pull request's sandbox. Plans show these exchanges under
Docs worth reading, and kept that way215 "Agents talking". From any other caller, `message_agent` sends a plain
216 message.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)217
Issues and pull requests replace intents and attempts218Every one of these is also an MCP tool: `list_issues`, `get_issue`,
Docs worth reading, and kept that way219`create_issue`, `update_issue`, `close_issue`, `reopen_issue`,
220`assign_issue`, `plan_work`, `get_plan`, `apply_plan`, `list_labels`,
221`add_comment`, `list_pull_requests`, `get_pull_request`,
Issues and pull requests replace intents and attempts222`create_pull_request`, `record_session`, `read_session`,
223`mark_pull_request_ready`, `close_pull_request`,
Docs worth reading, and kept that way224`get_pull_request_changes`, `review_pull_request`, `merge_pull_request`,
225`get_merge_queue`, `message_agent`, `answer_message`, `take_messages`,
Docs: integrations, and your own model provider226`list_integrations`, `connect_integration`, `test_integration`,
Model providers: gateway tokens for endpoints, tidier rows, and the docs227`disconnect_integration`, `get_model_routes`, `set_model_routes`,
Webhooks: every event, to your own addresses, signed and retried228`get_context`, `import_issue`, `list_webhooks`, `create_webhook`,
229`update_webhook`, `delete_webhook`, `ping_webhook`,
Sidebar: the panels really slide230`list_webhook_deliveries`, `redeliver_webhook`,
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs231`list_workflows`, `list_workflow_runs`, `get_workflow_run`, `get_job_logs`,
232`dispatch_workflow`, `cancel_workflow_run`, `rerun_workflow_run`,
233`update_workflow`, `list_actions_secrets`, `set_actions_secret`,
234`delete_actions_secret`, `list_actions_variables`, `set_actions_variable`,
235`delete_actions_variable`,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look236`list_repos`, `get_repo`, `create_repo`, `update_repo`, `rename_repo`,
237`rename_branch`, `set_repo_visibility`, `archive_repo`, `unarchive_repo`,
238`transfer_repo`, `delete_repo`, `list_deleted_repos`, `restore_repo`,
239`purge_repo`, `get_repo_settings`, `update_repo_settings`, `list_events`,
240`create_workspace`, `delete_workspace`, and `whoami`. A g1t agent's own
241token can never change a repository's details, rename it or its branches,
242make it public or private, archive, transfer, delete, restore or purge it,
243or delete a workspace. MCP tools take the repository as `repo`, written
244`owner/name`.
245
246## Access and roles
247
248Everyone's access to a repository is a role: `read` (read, clone, open
249issues and pull requests, comment), `triage` (also label, assign, close),
250`write` (also push, merge, and put agents to work: anything that spends
251compute), `maintain` (also settings, branch protection, guardrails) or
252`admin` (also webhooks, secrets, deployments, domains, who has access,
253rename, archive, visibility, default branch). Owners of a workspace have
254admin on all of its repositories and alone transfer or delete them;
255members get the workspace's base permission (write unless owners change
256it); anyone can be given a role on one repository, as an outside
257collaborator; anyone reads a public repository. The highest wins. A
258private repository you cannot read answers `404`; one you can read but
259lack the role for answers `403` naming the role needed. An agent works
260with the role of the person it acts for on its repository, never more
261than `write`, and its token can never change who has access. An outside
262collaborator with `write` can put agents to work; the runs are charged to
263the repository's workspace, and their agents are told the project's memory,
264never the workspace's. Who can do what elsewhere: deployments are seen with
265`read` (on a public repository, by anyone, build logs included), deployed
266with `write`, configured (settings, domains) with `admin`; project settings
267and dependencies need `maintain`; repository webhooks, secrets and
268variables need `admin`, seeing them included; security findings need
269`write`, allowing or resolving a secret `admin`, upkeep `maintain`;
270enabling or disabling a workflow needs `maintain`; plans and project memory
271are read by anyone who can read the repository, and project memory is
272changed with `write`; workspace memory is for members. People: the
273workspace's Settings → Members (`g1t.sh/<owner>/-/people`, with an Outside
274collaborators tab and the Base permission for owners); a repository's
275Settings → Access (`g1t.sh/<owner>/<repo>/settings/access`); invitations
276are answered at `g1t.sh/<owner>/<repo>/invitations`.
277`GET {repo}/collaborators/{username}/permission` gives a role and what it
278allows. Guide: https://docs.g1t.sh/guides/access-and-roles/
279
280## Manage a repository
281
282People with the admin role rename it (`POST {repo}/rename` with `name`; the
283old address redirects), make it public or private
284(`POST {repo}/visibility` with `private` and its full name in `confirm`),
285archive or unarchive it (`POST {repo}/archive`, `POST {repo}/unarchive`),
286and owners of its workspace delete it (`DELETE {repo}` with its full name
287in `confirm`). A deleted
288repository can be restored for 30 days (`POST {repo}/restore`, listed by
289`GET /workspaces/{workspace}/repos/deleted`) and is then purged; its name
290stays taken until then, or until `POST {repo}/purge`. Maintain changes the
291description, `website` and `topics` with `PATCH {repo}`, admin the
292`default_branch`, and write renames branches with
293`POST {repo}/branches/{branch}/rename` and `new_name` (slashes in the
294branch URL-encoded); only admin renames the default branch. An archived
295repository is read-only: pushes and merges are refused, issues and pull
296requests are locked, and agents and workflows do not run on it.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)297
Docs: integrations, and your own model provider298## Integrations
299
300A workspace's owners connect it to outside systems on its **Integrations**
301page, or with `POST /workspaces/{workspace}/integrations`:
302
A catalogue of model providers, and settings that feel like settings303- **Its own model providers** (`anthropic`, `openai`, `gemini`, `xai`,
304 `mistral`, `deepseek`, `azure_openai`, `openrouter`, `groq`, `together`,
305 `fireworks`, `cerebras`, `anthropic_endpoint`, `openai_endpoint`), as many
306 as it uses, with each
Model providers: gateway tokens for endpoints, tidier rows, and the docs307 kind of work routed to one of them or to g1t's hosted models
308 (`PUT /workspaces/{workspace}/model-routes`). Those providers bill the
Prices are what g1t pays plus 20%, from the first second309 workspace; g1t charges nothing while it is being built out (later, only
310 each run's sandbox time, at cost plus 20%). Sandboxes never hold a key.
Docs: integrations, and your own model provider311- **Alerts** (`sentry`, `datadog`, `webhook`): each problem opens one issue
312 in a chosen repository, optionally with an agent put on it at once.
313 Senders sign requests to `https://api.g1t.sh/hooks/{integration}`.
314- **Trackers** (`jira`, `linear`): `GET {repo}/context?reference=TECH-1234`
315 fetches a ticket; `POST {repo}/issues/import` with `reference` (and
316 `assign`) opens a linked issue. Agents get tickets their work mentions in
317 their starting context. Ticket text is reference material, never
318 instructions.
319
Webhooks: every event, to your own addresses, signed and retried320## Webhooks
321
322`POST {repo}/hooks` (or `/workspaces/{workspace}/hooks` for every
323repository in a workspace) with `url` and optional `events` sends events
324to that HTTPS address as they happen, signed in `X-G1t-Signature-256`
325(HMAC-SHA256 of the body), retried for about seven hours. Deliveries,
326with request and response, are at `…/hooks/{id}/deliveries`.
327
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs328## GitHub Actions
329
330GitHub Actions workflows run on g1t unchanged, from `.g1t/workflows/`
331(g1t never reads `.github`): moving a repository is `git mv .github .g1t`.
332Runs, jobs and logs are at GitHub's own routes under
333`{repo}/actions/...`. A run on a pull request's head is a check: pending
334holds the merge, failure refuses it and sends a g1t agent back to fix it.
Secrets and variables: one list, rows per environment, for workflows and deployments335Secrets and variables are one list per repository (site:
336`g1t.sh/<owner>/<repo>/settings/secrets`) and per workspace: each row is a
337key, Secret or Config, the environments it applies to (all, or e.g.
338production/preview, or a job's `environment:`), and whether workflows,
339deployments or both read it. API: `{repo}/actions/secrets` and
340`{repo}/actions/variables` (GitHub's routes) with extra `environments`,
Deployments work end to end: fixes from the first live run341`available_to`, `repositories`, `note`, `id`. Trusted jobs get
Secrets and variables: one list, rows per environment, for workflows and deployments342`secrets.G1T_TOKEN` (the workspace's token; `GITHUB_TOKEN` is its alias),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look343which cannot change secrets. A pull request's runs and preview are trusted
344only when its author has `write` or higher on the repository (a member or
345an outside collaborator) or is g1t's agent; anyone else's run with config
346only. Guide:
Secrets and variables: one list, rows per environment, for workflows and deployments347https://docs.g1t.sh/guides/secrets-and-variables/
Docs: automations348
Projects: what a workspace builds and runs, first on every page349## Projects
350
351A project is what a workspace builds and runs; every repository is a
352project of its own name (`g1t.sh/<owner>/<project>` opens its overview; its
353code is under `/code`; every repository address still works). Deployments,
354secrets and variables belong to the project; branches, pull requests,
355review and merge rules to its repository (Settings → Repository). Guide:
356https://docs.g1t.sh/guides/projects/
357
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API358## Security
359
360A push that adds a known key or token format (AWS, GitHub, GitLab, Stripe
361live, Slack, Google, Anthropic, OpenAI, npm, g1t, SendGrid, PEM private
362keys, service-role JWTs) is refused with `file:line` in git's output; this
363includes an agent's push to its pull request. Never commit a secret: read it
364from the environment. A test fixture that only looks like one carries
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look365`g1t:allow-secret` in a comment on its line; someone with admin can also allow a
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API366finding once at `g1t.sh/<owner>/<project>/security`. Lockfiles (npm, pnpm,
367yarn, Cargo, Go, Python) are checked against OSV on every default-branch
368push and daily; each vulnerable package with a fix gets an issue "Upgrade
369<package> to <version>: fixes <advisory>" labelled `dependencies` and
370`security`, whose acceptance checks fail while the lockfile still resolves
371the vulnerable version and run the tests. An agent on one upgrades the
372package and fixes whatever the upgrade breaks, in the same pull request.
373Guide: https://docs.g1t.sh/guides/security/
374
Deployments: a preview for every pull request, production on g1t.page375## Deployments
376
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look377Part of the g1t plan ($20 a month per workspace, started by an owner
378under the workspace's Billing): 10 apps, 1M requests, 3M CPU ms, 3 custom
379domains and 200 build minutes a month; past that at cost + 20%. The trial
380never covers deployments. Then someone with admin on the repository
Projects: what a workspace builds and runs, first on every page381turns deployments on for a project (Settings → Deployments, or Deploy on
382its overview). Production deploys from the default branch to
383`https://<project>-<owner>.g1t.page` on each push; every branch with an
384open pull request gets a preview at
385`https://<project>-git-<branch>-<owner>.g1t.page` (a fork's pull request is
386`pr-<n>`), shown on it as the check `g1t / deploy`. Builds and running apps
387read the project's secrets and variables available to Deployments, each
388key's Production or Preview row. Workers projects (`wrangler.jsonc`) and
389static sites build without configuration. Previews come down when the pull
390request closes and after idle days. There is no API for deployments yet.
391Guide: https://docs.g1t.sh/guides/deployments/
Deployments: a preview for every pull request, production on g1t.page392
Search across all of g1t, Explore, and a command palette393## Search
394
395`GET https://api.g1t.sh/search?q=<query>&type=<type>` (MCP tool `search`)
396searches all of g1t: repositories (name, description, topics, README), code
397on default branches, issues, pull requests, people and workspaces. No token
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look398needed for public results; with one, private results the token's person
399can read are included (their workspaces' repositories, and those they were
400given a role on), checked against current membership and roles. `type` is
Search across all of g1t, Explore, and a command palette401`repositories`, `code`, `issues`, `pulls` or `people` (worked out from the
402qualifiers when left out); `page` and `per_page` (at most 50) page through.
403The query takes words, `"exact phrases"`, `-word` to leave out, and
404`repo:owner/name`, `org:<workspace>`, `language:<lang>`, `path:<prefix or
405*.glob>`, `is:issue`, `is:pr`, `is:open`, `is:closed`, `is:merged`,
406`author:<username>`, `label:<label>`. Code search matches any run of three
407characters or more; vendored directories, lockfiles, binaries and files
408over 512 KB are not indexed. Results give `counts` per type and each hit's
409`snippet` or code `lines` as parts with `highlight`. On the site:
410`https://g1t.sh/search?q=`, ⌘K, and `https://g1t.sh/explore` for public
411projects by activity, language (`?language=`) and topic (`?topic=`).
412`search_context` stays the search of one workspace's context hub. Guide:
413https://docs.g1t.sh/guides/search/
414
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)415## Facts
416
API and MCP server in Rust; a public index at the API root417- API base: `https://api.g1t.sh`. `GET /` lists every URL as a template.
418 Auth: `Authorization: Bearer g1t_…`. Public data needs no token. Errors are
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)419 `{"error": {"code": "…", "message": "…"}}` with codes `unauthenticated`
420 (401), `forbidden` (403), `not_found` (404), `conflict` (409), `invalid`
Device sign-in replaces registering and minting tokens over the API421 (422). The full description is at https://api.g1t.sh/openapi.json.
Workspaces own repositories422- Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths,
Issues and pull requests replace intents and attempts423 `{owner}` is the workspace. Pull request forks:
424 `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)425- Limits: 1 GB per repository, 32 MB per file, 100 MB per push.
Device sign-in replaces registering and minting tokens over the API426- Forgotten password: https://g1t.sh/forgot (the person does this, in a
427 browser).
Issues and pull requests replace intents and attempts428- Times are RFC 3339 in UTC.
OAuth 2.1 sign-in for MCP clients and other applications429- OAuth 2.1 for applications: metadata at
430 `https://api.g1t.sh/.well-known/oauth-authorization-server`; authorization
431 code with PKCE (S256), public clients, dynamic registration.
Acceptance checks in sandboxes, line comments and review verdicts432- A pull request whose checks have not passed is refused a merge with
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look433 `409`; someone who can merge can send `{"ignore_checks": true}`.
Acceptance checks in sandboxes, line comments and review verdicts434- Not available yet: merge commits made on the server.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look435- Pricing (https://g1t.sh/pricing): the forge is free. One plan, g1t, at
436 $20 a month per workspace with unlimited members, includes $10 of usage
437 at cost + 20% (unused does not roll over). Compute needs the plan or a
438 card check (never charged); the $5 trial needs a credit or debit card,
439 not a prepaid one. Private storage: 1 GB free, never charged (pushes to
440 private repositories stop past it), 10 GB on the plan. Limits: $100 in a
441 paid workspace's first month, rising as payments clear; owners set a
442 spend limit, prepay, or ask with Raise my limit. Caps: $2 a run and $10
443 an issue by default. A spend spike pauses new compute until an owner
444 chooses Keep going or Stop (`/<workspace>/-/billing`). Audit log: 90 days
445 on every plan.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)446
447## More
448
Device sign-in replaces registering and minting tokens over the API449- [Quickstart](https://docs.g1t.sh/quickstart/)
Docs worth reading, and kept that way450- [How g1t works](https://docs.g1t.sh/concepts/overview/)
Search across all of g1t, Explore, and a command palette451- [Search and Explore](https://docs.g1t.sh/guides/search/)
Docs worth reading, and kept that way452- [g1t agents](https://docs.g1t.sh/guides/g1t-agents/)
453- [Outcomes and plans](https://docs.g1t.sh/guides/outcomes/)
454- [Talking to agents](https://docs.g1t.sh/guides/talking-to-agents/)
455- [Bring your own agent](https://docs.g1t.sh/guides/bring-your-own-agent/)
456- [The merge queue](https://docs.g1t.sh/guides/merge-queue/)
457- [Sessions and why-blame](https://docs.g1t.sh/guides/why-blame/)
Device sign-in replaces registering and minting tokens over the API458- [Forks and branches](https://docs.g1t.sh/concepts/forks/)
Docs worth reading, and kept that way459- [Accounts and sign-in](https://docs.g1t.sh/guides/authentication/)
460- [Workspaces and tokens](https://docs.g1t.sh/guides/workspaces/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look461- [Access and roles](https://docs.g1t.sh/guides/access-and-roles/)
462- [Managing a repository](https://docs.g1t.sh/guides/managing-repositories/)
Docs: integrations, and your own model provider463- [Integrations](https://docs.g1t.sh/guides/integrations/)
Model providers: gateway tokens for endpoints, tidier rows, and the docs464- [Model providers](https://docs.g1t.sh/guides/models/)
Webhooks: every event, to your own addresses, signed and retried465- [Webhooks](https://docs.g1t.sh/guides/webhooks/)
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs466- [GitHub Actions](https://docs.g1t.sh/guides/actions/)
Docs worth reading, and kept that way467- [Usage and billing](https://docs.g1t.sh/guides/usage-and-billing/)
Docs as their own app; shared theme package468- [Git](https://docs.g1t.sh/guides/git/)
Docs worth reading, and kept that way469- [MCP tools](https://docs.g1t.sh/reference/mcp/)
Merge branch 'worktree-agent-ab2e39e11a6493412'470- [API reference](https://docs.g1t.sh/reference/api/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look471- [Source](https://g1t.sh/flagon-io/g1t), MIT licensed
472
473## Help, status and policies
474
475- [Status](https://g1t.sh/status): whether each part of g1t is working now; the same as JSON at https://g1t.sh/status.json
476- [Support](https://g1t.sh/support): where to get help (hey@flagon.io, hey@flagon.io)
477- [Security](https://g1t.sh/security): how g1t protects code and accounts, and responsible disclosure (hey@flagon.io, https://g1t.sh/.well-known/security.txt)
478- [Policies](https://g1t.sh/policies): [Terms of Service](https://g1t.sh/policies/terms), [Privacy Policy](https://g1t.sh/policies/privacy), [Acceptable Use](https://g1t.sh/policies/acceptable-use), [Refunds and Cancellation](https://g1t.sh/policies/refunds), [Subprocessors](https://g1t.sh/policies/subprocessors)
479- g1t is made by Flagon, Inc. (https://www.flagon.io)

This file's history is long; its oldest lines are credited to the oldest commit read.