Skip to content
931 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs1import type { ActionsApi } from "./actions";
Billing accounts, terms and enterprises; g1t is no longer free2import type { BillingAdminApi, BillingApi } from "./billing";
Deployments: a preview for every pull request, production on g1t.page3import type { DeploymentsApi } from "./deployments";
Projects: what a workspace builds and runs, first on every page4import type { ProjectsApi } from "./projects";
Events service in Rust, with RFC 3339 times and accurate push events5import type { EventsApi } from "./events";
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace6import type { IdentityAdminApi, IdentityApi } from "./identity";
Integrations: your own model provider, alerts that open issues, tickets agents read7import type { IntegrationsApi } from "./integrations";
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member8import type { PackagesApi } from "./packages";
Webhooks: every event, to your own addresses, signed and retried9import type { WebhooksApi } from "./webhooks";
Rust repos service with shipping; pull requests kept in the model10import type { ReposApi } from "./repos";
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar11import type { PullDetail, WorkApi } from "./work";
12import type { Result } from "./result";
Fast pages, required checks on the branch, self-hosted runners, honest incidents13import type { RunnersApi } from "./runners";
API and MCP server, Rust identity service, registration, site redesign14
15/** A service binding, as far as these clients need it. */
16export type ServiceBinding = {
17 fetch(input: string, init?: RequestInit): Promise<Response>;
18};
19
20/**
21 * Calls a method on a service that speaks the JSON protocol used by the
22 * Rust services: `POST /rpc/<method>` with the arguments as the body.
23 */
24async function rpc<T>(
25 service: ServiceBinding,
26 method: string,
27 args: object,
28): Promise<T> {
29 // The hostname is ignored; a service binding always reaches its service.
30 const response = await service.fetch(`https://service/rpc/${method}`, {
31 method: "POST",
32 headers: { "content-type": "application/json" },
33 body: JSON.stringify(args),
34 });
35 if (!response.ok) {
36 throw new Error(`${method} failed with status ${response.status}`);
37 }
Agents as a team: lifecycle, merge queue, billing and a new shell38 return (await response.json()) as T;
API and MCP server, Rust identity service, registration, site redesign39}
40
41export function identityClient(service: ServiceBinding): IdentityApi {
42 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
43 return {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look44 register: (username, email, password, inviteCode, client) =>
45 call("register", { username, email, password, invite_code: inviteCode ?? null, client: client ?? null }),
46 signIn: (username, password, client) => call("sign_in", { username, password, client: client ?? null }),
Merge main (membership, two-factor, GitHub repo roles) into tokens47 twoFactorSignIn: (challenge, code, client) => call("two_factor_sign_in", { challenge, code, client: client ?? null }),
API and MCP server, Rust identity service, registration, site redesign48 signOut: (sessionToken) => call("sign_out", { sessionToken }),
Email verification, password reset, and Git for AI scale positioning49 resendVerification: (user) => call("resend_verification", { user }),
50 verifyEmail: (token) => call("verify_email", { token }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look51 requestPasswordReset: (email, client) => call("request_password_reset", { email, client: client ?? null }),
Email verification, password reset, and Git for AI scale positioning52 resetPassword: (token, password) =>
53 call("reset_password", { token, password }),
Device sign-in replaces registering and minting tokens over the API54 deviceStart: (clientName) => call("device_start", { clientName }),
55 deviceLookup: (userCode) => call("device_lookup", { userCode }),
56 deviceResolve: (userCode, user, approve) =>
57 call("device_resolve", { userCode, user, approve }),
58 deviceClaim: (deviceCode) => call("device_claim", { deviceCode }),
OAuth 2.1 sign-in for MCP clients and other applications59 oauthAuthorize: (user, approval) => call("oauth_authorize", { user, ...approval }),
60 oauthExchange: (code, codeVerifier, clientId, redirectUri) =>
61 call("oauth_exchange", { code, codeVerifier, clientId, redirectUri }),
62 oauthRefresh: (refreshToken, clientId) =>
63 call("oauth_refresh", { refreshToken, clientId }),
64 listOAuthGrants: (user) => call("list_oauth_grants", { user }),
65 revokeOAuthGrant: (user, id) => call("revoke_oauth_grant", { user, id }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step66 updateOAuthGrant: (user, id, grant) =>
67 call("update_oauth_grant", { user, id, scopes: grant.scopes }),
Workspaces own repositories68 createWorkspace: (user, slug, name) => call("create_workspace", { user, slug, name }),
69 getWorkspace: (slug) => call("get_workspace", { slug }),
Merge branch 'worktree-agent-a2013627e5ea4ab13'70 workspaceResidency: (slug) => call("workspace_residency", { slug }),
71 setWorkspaceResidency: (actor, slug, residency) => call("set_workspace_residency", { actor, slug, residency }),
Workspaces own repositories72 listMembers: (slug, viewer) => call("list_members", { slug, viewer }),
73 addMember: (actor, slug, username) => call("add_member", { actor, slug, username }),
74 removeMember: (actor, slug, username) =>
Merge main (membership, two-factor, GitHub repo roles) into tokens75 call("remove_member", { actor, slug, username, surface: "web" }),
76 updateMember: (actor, slug, username, change) =>
77 call("update_member", { actor, slug, username, role: change.role ?? null, org_roles: change.org_roles ?? null, surface: "web" }),
78 transferOwnership: (actor, slug, username) => call("transfer_ownership", { actor, slug, username, surface: "web" }),
79 leaveWorkspace: (user, slug) => call("leave_workspace", { user, slug, surface: "web" }),
80 setMemberPrivileges: (actor, slug, change) => call("set_member_privileges", { actor, slug, privileges: change, surface: "web" }),
81 setTwoFactorRequirement: (actor, slug, required) =>
82 call("set_two_factor_requirement", { actor, slug, required, surface: "web" }),
Agents as a team: lifecycle, merge queue, billing and a new shell83 updateWorkspace: (actor, slug, details) =>
84 call("update_workspace", { actor, slug, ...details }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains85 renameWorkspace: (actor, slug, newSlug) => call("rename_workspace", { actor, slug, newSlug }),
86 checkWorkspaceRename: (actor, slug, newSlug) =>
87 call("check_workspace_rename", { actor, slug, newSlug }),
88 resolveSlug: (slug) => call("resolve_slug", { slug }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look89 deleteWorkspace: (actor, slug, confirm) => call("delete_workspace", { actor, slug, confirm }),
90 checkWorkspaceDeletion: (actor, slug) => call("check_workspace_deletion", { actor, slug }),
Workspace names and icons, and a component kit for every control91 setWorkspaceAvatar: (actor, slug, image) => call("set_workspace_avatar", { actor, slug, image }),
92 setUserAvatar: (user, image) => call("set_user_avatar", { user, image }),
Agents as a team: lifecycle, merge queue, billing and a new shell93 listWorkspaceTokens: (slug, viewer) => call("list_workspace_tokens", { slug, viewer }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step94 createWorkspaceToken: (actor, slug, name, grant) =>
95 call("create_workspace_token", {
96 actor,
97 slug,
98 name,
99 scopes: grant?.scopes ?? null,
100 ttl_seconds: grant?.ttlSeconds ?? null,
Settings: fine-grained tokens, workspace token Admin, workspace personal access token rules101 admin: grant?.admin ?? false,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step102 }),
Agents as a team: lifecycle, merge queue, billing and a new shell103 removeWorkspaceToken: (actor, slug, id) =>
104 call("remove_workspace_token", { actor, slug, id }),
Settings: fine-grained tokens, workspace token Admin, workspace personal access token rules105 createFineGrainedToken: (user, input) =>
106 call("create_fine_grained_token", {
107 user,
108 name: input.name,
109 description: input.description ?? null,
110 ttl_seconds: input.ttlSeconds,
111 workspace: input.workspace,
112 repository_selection: input.repositorySelection,
113 repositories: input.repositories,
114 permissions: input.permissions,
115 }),
116 updateFineGrainedToken: (user, id, change) =>
117 call("update_fine_grained_token", {
118 user,
119 id,
120 name: change.name ?? null,
121 description: change.description ?? null,
122 repository_selection: change.repositorySelection ?? null,
123 repositories: change.repositories ?? null,
124 permissions: change.permissions ?? null,
125 }),
126 getTokenPolicy: (slug, viewer) => call("get_token_policy", { slug, viewer }),
127 setTokenPolicy: (actor, slug, change) =>
128 call("set_token_policy", {
129 actor,
130 slug,
131 allow_classic: change.allowClassic ?? null,
132 allow_fine_grained: change.allowFineGrained ?? null,
133 require_approval: change.requireApproval ?? null,
134 max_lifetime_days: change.maxLifetimeDays ?? null,
135 forbid_no_expiry: change.forbidNoExpiry ?? null,
136 surface: "web",
137 }),
138 listMemberTokens: (actor, slug, filter = {}) =>
139 call("list_member_tokens", { actor, slug, status: filter.status ?? null, kind: filter.kind ?? null }),
140 reviewTokenRequest: (actor, slug, id, approve, reason) =>
141 call("review_token_request", { actor, slug, id, approve, reason: reason ?? null, surface: "web" }),
142 revokeMemberToken: (actor, slug, id, reason) =>
143 call("revoke_member_token", { actor, slug, id, reason: reason ?? null, surface: "web" }),
API and MCP server, Rust identity service, registration, site redesign144 userForSession: (sessionToken) => call("user_for_session", { sessionToken }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look145 registration: () => call("registration", {}),
146 listInvites: (user) => call("list_invites", { user }),
147 createInvite: (user, options = {}) =>
148 call("create_invite", { user, email: options.email ?? null, workspace: options.workspace ?? null }),
149 revokeInvite: (user, id) => call("revoke_invite", { user, id }),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas150 checkInvite: (code, client, options = {}) =>
151 call("check_invite", {
152 code,
153 client: client ?? null,
154 viewer: options.viewer ?? null,
155 any_status: options.anyStatus ?? false,
156 }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look157 acceptInvite: (user, code) => call("accept_invite", { user, code }),
158 inviteMember: (actor, slug, email) => call("invite_member", { actor, slug, email }),
159 workspaceInvites: (slug, viewer) => call("workspace_invites", { slug, viewer }),
160 revokeWorkspaceInvite: (actor, slug, id) => call("revoke_workspace_invite", { actor, slug, id }),
161 requestAccess: (email, about, client) => call("request_access", { email, about, client: client ?? null }),
API and MCP server, Rust identity service, registration, site redesign162 userForGitCredentials: (username, secret) =>
163 call("user_for_git_credentials", { username, secret }),
164 userForAccessToken: (token) => call("user_for_access_token", { token }),
165 userForSshKey: (fingerprint) => call("user_for_ssh_key", { fingerprint }),
166 userByUsername: (username) => call("user_by_username", { username }),
What happened across an outcome, as a feed beside its graph167 usernames: (ids) => call("usernames", { ids }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains168 profile: (username) => call("profile", { username }),
169 updateProfile: (actor, fields) => call("update_profile", { actor, ...fields }),
170 profileWorkspaces: (username, viewer, publicIn) =>
171 call("profile_workspaces", { username, viewer, public: publicIn }),
API and MCP server, Rust identity service, registration, site redesign172 listSshKeys: (user) => call("list_ssh_keys", { user }),
173 addSshKey: (user, title, publicKey) =>
174 call("add_ssh_key", { user, title, publicKey }),
175 removeSshKey: (user, id) => call("remove_ssh_key", { user, id }),
176 listAccessTokens: (user) => call("list_access_tokens", { user }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step177 createAccessToken: (user, name, ttlSeconds, grant) =>
178 call("create_access_token", {
179 user,
180 name,
181 ttlSeconds,
182 scopes: grant?.scopes ?? null,
183 listed: grant?.listed ?? false,
184 }),
185 updateAccessToken: (user, id, grant) =>
186 call("update_access_token", { user, id, scopes: grant.scopes }),
Agents as a team: lifecycle, merge queue, billing and a new shell187 createAgentToken: (onBehalfOf, scope, ttlSeconds) =>
188 call("create_agent_token", { onBehalfOf, scope, ttlSeconds }),
API and MCP server, Rust identity service, registration, site redesign189 removeAccessToken: (user, id) => call("remove_access_token", { user, id }),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API190 createRunCredential: (input) => call("create_run_credential", input),
191 bindRunCredentials: (tokenHashes, runId) => call("bind_run_credentials", { tokenHashes, runId }),
192 revokeRunCredentials: (target) => call("revoke_run_credentials", target),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look193 // Who has access to a repository; see access.ts.
194 repoAccess: (owner, name, viewer) => call("repo_access", { viewer, path: { namespace: owner, name } }),
195 addCollaborator: (actor, owner, name, invitee, role) =>
196 call("add_collaborator", { actor, path: { namespace: owner, name }, invitee, role }),
197 setCollaboratorRole: (actor, owner, name, username, role) =>
198 call("set_collaborator_role", { actor, path: { namespace: owner, name }, username, role }),
199 removeCollaborator: (actor, owner, name, username) =>
200 call("remove_collaborator", { actor, path: { namespace: owner, name }, username }),
201 collaboratorPermission: (viewer, owner, name, username) =>
202 call("collaborator_permission", { viewer, path: { namespace: owner, name }, username }),
203 myRepoInvitations: (user) => call("my_repo_invitations", { user }),
204 respondRepoInvitation: (user, id, accept) => call("respond_repo_invitation", { user, id, accept }),
205 revokeRepoInvitation: (actor, owner, name, id) =>
206 call("revoke_repo_invitation", { actor, path: { namespace: owner, name }, id }),
207 setBasePermission: (actor, slug, base) => call("set_base_permission", { actor, slug, base_permission: base }),
208 outsideCollaborators: (viewer, slug) => call("outside_collaborators", { viewer, slug }),
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca209 // A repository's deploy keys; see deploy-keys.ts.
210 listDeployKeys: (viewer, owner, name) => call("list_deploy_keys", { viewer, path: { namespace: owner, name } }),
211 addDeployKey: (actor, owner, name, key) =>
212 call("add_deploy_key", { actor, path: { namespace: owner, name }, title: key.title, key: key.key, read_only: key.readOnly }),
213 removeDeployKey: (actor, owner, name, id) => call("remove_deploy_key", { actor, path: { namespace: owner, name }, id }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar214 // Teams; see teams.ts.
215 listTeams: (viewer, workspace, query) => call("list_teams", { viewer, workspace, query: query ?? null }),
216 getTeam: (viewer, workspace, team) => call("get_team", { viewer, workspace, team }),
217 createTeam: (actor, workspace, team) => call("create_team", { actor, workspace, ...team }),
Merge branch 'worktree-agent-ad7c6d88d93adc817'218 setTeamCreation: (actor, slug, setting) => call("set_team_creation", { actor, slug, team_creation: setting }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar219 updateTeam: (actor, workspace, team, changes) => call("update_team", { actor, workspace, team, ...changes }),
220 deleteTeam: (actor, workspace, team) => call("delete_team", { actor, workspace, team }),
221 teamMembers: (viewer, workspace, team, includeChildTeams) =>
222 call("team_members", { viewer, workspace, team, include_child_teams: includeChildTeams ?? false }),
223 setTeamMember: (actor, workspace, team, username, role) =>
224 call("set_team_member", { actor, workspace, team, username, role }),
225 removeTeamMember: (actor, workspace, team, username) =>
226 call("remove_team_member", { actor, workspace, team, username }),
227 childTeams: (viewer, workspace, team) => call("child_teams", { viewer, workspace, team }),
228 teamRepos: (viewer, workspace, team) => call("team_repos", { viewer, workspace, team }),
229 setTeamRepo: (actor, workspace, team, owner, name, role) =>
230 call("set_team_repo", { actor, workspace, team, repo: { namespace: owner, name }, role }),
231 removeTeamRepo: (actor, workspace, team, owner, name) =>
232 call("remove_team_repo", { actor, workspace, team, repo: { namespace: owner, name } }),
233 userTeams: (viewer, workspace, username) => call("user_teams", { viewer, workspace, username }),
234 teamMemberships: (viewer, workspace) => call("team_memberships", { viewer, workspace }),
API and MCP server, Rust identity service, registration, site redesign235 };
236}
Rust repos service with shipping; pull requests kept in the model237
Agents and memory, checks and conflicts, profiles, slug renames, custom domains238/**
239 * The slug a renamed workspace has now, for a `workspace.renamed` handler:
240 * asked of identity by the workspace's id, so that renames delivered twice
241 * or out of order converge. Falls back to the event's `to`.
242 */
243export async function currentWorkspaceSlug(
244 identity: ServiceBinding,
245 renamed: { workspaceId: string; to: string },
246): Promise<string> {
247 const names = await identityClient(identity).usernames([renamed.workspaceId]);
248 return names[renamed.workspaceId] ?? renamed.to;
249}
250
251/** The slugs whose rows move to `current`: the two a rename names, less `current`. */
252export function staleSlugs(renamed: { from: string; to: string }, current: string): string[] {
253 return [...new Set([renamed.from, renamed.to])].filter((slug) => slug !== current);
254}
255
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look256/**
257 * Where a transferred repository is now, as `namespace/name`, for a
258 * `repo.transferred` handler: asked of repos by id, so transfers delivered
259 * twice or out of order converge. Falls back to the event's destination.
260 */
261export async function currentRepoPath(
262 repos: ServiceBinding,
263 transferred: { repoId: string; name: string; to: string },
264): Promise<string> {
265 const path = await rpc<{ namespace: string; name: string } | null>(repos, "path_by_id", { id: transferred.repoId });
266 return path ? `${path.namespace}/${path.name}` : `${transferred.to}/${transferred.name}`;
267}
268
269/** The paths whose rows move to `current`: the two a transfer names, less `current`. */
270export function stalePaths(transferred: { name: string; from: string; to: string }, current: string): string[] {
271 return [...new Set([transferred.from, transferred.to].map((ns) => `${ns}/${transferred.name}`))].filter(
272 (path) => path !== current,
273 );
274}
275
276/**
277 * A repository's path change, from `repo.transferred` or `repo.renamed`,
278 * read the same way: the two paths (`namespace/name`) the event names, old
279 * then new. Null for any other event.
280 */
281export type RepoMove = { repoId: string; paths: [string, string] };
282
283export function repoMove(event: { type: string; data: unknown }): RepoMove | null {
284 const data = event.data as Record<string, string>;
285 if (event.type === "repo.transferred") {
286 return { repoId: data.repoId!, paths: [`${data.from}/${data.name}`, `${data.to}/${data.name}`] };
287 }
288 if (event.type === "repo.renamed") {
289 return { repoId: data.repoId!, paths: [`${data.namespace}/${data.from}`, `${data.namespace}/${data.to}`] };
290 }
291 return null;
292}
293
294/**
295 * Where a moved repository is now, as `namespace/name`: asked of repos by
296 * id, so moves delivered twice or out of order converge. Falls back to the
297 * event's new path.
298 */
299export async function currentMovedPath(repos: ServiceBinding, move: RepoMove): Promise<string> {
300 const path = await rpc<{ namespace: string; name: string } | null>(repos, "path_by_id", { id: move.repoId });
301 return path ? `${path.namespace}/${path.name}` : move.paths[1];
302}
303
304/** The paths whose rows move to `current`: the two a move names, less `current`. */
305export function staleMovedPaths(move: RepoMove, current: string): string[] {
306 return [...new Set(move.paths)].filter((path) => path !== current);
307}
308
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace309/** Staff-only identity. Only sudo binds to it; see `IdentityAdminApi`. */
310export function identityAdminClient(service: ServiceBinding): IdentityAdminApi {
311 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
312 return {
313 workspaces: (query) => call("admin_workspaces", { query: query ?? null }),
314 workspace: (slug) => call("admin_workspace", { slug }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look315 waitlist: (query, status) => call("admin_waitlist", { query: query ?? null, status: status ?? null }),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas316 waitlistPending: () => call("admin_waitlist_pending", {}),
317 decideWaitlist: (id, approve, staff, note) => call("admin_decide_waitlist", { id, approve, staff, note: note ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look318 invites: (query) => call("admin_invites", { query: query ?? null }),
319 revokeInvite: (id, staff) => call("admin_revoke_invite", { id, staff }),
320 mintInvite: (email, staff) => call("admin_mint_invite", { email, staff }),
321 grantInvites: (target, name, amount, note, staff) =>
322 call("admin_grant_invites", { target, name, amount, note, staff }),
323 inviteTree: (username) => call("admin_invite_tree", { username }),
324 workspaceInvites: (slug) => call("admin_workspace_invites", { slug }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member325 deletedWorkspaces: () => call("admin_deleted_workspaces", {}),
326 restoreWorkspace: (workspaceId, staff) => call("admin_restore_workspace", { workspaceId, staff }),
327 purgeWorkspace: (workspaceId, staff, confirm) => call("admin_purge_workspace", { workspaceId, staff, confirm }),
Merge branch 'worktree-agent-a8385d293d42c913a'328 aliases: () => call("admin_aliases", {}),
329 setAlias: (alias, workspace, note, staff) => call("admin_set_alias", { alias, workspace, note, staff }),
330 removeAlias: (alias, reason, staff) => call("admin_remove_alias", { alias, reason, staff }),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace331 };
332}
333
Rust repos service with shipping; pull requests kept in the model334export function reposClient(service: ServiceBinding): ReposApi {
335 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
336 return {
337 get: (path, viewer) => call("get", { path, viewer }),
338 getById: (id, viewer) => call("get_by_id", { id, viewer }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents339 readable: (ids, viewer) => call("readable", { ids, viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains340 publicNamespaces: (ownerId) => call("public_namespaces", { ownerId }),
Rust repos service with shipping; pull requests kept in the model341 list: (viewer, options = {}) => call("list", { viewer, ...options }),
342 create: (owner, input) => call("create", { owner, ...input }),
Agents as a team: lifecycle, merge queue, billing and a new shell343 update: (actor, path, changes) => call("update", { actor, path, ...changes }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look344 transfer: (actor, path, to) => call("transfer", { actor, path, to }),
345 delete: (actor, path, confirm) => call("delete", { actor, path, confirm }),
346 deleted: (viewer, namespace) => call("deleted", { viewer, namespace }),
347 restore: (actor, path) => call("restore", { actor, path }),
348 purge: (actor, path, confirm) => call("purge", { actor, path, confirm }),
349 rename: (actor, path, name) => call("rename", { actor, path, name }),
350 archive: (actor, path, archived) => call("archive", { actor, path, archived }),
351 setVisibility: (actor, path, isPrivate, confirm) => call("set_visibility", { actor, path, isPrivate, confirm }),
352 setDefaultBranch: (actor, path, branch) => call("set_default_branch", { actor, path, branch }),
353 renameBranch: (actor, path, from, to) => call("rename_branch", { actor, path, from, to }),
354 resolveBranch: (repoId, branch) => call("resolve_branch", { repoId, branch }),
355 statusById: (id) => call("status_by_id", { id }),
Merge branch 'worktree-agent-a2013627e5ea4ab13'356 storageOptions: () => call("storage_options", {}),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look357 resolvePath: (path) => call("resolve_path", { path }),
Rust repos service with shipping; pull requests kept in the model358 tree: (path, viewer, ref, treePath) =>
359 call("tree", { path, viewer, ref, treePath }),
360 blob: (path, viewer, ref, filePath) =>
361 call("blob", { path, viewer, ref, filePath }),
362 log: (path, viewer, ref, limit) => call("log", { path, viewer, ref, limit }),
Agents as a team: lifecycle, merge queue, billing and a new shell363 blame: (path, viewer, ref, filePath) => call("blame", { path, viewer, ref, filePath }),
Issues and pull requests replace intents and attempts364 forkForPull: (sourceId, pullId, actor) =>
365 call("fork_for_pull", { sourceId, pullId, actor }),
Rust repos service with shipping; pull requests kept in the model366 gitAccess: (path, viewer, service) =>
367 call("git_access", { path, viewer, service }),
Pull requests from branches368 branches: (path, viewer) => call("branches", { path, viewer }),
Branches and Tags pages, each file's last commit, and the branch menu on files369 lastCommits: (path, viewer, ref, treePath) => call("last_commits", { path, viewer, ref, treePath }),
Merge project overview: one branch_drift call, spliced histories, cached tags, 6 repos calls instead of 25370 branchDrift: (path, viewer, base, heads) => call("branch_drift", { path, viewer, base, heads }),
Branches and Tags pages, each file's last commit, and the branch menu on files371 tags: (path, viewer) => call("tags", { path, viewer }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97372 about: (path, viewer) => call("about", { path, viewer }),
373 languages: (path, viewer) => call("languages", { path, viewer }),
374 contributors: (path, viewer) => call("contributors", { path, viewer }),
375 license: (path, viewer) => call("license", { path, viewer }),
376 stars: (path, viewer) => call("stars", { path, viewer }),
377 star: (actor, path, starred) => call("star", { path, actor, starred }),
378 stargazers: (path, viewer, page) => call("stargazers", { path, viewer, page: page ?? null }),
379 starred: (username, viewer) => call("starred", { username, viewer }),
380 releases: (path, viewer) => call("releases", { path, viewer }),
381 release: (path, viewer, which) => call("release", { path, viewer, id: which.id ?? null, tag: which.tag ?? null, latest: which.latest ?? false }),
382 createRelease: (actor, path, release) => call("create_release", { path, actor, ...release }),
383 updateRelease: (actor, path, id, change) => call("update_release", { path, actor, id, ...change }),
384 deleteRelease: (actor, path, id) => call("delete_release", { path, actor, id }),
Download ZIP from the Code button; a slimmer lifecycle panel; agent steps say what was done, not sandbox paths385 listFiles: (repoId, ref, limit) => call("list_files", { repoId, ref, skipDirs: [], limit }),
386 rawBlobs: (repoId, hashes, maxBytes) => call("raw_blobs", { repoId, hashes, maxBytes }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents387 commitFile: (repo, actor, file) => call("commit_file", { repo, actor, ...file }),
Pull requests from branches388 land: (sourceId, actor, branch) => call("land", { sourceId, actor, branch }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar389 compare: (repoId, viewer, base, head, baseBranch) => call("compare", { repoId, viewer, base, head, baseBranch }),
Merge branch 'worktree-agent-ac5b181a013e54348'390 claimBackups: (limit, maxRunning) => call("claim_backups", { limit, maxRunning }),
391 // The sandbox's own calls are snake_case (they come through the API).
392 failBackup: (jobId, token, error) => call("backup_fail", { job_id: jobId, token, error }),
Rust repos service with shipping; pull requests kept in the model393 };
394}
Work service in Rust, with RFC 3339 timestamps395
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar396/**
397 * `PullDetail`'s own fields that the work service writes in snake_case:
398 * `g1t_contracts::work::PullDetail` has no camelCase renaming, though what
399 * it holds (`Pull`, `CheckRun` and the rest) does. Each with its name here.
400 */
401const PULL_DETAIL_FIELDS = [
402 ["review_pending", "reviewPending"],
403 ["earlier_checks", "earlierChecks"],
404 ["required_checks", "requiredChecks"],
405 ["code_owners", "codeOwners"],
406] as const;
407
408/**
409 * A pull request's detail as the work service sent it, with its own fields
410 * in the camelCase this package uses: read at the edge, by `workClient`'s
411 * `getPull`. Either spelling is taken, so a service that already sends
412 * camelCase reads the same.
413 */
414export function pullDetailFromWire(raw: Record<string, unknown>): PullDetail {
415 const detail: Record<string, unknown> = { ...raw };
416 for (const [snake, camel] of PULL_DETAIL_FIELDS) {
417 if (snake in detail) {
418 if (!(camel in detail)) detail[camel] = detail[snake];
419 delete detail[snake];
420 }
421 }
422 if (typeof detail.reviewPending !== "boolean") detail.reviewPending = false;
423 return detail as PullDetail;
424}
425
Work service in Rust, with RFC 3339 timestamps426export function workClient(service: ServiceBinding): WorkApi {
427 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
428 return {
Issues and pull requests replace intents and attempts429 openIssue: (actor, repo, input) => call("open_issue", { actor, repo, ...input }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step430 delegateIssue: (actor, repo, input) => call("delegate_issue", { actor, repo, ...input }),
Issues and pull requests replace intents and attempts431 listIssues: (repo, viewer, filter = {}) => call("list_issues", { repo, viewer, ...filter }),
432 getIssue: (repo, number, viewer) => call("get_issue", { repo, number, viewer }),
433 updateIssue: (actor, repo, number, input) =>
434 call("update_issue", { actor, repo, number, ...input }),
435 closeIssue: (actor, repo, number, reason) =>
436 call("close_issue", { actor, repo, number, reason }),
437 reopenIssue: (actor, repo, number) => call("reopen_issue", { actor, repo, number }),
438 listLabels: (repo, viewer) => call("list_labels", { repo, viewer }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar439 saveLabel: (actor, repo, label) => call("save_label", { actor, repo, ...label }),
440 deleteLabel: (actor, repo, name) => call("delete_label", { actor, repo, name }),
441 addDefaultLabels: (actor, repo) => call("add_default_labels", { actor, repo }),
442 setLabels: (actor, repo, number, labels, change = "set") =>
443 call("set_labels", { actor, repo, number, labels, change }),
444 listMilestones: (repo, viewer, state) => call("list_milestones", { repo, viewer, state }),
445 getMilestone: (repo, number, viewer) => call("get_milestone", { repo, number, viewer }),
446 saveMilestone: (actor, repo, milestone) => call("save_milestone", { actor, repo, ...milestone }),
447 deleteMilestone: (actor, repo, number) => call("delete_milestone", { actor, repo, number }),
Issues and pull requests replace intents and attempts448 counts: (repo, viewer) => call("counts", { repo, viewer }),
Acceptance checks in sandboxes, line comments and review verdicts449 addComment: (actor, repo, number, comment) =>
450 call("add_comment", { actor, repo, number, ...comment }),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts451 editComment: (actor, repo, commentId, body) => call("edit_comment", { actor, repo, commentId, body }),
452 deleteComment: (actor, repo, commentId) => call("delete_comment", { actor, repo, commentId }),
Acceptance checks in sandboxes, line comments and review verdicts453 startChecks: (pullId) => call("start_checks", { pullId }),
454 reportChecks: (runId, token, report) =>
455 call("report_checks", { runId, token, ...report }),
Agents as a team: lifecycle, merge queue, billing and a new shell456 startReview: (pullId) => call("start_review", { pullId }),
457 failReview: (runId, token, error) => call("report_review", { runId, token, error }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains458 startMergecheck: (pullId) => call("start_mergecheck", { pullId }),
459 failMergecheck: (pullId, token, error) => call("report_mergecheck", { pullId, token, error }),
Agents as a team: lifecycle, merge queue, billing and a new shell460 advance: (pullId) => call("advance", { pullId }),
461 stall: (pullId, reason) => call("stall", { pullId, reason }),
462 managedPulls: (repoId) => call("managed_pulls", { repoId }),
463 queue: (repo, viewer) => call("queue", { repo, viewer }),
464 queueBuild: (repoId) => call("queue_build", { repoId }),
465 failQueue: (entryId, token, error) => call("report_queue", { entryId, token, error }),
466 removeFromQueue: (actor, repo, number) => call("remove_from_queue", { actor, repo, number }),
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request467 messageAgent: (actor, repo, number, body) => call("message_agent", { actor, repo, number, body }),
Agents as a team: lifecycle, merge queue, billing and a new shell468 catchUpJob: (pullId) => call("catch_up_job", { pullId }),
Agents asked while not at work are woken to answer469 wakeForMessages: (pullId) => call("wake_for_messages", { pullId }),
Agents as a team: lifecycle, merge queue, billing and a new shell470 getSettings: (repo, viewer) => call("get_settings", { repo, viewer }),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge471 // Rulesets travel in snake_case (rules.ts).
472 listRulesets: (owner, viewer, includeParents = false) =>
473 call("list_rulesets", { viewer, ...owner, include_parents: includeParents }),
474 getRuleset: (owner, id, viewer) => call("get_ruleset", { viewer, ...owner, id }),
475 saveRuleset: (actor, owner, ruleset, id) => call("save_ruleset", { actor, ...owner, id: id ?? null, ruleset }),
476 deleteRuleset: (actor, owner, id) => call("delete_ruleset", { actor, ...owner, id }),
477 effectiveRules: (repo, name, viewer, target = "branch") => call("effective_rules", { viewer, repo, name, target }),
478 ruleEvaluations: (owner, viewer, filter = {}) => call("rule_evaluations", { viewer, ...owner, ...filter }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents479 seenChecks: (repo, viewer) => call("seen_checks", { repo, viewer }),
Merge checks: statuses and check runs on every commit480 commitChecks: (repo, viewer, shas) => call("commit_checks", { repo, viewer, shas }),
481 getCheckRun: (repo, id, viewer) => call("get_check_run", { repo, id, viewer }),
482 checkRunAnnotations: (repo, id, viewer) => call("check_run_annotations", { repo, id, viewer }),
483 requestCheckAction: (actor, repo, id, identifier) => call("request_check_action", { actor, repo, id, identifier }),
484 rerequestCheckRun: (actor, repo, id) => call("rerequest_check_run", { actor, repo, id }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar485 codeownersErrors: (repo, viewer, ref) => call("codeowners_errors", { repo, viewer, ref: ref ?? null }),
Agents as a team: lifecycle, merge queue, billing and a new shell486 updateSettings: (actor, repo, settings) =>
487 call("update_settings", { actor, repo, settings }),
Issues and pull requests replace intents and attempts488 openPull: (actor, repo, input) => call("open_pull", { actor, repo, ...input }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar489 listPulls: (repo, viewer, state, filter = {}) => call("list_pulls", { repo, viewer, state, ...filter }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents490 pullsForRepos: (repoIds, viewer, limit) => call("pulls_for_repos", { repoIds, viewer, limit }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar491 // Its own fields arrive in snake_case: read into camelCase here.
492 getPull: (repo, number, viewer) =>
493 call<Result<Record<string, unknown>>>("get_pull", { repo, number, viewer }).then(
494 (found): Result<PullDetail> => (found.ok ? { ok: true, value: pullDetailFromWire(found.value) } : found),
495 ),
Agents as a team: lifecycle, merge queue, billing and a new shell496 updatePull: (actor, repo, number, changes) =>
497 call("update_pull", { actor, repo, number, ...changes }),
Catching up with main takes seconds when the two sides touched different files498 catchUpPull: (actor, repo, number) => call("catch_up_pull", { actor, repo, number }),
Issues and pull requests replace intents and attempts499 readyPull: (actor, repo, number, summary) =>
500 call("ready_pull", { actor, repo, number, summary }),
501 closePull: (actor, repo, number) => call("close_pull", { actor, repo, number }),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts502 reopenPull: (actor, repo, number) => call("reopen_pull", { actor, repo, number }),
503 convertPullToDraft: (actor, repo, number) => call("convert_pull_to_draft", { actor, repo, number }),
Acceptance checks in sandboxes, line comments and review verdicts504 mergePull: (actor, repo, number, options = {}) =>
505 call("merge_pull", { actor, repo, number, ...options }),
Issues and pull requests replace intents and attempts506 listActivePulls: (viewer) => call("list_active_pulls", { viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains507 byAuthor: (username, viewer, filter = {}) => call("by_author", { username, viewer, ...filter }),
Agents as a team: lifecycle, merge queue, billing and a new shell508 startPlan: (actor, repo, brief) => call("start_plan", { actor, repo, brief }),
509 failPlan: (planId, token, error) => call("report_plan", { planId, token, error }),
510 getPlan: (repo, viewer, id) => call("get_plan", { repo, viewer, id }),
511 listPlans: (repo, viewer) => call("list_plans", { repo, viewer }),
512 applyPlan: (actor, repo, id, options = {}) =>
513 call("apply_plan", { actor, repo, id, ...options }),
514 queueIssue: (actor, repo, number, queued) =>
515 call("queue_issue", { actor, repo, number, queued }),
516 readyIssues: (repoId) => call("ready_issues", { repoId }),
517 listAssignedIssues: (viewer) => call("list_assigned_issues", { viewer }),
Issues and pull requests replace intents and attempts518 appendSession: (actor, repo, number, entries) =>
519 call("append_session", { actor, repo, number, entries }),
520 readSession: (repo, number, viewer, afterSeq = 0) =>
521 call("read_session", { repo, number, viewer, afterSeq }),
Work service in Rust, with RFC 3339 timestamps522 };
523}
Events service in Rust, with RFC 3339 times and accurate push events524
Agents as a team: lifecycle, merge queue, billing and a new shell525export function billingClient(service: ServiceBinding): BillingApi {
526 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
527 return {
528 status: () => call("status", {}),
529 account: (workspace, viewer) => call("account", { workspace, viewer }),
530 ledger: (workspace, viewer) => call("ledger", { workspace, viewer }),
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging531 credits: (workspace, viewer) => call("credits", { workspace, viewer }),
The statement is a month at a time, a line per kind of charge532 statement: (workspace, viewer, month = null, group = "day") => call("statement", { workspace, viewer, month, group }),
533 statementEntries: (workspace, viewer, filter) =>
534 call("statement_entries", {
535 workspace,
536 viewer,
537 month: filter.month,
538 kind: filter.kind,
539 day: filter.day ?? null,
540 project: filter.project ?? null,
541 before: filter.before ?? null,
542 }),
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request543 usage: (workspace, viewer, since) => call("usage", { workspace, viewer, since }),
Mission control shows model usage, yours and the workspace's: tokens, cost, active days, cache share, each day, and the mix544 tokenUsage: (workspace, viewer, options = {}) =>
545 call("token_usage", { workspace, viewer, person: options.person ?? null, days: options.days ?? null }),
546 recordTokens: (usage) => call("record_tokens", usage),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens547 gatewayModels: () => call("gateway_models", {}),
Merge branch 'main' into actions-toolkit-oidc-artifacts548 modelDefaults: () => call("model_defaults", {}),
549 recordDiscovery: (provider, models, by, error = null) => call("record_discovery", { provider, models, by, error }),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens550 gatewayAdmit: (workspace) => call("gateway_admit", { workspace }),
551 recordGateway: (record) => call("record_gateway", record),
552 gatewayRequests: (workspace, viewer, options = {}) =>
553 call("gateway_requests", { workspace, viewer, limit: options.limit ?? null, before: options.before ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look554 checkout: (actor, workspace, amountCents, returnUrl, method = "card") =>
555 call("checkout", { actor, workspace, amountCents, returnUrl, method }),
Agents as a team: lifecycle, merge queue, billing and a new shell556 confirm: (workspace, viewer, session) => call("confirm", { workspace, viewer, session }),
557 canStart: (workspace) => call("can_start", { workspace }),
A free allowance on g1t's models, so anyone can try its agents558 trial: (workspace, exempt) => call("trial", { workspace, exempt }),
Agents as a team: lifecycle, merge queue, billing and a new shell559 startRun: (run) => call("start_run", run),
Paid features: a workspace turns on Deployments with a monthly plan560 features: (workspace, viewer) => call("features", { workspace, viewer }),
561 subscribe: (actor, workspace, feature, returnUrl) =>
562 call("subscribe", { actor, workspace, feature, returnUrl }),
563 confirmSubscription: (workspace, viewer, session) =>
564 call("confirm_subscription", { workspace, viewer, session }),
565 cancelSubscription: (actor, workspace, feature, resume = false) =>
566 call("cancel_subscription", { actor, workspace, feature, resume }),
567 hasFeature: (workspace, feature) => call("has_feature", { workspace, feature }),
Merge Stripe Tax, the card fee on card payments, and one free workspace per person568 freeWorkspaces: (workspaces) => call("free_workspaces", { workspaces }),
Paid features: a workspace turns on Deployments with a monthly plan569 chargeFeature: (charge) => call("charge_feature", charge),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace570 billingPortal: (actor, workspace, returnUrl) => call("billing_portal", { actor, workspace, return_url: returnUrl }),
Every sandbox is metered by the second571 recordSandbox: (usage) => call("record_sandbox", usage),
Usage limits: unpaid usage can only go so far572 limit: (workspace, viewer) => call("limit", { workspace, viewer }),
573 checkLimit: (workspace) => call("check_limit", { workspace }),
Prices keep themselves current with what g1t pays574 prices: () => call("prices", {}),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas575 notePending: (workspace, source, costMicros, detail = null) => call("note_pending", { workspace, source, costMicros, detail }),
576 usageMeters: (workspace, viewer) => call("usage_meters", { workspace, viewer }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look577 setSpendLimit: (actor, workspace, spendLimitMicros, useFullLimit = false, raiseOnce = false) =>
578 call("set_spend_limit", { actor, workspace, spendLimitMicros, use_full_limit: useFullLimit, raise_once: raiseOnce }),
Two limits, real invoices, trust that grows by itself, sales signals579 invoices: (workspace, viewer) => call("invoices", { workspace, viewer }),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put580 entitlements: (workspace) => call("entitlements", { workspace }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look581 reserve: (reservation) => call("reserve", reservation),
582 settle: (reservationId, actualMicros) => call("settle", { reservationId, actualMicros }),
583 cardCheck: (actor, workspace, returnUrl) => call("card_check", { actor, workspace, returnUrl }),
584 confirmCardCheck: (workspace, viewer, session) => call("confirm_card_check", { workspace, viewer, session }),
585 requestLimit: (actor, workspace, request) => call("request_limit", { actor, workspace, ...request }),
586 limitRequests: (workspace, viewer) => call("limit_requests", { workspace, viewer }),
587 confirmSpike: (actor, workspace, keepGoing) => call("confirm_spike", { actor, workspace, keepGoing }),
588 setCaps: (actor, workspace, caps) => call("set_caps", { actor, workspace, ...caps }),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit589 usageReport: (workspace, viewer, range) =>
590 call("usage_report", { workspace, viewer, from: range.from, until: range.until, products: range.products ?? [], projects: range.projects ?? [] }),
591 aiCredit: (workspace, viewer) => call("ai_credit", { workspace, viewer }),
592 buyAiCredit: (actor, workspace, amountCents, returnUrl) => call("buy_ai_credit", { actor, workspace, amountCents, returnUrl }),
593 confirmAiCredit: (workspace, viewer, session) => call("confirm_ai_credit", { workspace, viewer, session }),
594 setAiReload: (actor, workspace, reload) => call("set_ai_reload", { actor, workspace, ...reload }),
595 setBudget: (actor, workspace, budget) => call("set_budget", { actor, workspace, ...budget }),
596 billingDetails: (workspace, viewer) => call("billing_details", { workspace, viewer }),
597 setBillingDetails: (actor, workspace, details) => call("set_billing_details", { actor, workspace, ...details }),
Agents as a team: lifecycle, merge queue, billing and a new shell598 };
599}
600
Billing accounts, terms and enterprises; g1t is no longer free601export function billingAdminClient(service: ServiceBinding): BillingAdminApi {
602 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
603 return {
604 accounts: (query) => call("admin_accounts", { query: query ?? null }),
605 account: (id) => call("admin_account", { id }),
606 setTerms: (id, terms, by) => call("admin_set_terms", { id, terms, by }),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put607 setAllowances: (id, allowances, note, by) => call("admin_set_allowances", { id, allowances, note, by }),
Billing accounts, terms and enterprises; g1t is no longer free608 createEnterprise: (name, workspaces, by) => call("admin_create_enterprise", { name, workspaces, by }),
609 attach: (workspace, account, by) => call("admin_attach", { workspace, account, by }),
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging610 credit: (workspace, amountMicros, note, by, options = { kind: "goodwill" }) =>
611 call("admin_credit", {
612 workspace,
613 amount_micros: amountMicros,
614 note,
615 by,
616 kind: options.kind,
617 expires_at: options.expiresAt ?? null,
618 refund_for: options.refundFor ?? null,
619 refund_day: options.refundDay ?? null,
620 }),
621 credits: (filter = {}) =>
622 call("admin_credits", {
623 workspace: filter.workspace ?? null,
624 kind: filter.kind ?? null,
625 month: filter.month ?? null,
626 by: filter.by ?? null,
627 }),
628 revokeCredit: (id, note, by) => call("admin_revoke_credit", { id, note, by }),
sudo: reset a test workspace's billing so it starts again as a new customer; refused on a live Stripe key, for comped workspaces and for an enterprise's629 resetBilling: (workspace, confirm, note, by) => call("admin_reset_billing", { workspace, confirm, note, by }),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace630 billingLink: (workspace, by) => call("admin_billing_link", { workspace, by }),
Stripe's webhook secret is a Worker secret, STRIPE_WEBHOOK_SECRET, from a destination made in Stripe's dashboard631 stripe: (fix = false, by) => call("admin_stripe", { fix, by: by ?? null }),
Stripe webhooks, enterprise invoices, and sudo for both632 enterpriseBilling: (id, email, by) => call("admin_enterprise_billing", { id, email, by }),
Merge Stripe Tax, the card fee on card payments, and one free workspace per person633 enterpriseAddress: (id, address, taxIdType, taxId, by) => call("admin_enterprise_address", { id, address, taxIdType, taxId, by }),
Stripe webhooks, enterprise invoices, and sudo for both634 invoiceEnterprise: (id, by) => call("admin_invoice_enterprise", { id, by }),
635 accountsFor: (workspaces) => call("admin_accounts", { query: null, workspaces }),
Two limits, real invoices, trust that grows by itself, sales signals636 signals: () => call("admin_signals", {}),
637 overview: () => call("admin_overview", {}),
638 sales: (workspace) => call("admin_sales", { workspace }),
639 setSales: (workspace, record, by) =>
640 call("admin_set_sales", {
641 workspace,
642 stage: record.stage,
643 owner: record.owner ?? null,
644 next_step: record.nextStep ?? null,
645 next_at: record.nextAt ?? null,
646 by,
647 }),
648 addNote: (workspace, text, by) => call("admin_add_note", { workspace, text, by }),
649 workspaceInvoices: (workspace) => call("admin_workspace_invoices", { workspace }),
Billing lists every invoice and every staff change; signals carry follow-ups650 allInvoices: (filter = {}) => call("admin_invoices", { status: filter.status ?? null, month: filter.month ?? null }),
651 audit: (filter = {}) =>
652 call("admin_audit", { by: filter.by ?? null, action: filter.action ?? null, before: filter.before ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look653 limitRequests: (status = "open") => call("admin_limit_requests", { status }),
654 decideLimitRequest: (id, decision, amountMicros, note, by) =>
655 call("admin_decide_limit_request", { id, decision, amount_micros: amountMicros, note, by }),
656 overages: () => call("admin_overages", {}),
657 goodwill: (workspace, amountMicros, reason, by, day = null) =>
658 call("admin_goodwill", { workspace, amount_micros: amountMicros, reason, by, day }),
659 velocity: () => call("admin_velocity", {}),
660 recordPayment: (workspace, amountMicros, reference, note, by) =>
661 call("admin_record_payment", { workspace, amount_micros: amountMicros, reference, note, by }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily662 costs: (days) => call("admin_costs", { days: days ?? null }),
663 costAlerts: () => call("admin_cost_alerts", {}),
Spend caps: a monthly budget for comped workspaces and a daily breaker on what g1t pays664 spendCaps: () => call("admin_spend_caps", {}),
665 liftBreaker: (note, by) => call("admin_lift_breaker", { note, by }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily666 decideProposal: (id, decision, note, by) => call("admin_decide_proposal", { id, decision, note, by }),
667 setCostSettings: (settings, by) => call("admin_set_cost_settings", { settings, by }),
668 setCostMapping: (mapping, by) =>
669 call("admin_set_cost_mapping", {
670 product: mapping.product,
671 meter: mapping.meter,
672 bucket: mapping.bucket ?? "",
673 price_meter: mapping.priceMeter ?? null,
674 own_meter: mapping.ownMeter ?? null,
675 scale_to_own: mapping.scaleToOwn ?? false,
676 drift_percent: mapping.driftPercent ?? null,
677 note: mapping.note ?? "",
678 remove: mapping.remove ?? false,
679 by,
680 }),
681 runCosts: (by) => call("admin_run_costs", { by }),
Merge branch 'main' into actions-toolkit-oidc-artifacts682 models: () => call("admin_models", {}),
683 decideModel: (model, decision, details, reason, by) =>
684 call("admin_decide_model", {
685 model,
686 decision,
687 name: details.name ?? null,
688 tier_hint: details.tierHint ?? null,
689 prices: details.prices
690 ? {
691 input_micros: details.prices.inputMicros,
692 output_micros: details.prices.outputMicros,
693 cache_read_micros: details.prices.cacheReadMicros,
694 cache_write_micros: details.prices.cacheWriteMicros,
695 cache_write_1h_micros: details.prices.cacheWrite1hMicros,
696 threshold: details.prices.threshold,
697 over_input_micros: details.prices.overInputMicros,
698 over_output_micros: details.prices.overOutputMicros,
699 over_cache_read_micros: details.prices.overCacheReadMicros,
700 over_cache_write_micros: details.prices.overCacheWriteMicros,
701 over_cache_write_1h_micros: details.prices.overCacheWrite1hMicros,
702 }
703 : null,
704 reason,
705 by,
706 }),
707 setModelDefault: (purpose, value, reason, by) =>
708 call("admin_set_model_default", {
709 purpose,
710 model: value.model ?? null,
711 tier: value.tier ?? null,
712 effort: value.effort ?? null,
713 reason,
714 by,
715 }),
Billing accounts, terms and enterprises; g1t is no longer free716 };
717}
718
Events service in Rust, with RFC 3339 times and accurate push events719export function eventsClient(service: ServiceBinding): EventsApi {
720 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
721 return {
722 publish: (events) => call("publish", { events }),
723 list: (query) => call("list", query),
724 };
725}
Integrations: your own model provider, alerts that open issues, tickets agents read726
727export function integrationsClient(service: ServiceBinding): IntegrationsApi {
728 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
729 return {
730 list: (workspace, viewer) => call("list", { workspace, viewer }),
731 connect: (actor, workspace, input) => call("connect", { actor, workspace, ...input }),
732 update: (actor, workspace, id, input) => call("update", { actor, workspace, id, ...input }),
733 disconnect: (actor, workspace, id) => call("disconnect", { actor, workspace, id }),
734 test: (actor, workspace, id) => call("test", { actor, workspace, id }),
735 deliveries: (workspace, viewer, id) => call("deliveries", { workspace, viewer, id }),
736 resolve: (workspace, viewer, reference) => call("resolve", { workspace, viewer, reference }),
737 references: (workspace, text, limit) => call("references", { workspace, text, limit }),
738 import: (actor, repo, reference, assign) => call("import", { actor, repo, reference, assign }),
739 links: (repo, number) => call("links", { repo, number }),
740 modelProvider: (workspace) => call("model_provider", { workspace }),
741 openModelSession: (run) => call("open_model_session", run),
742 modelUpstream: (token) => call("model_upstream", { token }),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens743 gatewayUpstream: (workspace) => call("gateway_upstream", { workspace }),
AI Gateway: OpenAI's format, open models, and your own providers744 gatewayProviders: (workspace) => call("gateway_providers", { workspace }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily745 closeModelSessions: (tokenHashes) => call("close_model_sessions", { token_hashes: tokenHashes }),
Models per workspace: several providers, routed by kind of work746 routes: (workspace, viewer) => call("routes", { workspace, viewer }),
747 setRoutes: (actor, workspace, routes) => call("set_routes", { actor, workspace, routes }),
Integrations: your own model provider, alerts that open issues, tickets agents read748 };
749}
Webhooks: every event, to your own addresses, signed and retried750
751export function webhooksClient(service: ServiceBinding): WebhooksApi {
752 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
753 return {
754 list: (viewer, owner) => call("list", { viewer, ...owner }),
755 create: (actor, owner, input) => call("create", { actor, ...owner, ...input }),
756 update: (actor, owner, id, input) => call("update", { actor, ...owner, id, ...input }),
757 delete: (actor, owner, id) => call("delete", { actor, ...owner, id }),
758 ping: (actor, owner, id) => call("ping", { actor, ...owner, id }),
759 deliveries: (viewer, owner, id) => call("deliveries", { viewer, ...owner, id }),
760 redeliver: (actor, owner, deliveryId) => call("redeliver", { actor, ...owner, deliveryId }),
761 };
762}
Automations: rules in .g1t/automations that act when something happens763
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs764export function actionsClient(service: ServiceBinding): ActionsApi {
765 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
766 return {
767 workflows: (repo, viewer) => call("workflows", { repo, viewer }),
768 runs: (repo, viewer, filter = {}) => call("runs", { repo, viewer, ...filter }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)769 run: (repo, viewer, id, attempt) => call("run", { repo, viewer, id, attempt: attempt ?? null }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs770 logs: (repo, viewer, job, after = 0) => call("logs", { repo, viewer, job, after }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)771 summaries: (repo, viewer, id, attempt) => call("summaries", { repo, viewer, id, attempt: attempt ?? null }),
772 jobLogText: (repo, viewer, job) => call("job_log_text", { repo, viewer, job }),
773 runLogs: (repo, viewer, id, attempt) => call("run_logs", { repo, viewer, id, attempt: attempt ?? null }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs774 dispatch: (actor, repo, workflow, ref, inputs) => call("dispatch", { actor, repo, workflow, ref, inputs }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)775 cancel: (actor, repo, id, force = false) => call("cancel", { actor, repo, id, force }),
776 rerun: (actor, repo, id, failedOnly = false, options = {}) =>
777 call("rerun", { actor, repo, id, failed_only: failedOnly, job: options.job ?? null, debug: options.debug ?? false }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs778 setWorkflowEnabled: (actor, repo, workflow, enabled) =>
779 call("set_workflow_enabled", { actor, repo, workflow, enabled }),
780 settings: (actor, owner, kind) => call("settings", { actor, ...owner, kind }),
Secrets and variables: one list, rows per environment, for workflows and deployments781 setSetting: (actor, owner, kind, name, value, options = {}) =>
782 call("set_setting", { actor, ...owner, kind, name, value, ...options }),
783 deleteSetting: (actor, owner, kind, name, id) => call("delete_setting", { actor, ...owner, kind, name, id }),
Merge branch 'worktree-agent-a3abfcce648e87dca'784 approveRun: (actor, repo, id) => call("approve_run", { actor, repo, id }),
785 pendingDeployments: (repo, viewer, id) => call("pending_deployments", { repo, viewer, id }),
786 reviewDeployments: (actor, repo, id, state, environments = [], comment) =>
787 call("review_deployments", { actor, repo, id, state, environments, comment: comment ?? null }),
788 actionsSettings: (repo, viewer) => call("actions_settings", { repo, viewer }),
789 setActionsSettings: (actor, repo, change) => call("set_actions_settings", { actor, repo, ...change }),
790 workspaceActionsSettings: (workspace, viewer) => call("workspace_actions_settings", { workspace, viewer }),
791 setWorkspaceActionsSettings: (actor, workspace, change) =>
792 call("set_workspace_actions_settings", { actor, workspace, ...change }),
793 environments: (repo, viewer) => call("environments", { repo, viewer }),
794 setEnvironment: (actor, repo, name, change) => call("set_environment", { actor, repo, name, ...change }),
795 deleteEnvironment: (actor, repo, name) => call("delete_environment", { actor, repo, name }),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2796 artifacts: (repo, viewer, filter = {}) => call("artifacts", { repo, viewer, ...filter }),
797 artifactDownload: (repo, viewer, by) => call("artifact_download", { repo, viewer, ...by }),
798 deleteArtifact: (actor, repo, id) => call("delete_artifact", { actor, repo, id }),
799 artifactRetention: (repo, viewer, days) => call("artifact_retention", { repo, viewer, days }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs800 };
801}
802
Deployments: a preview for every pull request, production on g1t.page803
Fast pages, required checks on the branch, self-hosted runners, honest incidents804/** Self-hosted runners, kept by the actions service. */
805export function runnersClient(service: ServiceBinding): RunnersApi {
806 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
807 return {
808 stuck: (viewer) => call("stuck_jobs", { viewer }),
809 list: (actor, owner) => call("runners", { actor, ...owner }),
810 createToken: (actor, owner, group) => call("create_registration_token", { actor, ...owner, group }),
811 remove: (actor, owner, id) => call("remove_runner", { actor, ...owner, id }),
812 groups: (actor, workspace) => call("runner_groups", { actor, workspace }),
813 setGroup: (actor, workspace, group) => call("set_runner_group", { actor, workspace, ...group }),
814 deleteGroup: (actor, workspace, id) => call("delete_runner_group", { actor, workspace, id }),
815 settings: (actor, owner) => call("runner_settings", { actor, ...owner }),
816 setSettings: (actor, owner, change) => call("set_runner_settings", { actor, ...owner, ...change }),
817 };
818}
819
Deployments: a preview for every pull request, production on g1t.page820export function deploymentsClient(service: ServiceBinding): DeploymentsApi {
821 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
822 return {
Projects: what a workspace builds and runs, first on every page823 settings: (project, viewer) => call("settings", { project, viewer }),
824 updateSettings: (actor, project, changes) => call("update_settings", { actor, project, changes }),
825 list: (project, viewer) => call("list", { project, viewer }),
826 get: (project, id, viewer) => call("get", { project, id, viewer }),
827 redeploy: (actor, project, branch) => call("redeploy", { actor, project, branch }),
828 takeDown: (actor, project, branch) => call("take_down", { actor, project, branch }),
Project dependencies: addresses, preview stacks, Affects, and agents who know829 stack: (actor, project, branch) => call("stack", { actor, project, branch }),
Projects: what a workspace builds and runs, first on every page830 overview: (workspace, viewer) => call("overview", { workspace, viewer }),
Deployments: a preview for every pull request, production on g1t.page831 usage: (workspace, viewer) => call("usage", { workspace, viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains832 domains: (project, viewer) => call("domains", { project, viewer }),
833 addDomain: (actor, project, hostname, options = {}) =>
834 call("add_domain", { actor, project, hostname, twin: !!options.twin }),
835 removeDomain: (actor, project, id) => call("remove_domain", { actor, project, id }),
836 refreshDomain: (actor, project, id) => call("refresh_domain", { actor, project, id }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97837 repoDeployments: (repo, viewer, filter = {}) => call("list_deployments", { repo, viewer, ...filter }),
838 repoDeployment: (repo, id, viewer) => call("get_deployment", { repo, id, viewer }),
839 environments: (repo, viewer) => call("list_environments", { repo, viewer }),
840 createDeployment: (actor, repo, input) => call("create_deployment", { repo, actor, ...input }),
841 createDeploymentStatus: (actor, repo, id, input) => call("create_deployment_status", { repo, actor, id, ...input }),
Deployments: a preview for every pull request, production on g1t.page842 };
843}
Projects: what a workspace builds and runs, first on every page844
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member845/** Packages: the registries beside the code (services/packages). */
846export function packagesClient(service: ServiceBinding): PackagesApi {
847 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
848 return {
849 list: (workspace, viewer, filter = {}) =>
850 call("list_packages", {
851 workspace,
852 viewer,
853 ecosystem: filter.ecosystem ?? null,
854 repo_id: filter.repoId ?? null,
855 query: filter.query ?? null,
856 }),
857 get: (workspace, ecosystem, name, viewer) => call("get_package", { workspace, ecosystem, name, viewer }),
858 deleteVersion: (actor, workspace, ecosystem, name, version, surface) =>
859 call("delete_version", { actor, workspace, ecosystem, name, version, surface: surface ?? null }),
860 deletePackage: (actor, workspace, ecosystem, name, surface) =>
861 call("delete_package", { actor, workspace, ecosystem, name, surface: surface ?? null }),
862 set: (actor, workspace, ecosystem, name, change, surface) =>
863 call("set_package", {
864 actor,
865 workspace,
866 ecosystem,
867 name,
868 visibility: change.visibility ?? null,
869 link: change.link ?? null,
870 unlink: change.unlink ?? false,
Merge packages: roles, Actions access, source label, soft delete, API871 inherit_access: change.inheritAccess ?? null,
872 surface: surface ?? null,
873 }),
874 settings: (workspace, ecosystem, name, viewer) => call("package_settings", { workspace, ecosystem, name, viewer }),
875 deleted: (workspace, viewer) => call("deleted_packages", { workspace, viewer }),
876 restorePackage: (actor, workspace, ecosystem, name, surface) =>
877 call("restore_package", { actor, workspace, ecosystem, name, surface: surface ?? null }),
878 restoreVersion: (actor, workspace, ecosystem, name, version, surface) =>
879 call("restore_version", { actor, workspace, ecosystem, name, version, surface: surface ?? null }),
880 setAccess: (actor, workspace, ecosystem, name, who, role, surface) =>
881 call("set_package_access", {
882 actor,
883 workspace,
884 ecosystem,
885 name,
886 user: "user" in who ? who.user : null,
887 team: "team" in who ? who.team : null,
888 role,
889 surface: surface ?? null,
890 }),
891 removeAccess: (actor, workspace, ecosystem, name, who, surface) =>
892 call("remove_package_access", {
893 actor,
894 workspace,
895 ecosystem,
896 name,
897 user: "user" in who ? who.user : null,
898 team: "team" in who ? who.team : null,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member899 surface: surface ?? null,
900 }),
Merge packages: roles, Actions access, source label, soft delete, API901 setActionsAccess: (actor, workspace, ecosystem, name, repo, role, surface) =>
902 call("set_actions_access", { actor, workspace, ecosystem, name, repo, role, surface: surface ?? null }),
903 removeActionsAccess: (actor, workspace, ecosystem, name, repo, surface) =>
904 call("remove_actions_access", { actor, workspace, ecosystem, name, repo, surface: surface ?? null }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member905 storage: (workspace) => call("storage", { workspace }),
906 storageAll: () => call("storage_all", {}),
Composer from the workspace's own repositories, and go get from g1t.sh907 syncComposer: (repoId) => call("sync_composer", { repo_id: repoId }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member908 };
909}
910
Projects: what a workspace builds and runs, first on every page911export function projectsClient(service: ServiceBinding): ProjectsApi {
912 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
913 return {
914 list: (workspace, viewer) => call("list", { workspace, viewer }),
915 get: (workspace, slug, viewer) => call("get", { workspace, slug, viewer }),
916 byRepo: (repoId) => call("by_repo", { repoId }),
917 create: (actor, workspace, input) => call("create", { actor, workspace, input }),
918 update: (actor, workspace, slug, changes) => call("update", { actor, workspace, slug, changes }),
A project is an app or a library: libraries show their package and how to ship a release, not production919 deploymentsChanged: (projectId, enabled) => call("deployments_changed", { projectId, enabled }),
Project dependencies: addresses, preview stacks, Affects, and agents who know920 dependencies: (workspace, slug, viewer) => call("dependencies", { workspace, slug, viewer }),
921 addDependency: (actor, workspace, slug, on, as) => call("add_dependency", { actor, workspace, slug, on, as }),
922 removeDependency: (actor, workspace, slug, on) => call("remove_dependency", { actor, workspace, slug, on }),
923 graph: (projectId) => call("graph", { projectId }),
Projects: pinned and recent projects, per person per workspace924 shortcuts: (workspace, viewer) => call("shortcuts", { workspace, viewer }),
925 pin: (actor, workspace, slug, position) => call("pin", { actor, workspace, slug, position: position ?? null }),
926 unpin: (actor, workspace, slug) => call("unpin", { actor, workspace, slug }),
927 reorderPins: (actor, workspace, slugs) => call("reorder_pins", { actor, workspace, slugs }),
928 visited: (actor, projectId) => call("visited", { actor, projectId }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97929 publicLinks: (repos) => call("public_links", { repos }),
Projects: what a workspace builds and runs, first on every page930 };
931}

This file's history is long; its oldest lines are credited to the oldest commit read.