g1t/apps/web/public/llms.txt

516 lines28,383 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)1# g1t
2
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look3> g1t (https://g1t.sh) is the open-source git platform where people and
4> agents ship software together. It is ordinary git over HTTPS, with
5> issues, pull requests and reviews. Agents are members of the forge: you
6> assign an issue to g1t-agent or connect your own over MCP, or hand g1t an
7> outcome and a planner splits it into issues with dependencies that agents
8> work in parallel, aware of each other. Checks run in clean sandboxes, a
9> merge queue lands each change on main only once it passes together with
10> everything ahead of it, and deployments put a preview of every pull
11> request and production on g1t.page. Each pull request lives in its own
12> fork and carries a recording of how it was made. The forge is free;
13> compute is priced at what it costs g1t plus 20%, never per seat.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)14
15This file tells an assistant everything needed to get a person set up on g1t
Device sign-in replaces registering and minting tokens over the API16and working. You never ask for, see, or send the person's password. Accounts
17are created and approved only in their browser.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)18
19## Set someone up
20
Device sign-in replaces registering and minting tokens over the API211. **Start a sign-in.**
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)22
23 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell24 curl -X POST https://api.g1t.sh/device/code \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)25 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API26 -d '{"client_name": "Claude Code"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)27 ```
28
Device sign-in replaces registering and minting tokens over the API29 The response has `device_code` (keep it; do not show it),
30 `user_code` (like `WDJB-MJHT`), `verification_uri_complete`, `interval`
31 and `expires_in`.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)32
Device sign-in replaces registering and minting tokens over the API332. **Send the person to their browser.** Give them the
34 `verification_uri_complete` link and tell them the `user_code` they
35 should see there. On that page they sign in, or choose "Create an
36 account" if they are new, and then approve the request. Wait for them.
37
38 A new account also gets a confirmation email from `noreply@g1t.sh`. Ask
39 them to open it and follow the link. Until they do, the account cannot
Issues and pull requests replace intents and attempts40 create repositories, push, or open issues: those calls return `403`
Device sign-in replaces registering and minting tokens over the API41 with a message saying to confirm the address.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)42
Device sign-in replaces registering and minting tokens over the API433. **Collect the token.** Poll every `interval` seconds, not faster:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)44
45 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell46 curl -X POST https://api.g1t.sh/device/token \
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)47 -H "Content-Type: application/json" \
Device sign-in replaces registering and minting tokens over the API48 -d '{"device_code": "DEVICE_CODE"}'
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)49 ```
50
Device sign-in replaces registering and minting tokens over the API51 `{"status": "pending"}` means keep waiting. `denied` and `expired` mean
52 start again from step 1. `approved` comes with `token`, `username` and
53 `verified`. The token is returned once. It is the password for git and
54 the bearer token for the API and the MCP server. Store it as `G1T_TOKEN`;
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas55 never write it into a repository. Your person can see and delete it at
56 g1t.sh/settings/tokens. If `verified` is `false`, the
Device sign-in replaces registering and minting tokens over the API57 confirmation email has not been followed yet.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)58
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look594. **Connect the MCP server** (any MCP client with HTTP transport works).
60 Claude Code:
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)61
62 ```sh
63 claude mcp add --transport http g1t https://mcp.g1t.sh \
64 --header "Authorization: Bearer $G1T_TOKEN"
65 ```
66
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look67 Codex, in `~/.codex/config.toml`:
68
69 ```toml
70 [mcp_servers.g1t]
71 url = "https://mcp.g1t.sh"
72 bearer_token_env_var = "G1T_TOKEN"
73 ```
74
75 OpenCode, in `opencode.json`:
76
77 ```json
78 { "mcp": { "g1t": { "type": "remote", "url": "https://mcp.g1t.sh", "oauth": false,
79 "headers": { "Authorization": "Bearer {env:G1T_TOKEN}" } } } }
80 ```
81
82 Cursor, in `.cursor/mcp.json`:
83
84 ```json
85 { "mcpServers": { "g1t": { "url": "https://mcp.g1t.sh",
86 "headers": { "Authorization": "Bearer ${env:G1T_TOKEN}" } } } }
87 ```
88
OAuth 2.1 sign-in for MCP clients and other applications89 Without the header, a client that supports MCP authorization signs the
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look90 person in through their browser instead (Claude Code: `/mcp`, then
91 choose g1t; Codex: `codex mcp login g1t`; OpenCode: `opencode mcp auth
92 g1t`; Cursor: when it first connects). The MCP server always needs one
93 or the other.
OAuth 2.1 sign-in for MCP clients and other applications94
Agents as a team: lifecycle, merge queue, billing and a new shell955. **Create a workspace** if `GET /user` shows none. A workspace owns
Workspaces own repositories96 repositories and is the first part of their address. Ask the person what
97 to call it; their username is a sensible default.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)98
99 ```sh
Agents as a team: lifecycle, merge queue, billing and a new shell100 curl -X POST https://api.g1t.sh/workspaces \
Workspaces own repositories101 -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \
102 -d '{"slug": "WORKSPACE"}'
103 ```
104
Agents as a team: lifecycle, merge queue, billing and a new shell1056. **Or import one.** `POST /repos` with `name` and
106 `import_url` (the https address of a public repository, such as one on
107 GitHub) copies its default branch.
108
1097. **Push a repository.** Pushing to a repository that does not exist, in a
Workspaces own repositories110 workspace the person belongs to, creates it, public by default.
111
112 ```sh
113 git remote add g1t https://g1t.sh/WORKSPACE/REPO.git
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)114 git -c credential.helper= \
115 -c "http.extraHeader=Authorization: Basic $(printf '%s' "USERNAME:$G1T_TOKEN" | base64)" \
116 push -u g1t main
117 ```
118
119 Or let git ask: the username is the g1t username and the password is the
120 token.
121
Docs worth reading, and kept that way1228. **Record Claude Code sessions automatically** (optional). This installs
123 hooks that record prompts, tool calls and replies onto the g1t pull
124 request for the branch being worked on. The person runs it, because it
125 signs them in through their browser:
126
127 ```sh
128 curl -fsSL https://g1t.sh/install/claude.sh | sh
129 ```
130
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)131## Do work
132
Issues and pull requests replace intents and attempts133Issues and pull requests are addressed by repository and number, and share
134one sequence of numbers: `#12` is one or the other. Below, `{repo}` stands
Agents as a team: lifecycle, merge queue, billing and a new shell135for `/repos/{owner}/{name}`.
Issues and pull requests replace intents and attempts136
137- **Find work:** `GET {repo}/issues?state=open`, optionally `&label=bug`.
138- **Open an issue:** `POST {repo}/issues` with `title`, `body`, and
139 optional `labels` (such as `bug` or `feature`; a new name makes a new
140 label) and `checks` (commands that should pass).
141- **Read an issue:** `GET {repo}/issues/{number}`. It lists every pull
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API142 request already made for it. A closed issue's `resolved_by` is the number
Issues and pull requests replace intents and attempts143 of the pull request that was merged.
144- **Open a pull request:** `POST {repo}/pulls` with `issue` (its number) and
145 `agent` (a label such as `claude-code`). Without an issue, send `title`.
146 The response has `pull.number` and `git.remote`, the pull request's own
147 fork. Clone it, commit, and push to it with the token. It starts as a
Pull requests from branches148 draft. If the change is already on a branch pushed to the repository,
149 send `branch` (and `title`, `body`) instead: no fork is made and the pull
150 request is ready at once.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)151- **Record the session** as you work, so people can see why a change was
Issues and pull requests replace intents and attempts152 made: `POST {repo}/pulls/{number}/session` with
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)153 `{"entries": [{"kind": "message", "text": "…"}]}`. Kinds are `prompt`,
154 `message`, `tool_call`, `tool_result`, `note`. Never include secrets;
155 sessions are as visible as the repository.
Issues and pull requests replace intents and attempts156- **Mark it ready:** `POST {repo}/pulls/{number}/ready` with `summary`, which
157 becomes the pull request's description.
158- **See what a pull request changes:** `GET {repo}/pulls/{number}/changes`.
Agents as a team: lifecycle, merge queue, billing and a new shell159- **Before going far**, read `overlaps` on `GET {repo}/pulls/{number}`:
160 other pull requests in progress changing the same files. `behind` says
161 whether main has moved since; if so, pull main into the fork and push.
Acceptance checks in sandboxes, line comments and review verdicts162- **Checks:** once a pull request is ready, g1t runs the issue's `checks`
163 against it in a clean sandbox. `GET {repo}/pulls/{number}` returns
164 `checks.results`, each with `passed` and `output`. If they failed, push a
165 fix and they run again.
Issues and pull requests replace intents and attempts166- **Comment** on an issue or a pull request:
Acceptance checks in sandboxes, line comments and review verdicts167 `POST {repo}/issues/{number}/comments` with `body`. On a pull request, add
168 `path` and `line` to comment on one line of the change.
169- **Review** someone else's pull request:
170 `POST {repo}/pulls/{number}/reviews` with `verdict` (`approve` or
171 `request_changes`) and `body`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look172- **Merge** (the Write role or higher on the repository):
Issues and pull requests replace intents and attempts173 `POST {repo}/pulls/{number}/merge`. This closes the issue it was for and
174 closes the other pull requests for that issue as superseded; send
175 `{"keep_issue_open": true}` if this is only part of the work. A `409`
176 saying main has moved means the fork is behind: pull main from
177 `https://g1t.sh/{owner}/{name}.git` into the fork, push, and merge again.
Docs worth reading, and kept that way178 With the merge queue on, merging adds the pull request to the queue
179 instead; `GET {repo}/queue` shows it being tested with the pull requests
180 ahead of it, and it lands only if that combination passes.
181
182## Hand work to g1t agents
183
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look184Agents, checks, workflows, the merge queue and deployments run on g1t's
185machines, so they need a paid workspace, or the one-time $5 trial after a
186card check. Checks, workflows and the merge queue on public repositories
187can also run from g1t's open-source pool, after the same card check.
188Agents never run from the pool. Each workspace decides how its agents
189reach a model: its own provider (connected under Integrations, billed by
190the provider) or g1t's hosted models; the sandbox is g1t's either way.
191When the plan refuses a start, these calls answer with a failure whose
192message says what to do and where (such as `/acme/-/billing`). When every
193agent slot of the workspace is busy, the message starts "Waiting for a
194free slot" and the work starts by itself when one finishes.
Docs worth reading, and kept that way195
196- **Hand off an outcome:** `POST {repo}/plans` with `brief`: what should be
197 true when the work is done. A planner reads the repository and proposes
198 issues, each with its checks, the files it touches, and what it depends
199 on. Read it with `GET {repo}/plans/{plan}` until `status` is `ready`
200 (a minute or two), then `POST {repo}/plans/{plan}/apply` with
201 `{"assign": true}`. Agents start at once on every issue that depends on
202 nothing and on the rest as what they depend on lands. `keep` opens only
203 some of the issues, by position counting from 1.
204- **Assign one issue:** `POST {repo}/issues/{number}/assign`. The agent
205 opens a pull request, meets the issue's checks, is reviewed by a second
206 agent, revises, and catches up when main moves. There is no model or
207 agent count to choose: to put more agents to work, assign more issues.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step208- **Put an agent on something in one step:** `POST {repo}/issues/delegate`
209 with `title`, `body` (what to do, in plain words) and optionally
210 `checks`. It opens the issue and assigns g1t-agent at once; it needs the
211 Write role, and nothing opens without it. The issue opens even when the
212 agent cannot start: `agent.status` is `started` (with `pull`), `queued`,
213 or `not_started` with `agent.code` (`not_paid`, `trial_used`, `limit`,
214 `paused`, `issue_cap`, `no_model`), `agent.message` and `agent.fix_url`.
215- **How sure g1t is of a change:** once a g1t agent finishes, the pull
216 request's `confidence` is `high`, `medium` or `low` with short `reasons`
217 ("tests not added", "3 revisions"), from its checks, revisions, review,
218 tests, size, reach, guardrails and unanswered questions. The agent's own
219 word (`self_reported`, `uncertain_about`) can only lower it. With the
220 repository setting `hold_low_confidence` on (the default), a change rated
221 low waits for a person's approval instead of merging by itself.
Docs worth reading, and kept that way222- **Steer a working agent:** `POST {repo}/pulls/{number}/messages` with
223 `body`. It reads the message at its next step.
224- **g1t agents talk to each other.** A g1t agent asks the agent on another
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step225 pull request a question, or hands it work, with `agent` `message`
226 (`kind` `question` or `handoff`, and `from_number`, its own pull
227 request). The other agent replies with `agent` `answer`
Agents asked while not at work are woken to answer228 (`POST {repo}/messages/{id}/answer`); one that is not at work is woken
229 to answer, in its own pull request's sandbox. Plans show these exchanges under
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step230 "Agents talking". From any other caller, `agent` `message` sends a plain
Docs worth reading, and kept that way231 message.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)232
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step233Every one of these is also on the MCP server. Its tools are resources,
234each with an `action`: `search`, `repository`, `issue`, `pull_request`,
235`agent`, `plan`, `memory`, `workflow`, `secret`, `webhook`, `access`,
236`workspace` and `account`. Call `tools/call` with the tool's name and
237`arguments` holding `action` and its inputs, such as
238`{"name": "issue", "arguments": {"action": "get", "repo": "acme/web", "number": 12}}`.
239The flow above is: `issue` `get`, `memory` `recall`, `pull_request`
240`create` (with `issue`), push, `pull_request` `record_session` as you go,
241`pull_request` `ready` with `summary`; read `overlaps`, `behind` and checks
242on `pull_request` `get`. `agent` `delegate` and `agent` `assign` hand work
243to g1t's agent; `plan` `create`, `get` and `apply` plan an outcome;
244`memory` `remember` saves a fact. `search` runs `code` and `account` runs
245`whoami` when `action` is left out. A call missing a required field says
246which, such as "issue.get needs number.". The earlier one-tool-per-operation
247names (`get_issue`, `create_pull_request`, …) still answer for now but are
248no longer listed. Every tool and action, with its required fields and
249scope: https://docs.g1t.sh/reference/mcp/
250
251A g1t agent's own token can never change a repository's details, rename it
252or its branches, make it public or private, archive, transfer, delete,
253restore or purge it, or delete a workspace. MCP tools take the repository
254as `repo`, written `owner/name`.
255
256## Scopes
257
258Every access token and OAuth sign-in has scopes, `resource:level`:
259`repo`, `code`, `issues`, `pull_requests`, `workflows`, `memory`,
260`account`, `access`, `webhooks`, `secrets` (read, write or admin as each
261has them), `agents:run`, `workspace:read` and `workspace:admin`. A higher
262level includes the lower. A token may expire. It reaches every workspace
263and repository its owner can (a workspace's token, that workspace only);
264what a call may do is the owner's role and the token's scopes together.
265A token sees only the MCP tools and actions its scopes allow. A missing scope answers `403` with
266`{"error": {"code": "forbidden", "message": "This access token needs the issues:write scope to use create_issue.", "needed_scope": "issues:write"}}`.
267Pushing needs `code:write`; cloning a private repository `code:read`. For
268an agent, use the Agent preset (every read scope, plus `code:write`,
269`issues:write`, `pull_requests:write`, `agents:run`, `memory:write`).
270OAuth clients may send `scope`;
271the person can untick any; asking for none gives the Agent preset. Tokens
272from device sign-in (above) have full access. Guide:
273https://docs.g1t.sh/guides/authentication/#scopes
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look274
275## Access and roles
276
277Everyone's access to a repository is a role: `read` (read, clone, open
278issues and pull requests, comment), `triage` (also label, assign, close),
279`write` (also push, merge, and put agents to work: anything that spends
280compute), `maintain` (also settings, branch protection, guardrails) or
281`admin` (also webhooks, secrets, deployments, domains, who has access,
282rename, archive, visibility, default branch). Owners of a workspace have
283admin on all of its repositories and alone transfer or delete them;
284members get the workspace's base permission (write unless owners change
285it); anyone can be given a role on one repository, as an outside
286collaborator; anyone reads a public repository. The highest wins. A
287private repository you cannot read answers `404`; one you can read but
288lack the role for answers `403` naming the role needed. An agent works
289with the role of the person it acts for on its repository, never more
290than `write`, and its token can never change who has access. An outside
291collaborator with `write` can put agents to work; the runs are charged to
292the repository's workspace, and their agents are told the project's memory,
293never the workspace's. Who can do what elsewhere: deployments are seen with
294`read` (on a public repository, by anyone, build logs included), deployed
295with `write`, configured (settings, domains) with `admin`; project settings
296and dependencies need `maintain`; repository webhooks, secrets and
297variables need `admin`, seeing them included; security findings need
298`write`, allowing or resolving a secret `admin`, upkeep `maintain`;
299enabling or disabling a workflow needs `maintain`; plans and project memory
300are read by anyone who can read the repository, and project memory is
301changed with `write`; workspace memory is for members. People: the
302workspace's Settings → Members (`g1t.sh/<owner>/-/people`, with an Outside
303collaborators tab and the Base permission for owners); a repository's
304Settings → Access (`g1t.sh/<owner>/<repo>/settings/access`); invitations
305are answered at `g1t.sh/<owner>/<repo>/invitations`.
306`GET {repo}/collaborators/{username}/permission` gives a role and what it
307allows. Guide: https://docs.g1t.sh/guides/access-and-roles/
308
309## Manage a repository
310
311People with the admin role rename it (`POST {repo}/rename` with `name`; the
312old address redirects), make it public or private
313(`POST {repo}/visibility` with `private` and its full name in `confirm`),
314archive or unarchive it (`POST {repo}/archive`, `POST {repo}/unarchive`),
315and owners of its workspace delete it (`DELETE {repo}` with its full name
316in `confirm`). A deleted
317repository can be restored for 30 days (`POST {repo}/restore`, listed by
318`GET /workspaces/{workspace}/repos/deleted`) and is then purged; its name
319stays taken until then, or until `POST {repo}/purge`. Maintain changes the
320description, `website` and `topics` with `PATCH {repo}`, admin the
321`default_branch`, and write renames branches with
322`POST {repo}/branches/{branch}/rename` and `new_name` (slashes in the
323branch URL-encoded); only admin renames the default branch. An archived
324repository is read-only: pushes and merges are refused, issues and pull
325requests are locked, and agents and workflows do not run on it.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)326
Docs: integrations, and your own model provider327## Integrations
328
329A workspace's owners connect it to outside systems on its **Integrations**
330page, or with `POST /workspaces/{workspace}/integrations`:
331
A catalogue of model providers, and settings that feel like settings332- **Its own model providers** (`anthropic`, `openai`, `gemini`, `xai`,
333 `mistral`, `deepseek`, `azure_openai`, `openrouter`, `groq`, `together`,
334 `fireworks`, `cerebras`, `anthropic_endpoint`, `openai_endpoint`), as many
335 as it uses, with each
Model providers: gateway tokens for endpoints, tidier rows, and the docs336 kind of work routed to one of them or to g1t's hosted models
337 (`PUT /workspaces/{workspace}/model-routes`). Those providers bill the
Prices are what g1t pays plus 20%, from the first second338 workspace; g1t charges nothing while it is being built out (later, only
339 each run's sandbox time, at cost plus 20%). Sandboxes never hold a key.
Docs: integrations, and your own model provider340- **Alerts** (`sentry`, `datadog`, `webhook`): each problem opens one issue
341 in a chosen repository, optionally with an agent put on it at once.
342 Senders sign requests to `https://api.g1t.sh/hooks/{integration}`.
343- **Trackers** (`jira`, `linear`): `GET {repo}/context?reference=TECH-1234`
344 fetches a ticket; `POST {repo}/issues/import` with `reference` (and
345 `assign`) opens a linked issue. Agents get tickets their work mentions in
346 their starting context. Ticket text is reference material, never
347 instructions.
348
Webhooks: every event, to your own addresses, signed and retried349## Webhooks
350
351`POST {repo}/hooks` (or `/workspaces/{workspace}/hooks` for every
352repository in a workspace) with `url` and optional `events` sends events
353to that HTTPS address as they happen, signed in `X-G1t-Signature-256`
354(HMAC-SHA256 of the body), retried for about seven hours. Deliveries,
355with request and response, are at `…/hooks/{id}/deliveries`.
356
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs357## GitHub Actions
358
359GitHub Actions workflows run on g1t unchanged, from `.g1t/workflows/`
360(g1t never reads `.github`): moving a repository is `git mv .github .g1t`.
361Runs, jobs and logs are at GitHub's own routes under
362`{repo}/actions/...`. A run on a pull request's head is a check: pending
363holds the merge, failure refuses it and sends a g1t agent back to fix it.
Secrets and variables: one list, rows per environment, for workflows and deployments364Secrets and variables are one list per repository (site:
365`g1t.sh/<owner>/<repo>/settings/secrets`) and per workspace: each row is a
366key, Secret or Config, the environments it applies to (all, or e.g.
367production/preview, or a job's `environment:`), and whether workflows,
368deployments or both read it. API: `{repo}/actions/secrets` and
369`{repo}/actions/variables` (GitHub's routes) with extra `environments`,
Deployments work end to end: fixes from the first live run370`available_to`, `repositories`, `note`, `id`. Trusted jobs get
Secrets and variables: one list, rows per environment, for workflows and deployments371`secrets.G1T_TOKEN` (the workspace's token; `GITHUB_TOKEN` is its alias),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look372which cannot change secrets. A pull request's runs and preview are trusted
373only when its author has `write` or higher on the repository (a member or
374an outside collaborator) or is g1t's agent; anyone else's run with config
375only. Guide:
Secrets and variables: one list, rows per environment, for workflows and deployments376https://docs.g1t.sh/guides/secrets-and-variables/
Docs: automations377
Projects: what a workspace builds and runs, first on every page378## Projects
379
380A project is what a workspace builds and runs; every repository is a
381project of its own name (`g1t.sh/<owner>/<project>` opens its overview; its
382code is under `/code`; every repository address still works). Deployments,
383secrets and variables belong to the project; branches, pull requests,
384review and merge rules to its repository (Settings → Repository). Guide:
385https://docs.g1t.sh/guides/projects/
386
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API387## Security
388
389A push that adds a known key or token format (AWS, GitHub, GitLab, Stripe
390live, Slack, Google, Anthropic, OpenAI, npm, g1t, SendGrid, PEM private
391keys, service-role JWTs) is refused with `file:line` in git's output; this
392includes an agent's push to its pull request. Never commit a secret: read it
393from the environment. A test fixture that only looks like one carries
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look394`g1t:allow-secret` in a comment on its line; someone with admin can also allow a
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API395finding once at `g1t.sh/<owner>/<project>/security`. Lockfiles (npm, pnpm,
396yarn, Cargo, Go, Python) are checked against OSV on every default-branch
397push and daily; each vulnerable package with a fix gets an issue "Upgrade
398<package> to <version>: fixes <advisory>" labelled `dependencies` and
399`security`, whose acceptance checks fail while the lockfile still resolves
400the vulnerable version and run the tests. An agent on one upgrades the
401package and fixes whatever the upgrade breaks, in the same pull request.
402Guide: https://docs.g1t.sh/guides/security/
403
Deployments: a preview for every pull request, production on g1t.page404## Deployments
405
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look406Part of the g1t plan ($20 a month per workspace, started by an owner
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas407under the workspace's Billing). No quotas: unlimited projects and
408previews (never charged); builds by the second, requests ($0.36/M), CPU
409($0.024/M ms) and custom domains ($0.12 a month each) metered from the
410first at cost + 20%, from the plan's $10 first. The trial
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look411never covers deployments. Then someone with admin on the repository
Projects: what a workspace builds and runs, first on every page412turns deployments on for a project (Settings → Deployments, or Deploy on
413its overview). Production deploys from the default branch to
414`https://<project>-<owner>.g1t.page` on each push; every branch with an
415open pull request gets a preview at
416`https://<project>-git-<branch>-<owner>.g1t.page` (a fork's pull request is
417`pr-<n>`), shown on it as the check `g1t / deploy`. Builds and running apps
418read the project's secrets and variables available to Deployments, each
419key's Production or Preview row. Workers projects (`wrangler.jsonc`) and
420static sites build without configuration. Previews come down when the pull
421request closes and after idle days. There is no API for deployments yet.
422Guide: https://docs.g1t.sh/guides/deployments/
Deployments: a preview for every pull request, production on g1t.page423
Search across all of g1t, Explore, and a command palette424## Search
425
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step426`GET https://api.g1t.sh/search?q=<query>&type=<type>` (MCP: `search`, action `code`, the default)
Search across all of g1t, Explore, and a command palette427searches all of g1t: repositories (name, description, topics, README), code
428on default branches, issues, pull requests, people and workspaces. No token
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look429needed for public results; with one, private results the token's person
430can read are included (their workspaces' repositories, and those they were
431given a role on), checked against current membership and roles. `type` is
Search across all of g1t, Explore, and a command palette432`repositories`, `code`, `issues`, `pulls` or `people` (worked out from the
433qualifiers when left out); `page` and `per_page` (at most 50) page through.
434The query takes words, `"exact phrases"`, `-word` to leave out, and
435`repo:owner/name`, `org:<workspace>`, `language:<lang>`, `path:<prefix or
436*.glob>`, `is:issue`, `is:pr`, `is:open`, `is:closed`, `is:merged`,
437`author:<username>`, `label:<label>`. Code search matches any run of three
438characters or more; vendored directories, lockfiles, binaries and files
439over 512 KB are not indexed. Results give `counts` per type and each hit's
440`snippet` or code `lines` as parts with `highlight`. On the site:
441`https://g1t.sh/search?q=`, ⌘K, and `https://g1t.sh/explore` for public
442projects by activity, language (`?language=`) and topic (`?topic=`).
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step443The `search` tool's `context` action stays the search of one workspace's
444context hub. Guide:
Search across all of g1t, Explore, and a command palette445https://docs.g1t.sh/guides/search/
446
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)447## Facts
448
API and MCP server in Rust; a public index at the API root449- API base: `https://api.g1t.sh`. `GET /` lists every URL as a template.
450 Auth: `Authorization: Bearer g1t_…`. Public data needs no token. Errors are
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)451 `{"error": {"code": "…", "message": "…"}}` with codes `unauthenticated`
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step452 (401), `forbidden` (403, with `needed_scope` when the token lacks a
453 scope), `not_found` (404), `conflict` (409), `invalid` (422). Each
454 operation's scope is `x-scope` in the OpenAPI document. The full description is at https://api.g1t.sh/openapi.json.
Workspaces own repositories455- Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths,
Issues and pull requests replace intents and attempts456 `{owner}` is the workspace. Pull request forks:
457 `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)458- Limits: 1 GB per repository, 32 MB per file, 100 MB per push.
Device sign-in replaces registering and minting tokens over the API459- Forgotten password: https://g1t.sh/forgot (the person does this, in a
460 browser).
Issues and pull requests replace intents and attempts461- Times are RFC 3339 in UTC.
OAuth 2.1 sign-in for MCP clients and other applications462- OAuth 2.1 for applications: metadata at
463 `https://api.g1t.sh/.well-known/oauth-authorization-server`; authorization
464 code with PKCE (S256), public clients, dynamic registration.
Acceptance checks in sandboxes, line comments and review verdicts465- A pull request whose checks have not passed is refused a merge with
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look466 `409`; someone who can merge can send `{"ignore_checks": true}`.
Acceptance checks in sandboxes, line comments and review verdicts467- Not available yet: merge commits made on the server.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look468- Pricing (https://g1t.sh/pricing): the forge is free. One plan, g1t, at
469 $20 a month per workspace with unlimited members, includes $10 of usage
470 at cost + 20% (unused does not roll over). Compute needs the plan or a
471 card check (never charged); the $5 trial needs a credit or debit card,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas472 not a prepaid one. No quotas on the plan: everything is metered from the
473 first unit at cost + 20%, and only the spend limit stops work. Every
474 workspace has 1 GB of private storage and 50,000 git operations a month
475 free; past them, the plan pays ($0.60/GB-month, $0.18/1,000) and a free
476 workspace is held (pushes to private repositories stop; git slowed to 60
477 an hour). Limits: $100 in a
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look478 paid workspace's first month, rising as payments clear; owners set a
479 spend limit, prepay, or ask with Raise my limit. Caps: $2 a run and $10
480 an issue by default. A spend spike pauses new compute until an owner
481 chooses Keep going or Stop (`/<workspace>/-/billing`). Audit log: 90 days
482 on every plan.
Account dropdown, llms.txt onboarding, hosted agent runner (not yet deployed)483
484## More
485
Device sign-in replaces registering and minting tokens over the API486- [Quickstart](https://docs.g1t.sh/quickstart/)
Docs worth reading, and kept that way487- [How g1t works](https://docs.g1t.sh/concepts/overview/)
Search across all of g1t, Explore, and a command palette488- [Search and Explore](https://docs.g1t.sh/guides/search/)
Docs worth reading, and kept that way489- [g1t agents](https://docs.g1t.sh/guides/g1t-agents/)
490- [Outcomes and plans](https://docs.g1t.sh/guides/outcomes/)
491- [Talking to agents](https://docs.g1t.sh/guides/talking-to-agents/)
492- [Bring your own agent](https://docs.g1t.sh/guides/bring-your-own-agent/)
493- [The merge queue](https://docs.g1t.sh/guides/merge-queue/)
494- [Sessions and why-blame](https://docs.g1t.sh/guides/why-blame/)
Device sign-in replaces registering and minting tokens over the API495- [Forks and branches](https://docs.g1t.sh/concepts/forks/)
Docs worth reading, and kept that way496- [Accounts and sign-in](https://docs.g1t.sh/guides/authentication/)
497- [Workspaces and tokens](https://docs.g1t.sh/guides/workspaces/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look498- [Access and roles](https://docs.g1t.sh/guides/access-and-roles/)
499- [Managing a repository](https://docs.g1t.sh/guides/managing-repositories/)
Docs: integrations, and your own model provider500- [Integrations](https://docs.g1t.sh/guides/integrations/)
Model providers: gateway tokens for endpoints, tidier rows, and the docs501- [Model providers](https://docs.g1t.sh/guides/models/)
Webhooks: every event, to your own addresses, signed and retried502- [Webhooks](https://docs.g1t.sh/guides/webhooks/)
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs503- [GitHub Actions](https://docs.g1t.sh/guides/actions/)
Docs worth reading, and kept that way504- [Usage and billing](https://docs.g1t.sh/guides/usage-and-billing/)
Docs as their own app; shared theme package505- [Git](https://docs.g1t.sh/guides/git/)
Docs worth reading, and kept that way506- [MCP tools](https://docs.g1t.sh/reference/mcp/)
Merge branch 'worktree-agent-ab2e39e11a6493412'507- [API reference](https://docs.g1t.sh/reference/api/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look508- [Source](https://g1t.sh/flagon-io/g1t), MIT licensed
509
510## Help, status and policies
511
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas512- [Status](https://status.g1t.sh/): whether each part of g1t is working now, 90 days of uptime, and incidents; the same as JSON at https://status.g1t.sh/status.json
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look513- [Support](https://g1t.sh/support): where to get help (hey@flagon.io, hey@flagon.io)
514- [Security](https://g1t.sh/security): how g1t protects code and accounts, and responsible disclosure (hey@flagon.io, https://g1t.sh/.well-known/security.txt)
515- [Policies](https://g1t.sh/policies): [Terms of Service](https://g1t.sh/policies/terms), [Privacy Policy](https://g1t.sh/policies/privacy), [Acceptable Use](https://g1t.sh/policies/acceptable-use), [Refunds and Cancellation](https://g1t.sh/policies/refunds), [Subprocessors](https://g1t.sh/policies/subprocessors)
516- g1t is made by Flagon, Inc. (https://www.flagon.io)

This file's history is long; its oldest lines are credited to the oldest commit read.