Skip to content
957 linesCodeBlameRaw
1---
2title: Workspaces
3description: Workspaces, their names and icons, renaming and deleting one, members, owners and the roles that add to a member, member privileges, requiring two-factor authentication, and access tokens that belong to a workspace.
4---
5
6A workspace owns repositories and is the first part of their address:
7`g1t.sh/<workspace>/<repo>`. There is one kind. A workspace for just you and
8one for a company are the same thing with a different number of members, so
9there is no separate notion of an organization.
10
11## Create a workspace
12
13Your account does not own repositories itself: a workspace does, and
14repositories go in it. Every new account gets a workspace of its own, named
15for its username and on the free plan, unless its invite brings it into
16someone else's workspace; see
17[your first workspace](/guides/authentication/#your-first-workspace).
18Signed in without a workspace, g1t shows **Create your workspace or ask to
19join one** in place of Mission control: the invitations waiting for you,
20and the form below.
21
22To create another:
23
241. Open [g1t.sh/workspaces/new](https://g1t.sh/workspaces/new).
252. Choose its name in URLs: lowercase letters, digits and single hyphens.
26 An owner can [change it later](#rename-a-workspace), and old addresses
27 redirect for 90 days.
283. Optionally give it a display name.
29
30From the API, `POST /workspaces` with `slug` and `name`, or the
31`workspace` tool's `create` action:
32
33```sh
34curl -X POST https://api.g1t.sh/workspaces \
35 -H "Authorization: Bearer $G1T_TOKEN" \
36 -H "Content-Type: application/json" \
37 -d '{"slug": "acme", "name": "Acme"}'
38```
39
40You can belong to up to ten workspaces. `GET /user`, or the `account` tool's `whoami` action, lists the
41ones you belong to.
42
43A new workspace is free, and **each person can own one free workspace**.
44While you own a free workspace, the page shows **You already own a free
45workspace** in place of the form, with **Start the plan** on it; the API
46answers `402` (`payment_required`). Start the plan on it, or delete it,
47then create the new one. Several free workspaces from before are kept, but
48each needs the plan (or deleting) before you can create another. See
49[one free workspace per person](/guides/usage-and-billing/#one-free-workspace-per-person).
50
51Usernames and workspaces share one set of names, so a name means the same
52thing wherever it appears. Your username is reserved for you: only you can
53create a workspace with that name, and nobody can register a username that
54is already a workspace. The names `g1t` and `g1t-agent` belong to
55[g1t's agent](/guides/working-with-g1t/), and nobody can register them.
56
57## Display name, slug and icon
58
59A workspace has two names:
60
61| | Example | Where it appears | Changes |
62| --- | --- | --- | --- |
63| **Display name** | `Flagon Industries` | The sidebar, the top of its page, mission control and link previews | Any time, up to 80 characters; spaces and capitals are fine |
64| **Slug** | `flagon` | Every address: `g1t.sh/flagon/<repo>`, clone URLs, API paths and `g1t.page` app addresses | By an owner, once a day at most; the old one redirects for 90 days. See [rename a workspace](#rename-a-workspace) |
65
66Without a display name, the slug is shown. Where an address is shown, the
67slug is in monospace beside the name. Owners change the display name and
68description (up to 160 characters) on **Settings → General**, or with
69[`PATCH /workspaces/{workspace}`](/reference/api/workspaces/update-workspace/)
70(MCP: `workspace` `update`), which takes `name` and `description` and
71changes only the fields given. It needs the `workspace:admin` scope, and
72is recorded in the [audit log](/guides/audit-log/):
73
74```sh
75curl -X PATCH https://api.g1t.sh/workspaces/flagon \n -H "Authorization: Bearer $G1T_TOKEN" \n -H "Content-Type: application/json" \n -d '{"name": "Flagon Industries", "description": "Rockets, and the software that flies them."}'
76```
77
78Neither changes the slug; that is a [rename](#rename-a-workspace).
79
80A workspace also has an icon. Without
81one, g1t draws its first letter in a colour of its own. To upload one, an
82owner opens **Settings → General** and picks an image:
83
84- PNG, JPEG, WebP or GIF, at most 1 MB. Square images look best.
85- An image is checked by its contents, not its name. SVG is refused,
86 because it can carry script.
87- **Remove** goes back to the letter.
88
89The icon then shows wherever the workspace does, and on its link previews
90(PNG and JPEG icons only). Each image is served from
91`g1tusercontent.com/avatars/<sha256>`, an address named after its contents, so an icon
92that changes gets a new address and nothing shows the old one.
93
94You can upload a picture of yourself the same way, under
95[Settings → Profile](https://g1t.sh/settings/profile).
96
97## Rename a workspace
98
99Renaming changes the slug, the first part of every address under the
100workspace. The display name is separate; change it on its own under
101**Settings → General → Workspace details**. Only owners can rename a
102workspace.
103
1041. Open the workspace's **Settings → General** and go to **Address**.
1052. Type the new slug. The field shows the new address, `g1t.sh/<new>`, and
106 whether the name is available.
1073. Choose **Change address**, read what changes, type the new slug to
108 confirm, and choose **Change address** again.
109
110You land on the workspace's settings at its new address. Repositories,
111issues and the rest move with it within a few seconds.
112
113### What changes
114
115| | Before | After |
116| --- | --- | --- |
117| Pages | `g1t.sh/old/<repo>` | `g1t.sh/new/<repo>` |
118| Git remotes | `https://g1t.sh/old/<repo>.git` | `https://g1t.sh/new/<repo>.git` |
119| API paths | `https://api.g1t.sh/repos/old/<repo>` | `https://api.g1t.sh/repos/new/<repo>` |
120| MCP tool arguments | `"owner": "old"` | `"owner": "new"` |
121| Production apps | `https://<project>-old.g1t.page` | `https://<project>-new.g1t.page` |
122| Previews | `https://<project>-git-<branch>-old.g1t.page` | `https://<project>-git-<branch>-new.g1t.page` |
123
124These stay the same: the display name, description and icon, members and
125roles, access tokens, secrets and variables, integrations, webhooks,
126issues and pull requests, and billing, plans and credit.
127
128### What redirects, and for how long
129
130For 90 days after a rename, the old name keeps working:
131
132| | Behaviour |
133| --- | --- |
134| Web pages | Answer with a permanent redirect (301) to the same page under the new name, query string included. |
135| `git clone`, `fetch`, `pull` and `push` | Redirected to the new remote. Git follows it, but prints a warning each time until you update the remote. |
136| API and MCP | A call that names the old slug runs under the new one. |
137| `g1t.page` apps | Production and preview addresses under the old name redirect to the new ones. |
138
139Update your remotes now rather than relying on the redirect:
140
141```sh
142git remote set-url origin https://g1t.sh/<new>/<repo>.git
143```
144
145Update anything else that has the old name written into it, too: links in
146READMEs and docs, CI configuration, API clients and MCP clients.
147
148### Limits
149
150- A workspace can be renamed once every 24 hours.
151- For 90 days the old name is held for the workspace. Nobody else can take
152 it, and you can rename back to it.
153- After 90 days the redirects stop, and anyone can create a workspace or
154 register a username with the old name. Links and remotes that still use
155 it then reach whatever has the name, or nothing.
156- The new name follows the same rules as a new workspace: lowercase letters,
157 digits and single hyphens, up to 39 characters, not a reserved word, and
158 not another workspace's slug or someone else's username.
159
160## Data residency
161
162Data residency says where the git data of the workspace's new repositories
163is stored. The section appears in **Settings** once g1t can store
164repositories in the EU. Until then it is not shown, and every repository is
165stored wherever g1t stores repositories.
166
167| Setting | What it does |
168| --- | --- |
169| Anywhere | New repositories are stored wherever g1t stores repositories. The default. |
170| EU only | New repositories are stored in the EU. If EU storage cannot take one right now, the repository is not made, and you are told why. It is never stored somewhere else instead. |
171
172To change it:
173
1741. Open the workspace, then **Settings**. Only owners see the page.
1752. Under **Data residency**, choose **Anywhere** or **EU only**.
1763. Select **Save**.
177
178The setting applies to repositories made after you save it, however they
179are made: from the site, with the API, by pushing to a new address, or by
180importing. Repositories the workspace already has stay where they are. To
181move them, contact support; a move keeps each repository's address, history
182and settings, and pushes to it wait a few minutes while it happens.
183
184Data residency covers the git data: commits, branches, tags and files,
185including pull requests' working copies, which are stored with their
186repository. Issues, pull requests, comments and settings are not affected.
187A repository [transferred](/guides/transferring-repositories/) to another
188workspace stays where it is stored.
189
190Changing the setting is recorded in the
191[audit log](/guides/audit-log/) as `workspace.residency_changed`.
192
193## Delete a workspace
194
195Deleting a workspace takes everything in it with it, in one step: its
196repositories, projects, apps, members' access and tokens. Only an owner can,
197signed in as a person, typing the workspace's slug to confirm.
198
199It is not gone at once. For **30 days** g1t keeps all of it, so that a
200deletion you did not mean, or did not make, can be undone: an owner writes
201to support@g1t.sh, and support restores the workspace as it was. After 30
202days it is purged for good.
203
2041. Open the workspace's **Settings → General** and go to **Danger zone**.
205 It lists what will go with the workspace: its repositories, projects,
206 live apps and members.
2072. Choose **Delete workspace**, read what happens, type the workspace's
208 slug to confirm, and choose **Delete workspace** again. You are taken
209 back to your own home.
210
211The one thing that can stand in the way is billing: see
212[what billing needs](#what-billing-needs). Repositories you want to keep in
213another workspace, [transfer](/guides/transferring-repositories/) first;
214their old addresses keep redirecting after the workspace is gone.
215
216From the API, call
217[`DELETE /workspaces/{workspace}`](/reference/api/workspaces/delete-workspace/)
218with the slug in `confirm`; over MCP, the `workspace` tool's `delete`
219action.
220
221Some workspaces can never be deleted, by anyone, such as Flagon's, which
222runs g1t. Their Danger zone says so instead of offering the button.
223
224### What billing needs
225
226| | |
227| --- | --- |
228| Money owed | Charged to the workspace's card at once, with no minimum charge. With no card, add one or pay from **Billing** first. |
229| An unpaid invoice | Pay it from **Billing** first. |
230| Prepaid credit | It would be lost: spend it, or write to support@g1t.sh about a refund, first. |
231| Usage this month still being metered | Storage and git operations are charged when the month closes. You can delete the workspace from the 1st of next month. |
232| The g1t plan | Ends at Stripe at once, not at the end of the period. |
233| An enterprise account | A workspace billed through one is moved off it by g1t first: write to support@g1t.sh. |
234
235A comped workspace owes nothing; only its plan is ended.
236
237### What happens
238
239At once, when an owner deletes it:
240
241| | |
242| --- | --- |
243| Members | Lose access, and the workspace leaves their list. Their own accounts are not touched: a person with no workspace left can still sign in, and create or join one. |
244| Access tokens | The workspace's own tokens stop working. Personal tokens are not affected. |
245| Repositories | Deleted with it: git refuses them, and their pages answer 404. Agents and workflow runs stop. Ones deleted on their own earlier stay deleted. |
246| Projects and apps | Hidden. Its apps are taken offline and nothing builds. Custom domains are kept for a restore. |
247| Its pages | Answer 404, and it drops out of search. |
248| Billing | What it owes is charged, and its plan ends, as [billing needs](#what-billing-needs). Nothing more is charged. |
249| The audit log | Records the deletion. |
250
251Within 30 days, support can restore it: its members, tokens, repositories,
252projects and apps come back as they were, and its apps go back up as its
253limit allows. Its plan does not come back by itself: an owner starts it
254again from **Billing**. A repository deleted on its own before the
255workspace was stays in **Recently deleted**.
256
257After 30 days it is purged:
258
259| | |
260| --- | --- |
261| Repositories | Purged, their git data with them, including any that were in Recently deleted. |
262| Projects, apps and custom domains | Removed. |
263| Webhooks, integrations, secrets and variables | The workspace's own are removed. |
264| Memory and guardrails | The workspace's own are removed. |
265| Statements, invoices and the ledger | Kept, for accounting. |
266| The audit log | Kept as [long as its account keeps it](/guides/audit-log/#how-long-it-is-kept), with the purge as its last entry: once the plan ends with the workspace, that is 7 days, unless an enterprise pays for it or longer was arranged. With no owners left, ask support@g1t.sh for an export. |
267| Old addresses | Redirects for repositories transferred out keep working. The workspace's own pages answer 404. |
268
269### The name afterwards
270
271A deleted workspace's slug is never given to another workspace or used as
272someone else's username. While it can still be restored, the slug is held
273for it. Links and git remotes that still use it keep
274meaning what they meant: a transferred repository's old address keeps
275redirecting to it, and nobody can take the name in the meantime.
276
277The one exception: when the slug is your own username, you may create a
278workspace with that name again once the old one is purged. It starts empty, on standard billing terms,
279and a repository made in it at an old address ends that address's redirect.
280
281## Members and roles
282
283<a id="members-and-owners"></a>
284
285| Role | Can |
286| --- | --- |
287| Member | Create repositories (as the [member privileges](#member-privileges) allow), see the workspace's usage and billing, and get the workspace's [base permission](/guides/access-and-roles/#the-base-permission) on every repository in it: Read for a new workspace, which an owner can raise to Write to let members push, merge pull requests, plan work and put g1t to work. Admin on the repositories they create. |
288| Owner | Everything a member can, and manage members and owners, the base permission, the member privileges, two-factor requirement, the workspace's access tokens, its details, and billing: the plan, card checks, prepayment and limits. Admin on every repository, and the only ones who can transfer and delete them unless the member privileges allow admins; see [access and roles](/guides/access-and-roles/). |
289
290A workspace can have any number of owners, and always has at least one.
291
292### Roles that add to a member
293
294An owner can give a member one or both of these roles. Each adds to what
295the member already has; an owner has both already.
296
297| Role | Adds |
298| --- | --- |
299| **Billing manager** | Manages the workspace's billing as an owner does: the plan, budget and spend limit, AI credit and auto-reload, the card, billing details and invoices. Gives nothing on repositories. |
300| **Security manager** | Read on every repository, and seeing and managing every security alert and security setting on them: dismissing and reopening alerts, custom patterns, reviewing push protection bypass requests, and the workspace's security settings. |
301
302Neither passes to an agent working for the person.
303
304### Change someone's role
305
306On **Members and invites**, `g1t.sh/<workspace>/-/members` (People →
307Members and invites), an owner opens the **⋯** menu beside a member:
308
3091. **Make owner** or **Make member** changes their role.
3102. **Billing manager** and **Security manager** turn each role on or off.
3113. **Transfer ownership…** hands the workspace to that member: they become
312 an owner and you a member, in one step. To add an owner without stepping
313 down, choose **Make owner** instead.
3144. **Remove from {workspace}…** takes them out. Their roles on its
315 repositories and their place in its teams go too.
316
317Owners see a shield beside each member: green when two-factor
318authentication is on, amber when it is off.
319
320The last owner cannot be made a member, removed, or leave: make someone
321else an owner first, or [delete the workspace](#delete-a-workspace).
322
323### Leave a workspace
324
325Anyone can leave a workspace they belong to: at the bottom of **Members and
326invites**, choose **Leave {workspace}** and confirm. Your roles on its repositories
327and your place in its teams go with you at once. The only owner cannot
328leave.
329
330### Add people
331
332Whoever creates a workspace is its owner. Nobody is added to a workspace
333without saying yes: an owner invites people, and each person accepts or
334declines.
335
336This is an invitation to join one workspace. It is not the same as an
337invite to g1t, which only lets someone make an account:
338
339| | Invite to a workspace | Invite to g1t |
340| --- | --- | --- |
341| Where | The workspace's **Members and invites** page, **Invite to** *workspace* | [Settings → Invites](https://g1t.sh/settings/invites) |
342| What they get | An invitation to join the workspace, to accept or decline | One new account, in no workspace but its own |
343| Without an account | The invitation lets them sign up first, while g1t is invite-only | It lets them sign up |
344| When | Always | Only while g1t is invite-only |
345
346To invite someone to g1t without adding them to your workspace, use
347[Settings → Invites](/guides/authentication/#making-invites); the Members
348and invites page links there while g1t is invite-only.
349
350On the workspace's **Members and invites**, `g1t.sh/<workspace>/-/members`
351(People → Members and invites in the sidebar):
352
3531. Under **Invite to** *workspace name*, type a username, a name or an email address.
354 As you type, people on g1t are offered by username and name, with their
355 pictures; hover over one for their card. Only usernames, names and
356 pictures are shown, never anyone's email address.
3572. Choose the **Role** they join with: **Member** or **Owner**.
3583. Select **Invite**.
359
360- **By username**: they get a
361 [workspace invitation](/guides/authentication/#workspace-invitations) in
362 their notifications and by email, and join with that role when they accept at
363 [g1t.sh/invitations](https://g1t.sh/invitations). If they decline, you
364 are told in your notifications. It costs nothing.
365- **By email address**: g1t emails an invite that only that address can
366 use. With a g1t account, it is a workspace invitation like the one above
367 and costs nothing. Without one, the invitation also lets them make the
368 account first; while g1t is invite-only that uses one of the workspace's
369 granted invites, or else one of yours (see
370 [invites](/guides/authentication/#invites)), and once anyone can sign up
371 it costs nothing. The new account is then invited to the workspace, and
372 joins when it accepts. The page never says which it was.
373
374The email names you and the workspace and links to the invite's page.
375Someone new signs up right there, with the invited address filled in; once
376the address is confirmed (straight away when they opened the page from
377that email, which proves the address is theirs, otherwise with the code g1t
378emails them), they are asked to accept or decline the invitation. Someone
379with an account signs in and accepts on the page. Accepting lands them in
380the workspace, with a one-time welcome. See
381[using an invite](/guides/authentication/#using-an-invite).
382
383Pending invitations are listed under the members, with the person or
384address, the role, until when it works (30 days), a link to copy and
385**Revoke**: one waiting to be used, one whose new account is **confirming
386their email**, and one **waiting for them to accept**. Converting an
387outside collaborator to a member sends them an invitation the same way.
388Through the API, use
389[`POST /workspaces/{workspace}/invitations`](/reference/api/invites/invite-member/)
390with a `username` or an `email` and a `role` (the `workspace` tool's
391`invite_member` action over MCP); the person answers with
392[`POST /user/invitations/{id}/accept`](/reference/api/invites/accept-invitation/)
393or [`/decline`](/reference/api/invites/decline-invitation/).
394
395To give someone a role on one repository without making them a member,
396add them as an [outside collaborator](/guides/access-and-roles/#outside-collaborators).
397
398**A free workspace cannot add people.** Until it starts the g1t plan, it
399cannot add members, send invites, or invite outside collaborators, and an
400invite sent before waits until the plan is on. Its members stay. Members and
401invites shows **Start the plan to invite people** with the button in place of the
402form, and the API and MCP answer `402` (`payment_required`). See
403[who a free workspace can add](/guides/usage-and-billing/#who-a-free-workspace-can-add).
404
405### Members through the API
406
407| Route | MCP tool and action | What it does | Who |
408| --- | --- | --- | --- |
409| `GET /workspaces/{workspace}/members` | `workspace` `list_members` | Its members, owners first: `role` (`owner` or `member`), `org_roles` (`billing_manager`, `security_manager`) and, for owners, `two_factor`. | Members |
410| `PATCH /workspaces/{workspace}/members/{username}` | `workspace` `update_member` | Change `role` and `org_roles` (a list that replaces theirs). | Owners |
411| `DELETE /workspaces/{workspace}/members/{username}` | `workspace` `remove_member` | Remove someone. Your own username is leaving. | Owners |
412| `POST /workspaces/{workspace}/transfer_ownership` | `workspace` `transfer_ownership` | Hand it to `username`: they become an owner, you a member. | Owners |
413| `DELETE /user/memberships/{workspace}` | `workspace` `leave` | Leave it. | You |
414
415Each is for people, signed in or with a personal access token; never an
416agent. A change that would leave no owner answers `409`.
417
418```sh
419curl -X PATCH https://api.g1t.sh/workspaces/acme/members/grace \
420 -H "Authorization: Bearer $G1T_TOKEN" \
421 -d '{"org_roles": ["security_manager"]}'
422```
423
424## Member privileges
425
426What members can do beyond their role on each repository. Owners set them
427in the workspace's **Settings → Member privileges**,
428`g1t.sh/<workspace>/-/settings#member-privileges`, and can always do all of
429it themselves.
430
431| Setting | Default | When on |
432| --- | --- | --- |
433| **Members can create public repositories** (`members_can_create_public_repositories`) | On | Any member can create a public repository. |
434| **Members can create private repositories** (`members_can_create_private_repositories`) | On | Any member can create a private repository. |
435| **Repository admins can change visibility** (`members_can_change_repo_visibility`) | On | A member with Admin on a repository can make it public or private, if they could create one of that kind. |
436| **Repository admins can delete and transfer repositories** (`members_can_delete_repositories`) | Off | A member with Admin on a repository can delete it, or transfer it to a workspace where they can create one. |
437| **Repository admins can add outside collaborators** (`members_can_invite_outside_collaborators`) | On | A member with Admin on a repository can give a role on it to someone outside the workspace. |
438
439When one is off, only owners can do it; the refusal says so. Someone who is
440not a member, an outside collaborator with Admin, never gets these.
441Forking private repositories is not a setting: g1t has no personal forks
442to allow or refuse.
443
444Through the API, `GET /workspaces/{workspace}` returns each by its name,
445and [`PATCH /workspaces/{workspace}`](/reference/api/workspaces/update-workspace/)
446sets any of them (`workspace` `update` over MCP). Each change is in the
447[audit log](/guides/audit-log/) as `workspace.member_privileges_changed`.
448
449## Require two-factor authentication
450
451An owner can require everyone with access to the workspace, its members
452and its outside collaborators, to have
453[two-factor authentication](/guides/authentication/#two-factor-authentication)
454on.
455
4561. Turn it on for your own account first.
4572. Open **Settings**, `g1t.sh/<workspace>/-/settings#two-factor`. Under
458 **Authentication security**, it says how many members do not have it on,
459 and who.
4603. Turn on **Require two-factor authentication** and choose **Save**.
461
462From then on, someone without it keeps their place but cannot use the
463workspace: its private repositories, pages and API answer as if they were
464not a member, and every page shows them a notice with a link to turn it
465on. Turning it on gives everything back at once. Nobody can join or accept
466an invitation to the workspace without it.
467
468Through the API, `two_factor_requirement_enabled` on
469`PATCH /workspaces/{workspace}`. Recorded as `workspace.two_factor_required`
470and `workspace.two_factor_not_required`.
471
472## The workspace's page
473
474A workspace's own page, `g1t.sh/<workspace>`, has its icon, name, address
475and description at the top, then its overview: your
476[pinned projects](#pinned-and-recent-projects), then the most active ones,
477the pull requests in progress across them, and **All projects**. Members
478also see a **Usage** card with this month's spend, and who belongs.
479
480The workspace's other pages each have a heading of their own and a row in
481[the sidebar](#the-sidebar), lit while you are on them. The trail in the
482top bar, such as *acme / Projects*, leads back to the workspace's page.
483
484| Page | Address | Who | |
485| --- | --- | --- | --- |
486| **Overview** | `g1t.sh/<workspace>` | Everyone | The page above. |
487| **Projects** | `/-/projects` | Everyone | Every project you can see. See [the Projects page](#the-projects-page). |
488| [**Packages**](/guides/packages/) | `/-/packages` | Everyone | What the workspace publishes. A visitor opens it from **Packages** on the workspace's page. |
489| [**Teams**](/guides/teams/) | `/-/teams` | Members | Groups of members given roles on repositories together, mentioned as `@workspace/team` and asked to review together. Each team has its own page at `/-/teams/<team>`. |
490| [**People**](/guides/people-and-teams/) | `/-/people` | Members | The workspace's people, with their titles, teams and what they own. Each has a profile at `/-/people/<username>`. Agents are not in it; an agent's page is `/-/agents/<handle>`. |
491| [**Org chart**](/guides/people-and-teams/#the-org-chart) | `/-/org-chart` | Members | Who reports to whom, with the agents on the teams each person leads beside them. |
492| **Members and invites** | `/-/members` | Members | Who belongs. Owners invite, change roles and remove people here. |
493| **Insights** | `/-/insights` | Members | Coming soon: how the whole workspace delivers. |
494| **Settings** | `/-/settings` | Owners | How the workspace is set up and connected (below). |
495
496Each person sees the projects they can read: a member whose base permission
497is None, an [outside collaborator](/guides/access-and-roles/#outside-collaborators)
498or a visitor sees the public ones and those shared with them, without the
499workspace's people, deployments or settings.
500
501`g1t.sh/<workspace>?tab=projects` (or `repositories`, `packages`,
502`teams`, `people`, `members`, `insights` or `settings`) opens that page.
503
504### The Projects page
505
506The Projects page, `g1t.sh/<workspace>/-/projects`, is made for workspaces with hundreds of projects:
507
508- **Find a project** matches every word you type in a project's name, its
509 address or its description. Press <kbd>/</kbd> anywhere on the page to
510 start typing.
511- **Filters**: public or private; [what it is](/guides/projects/#what-a-project-is)
512 (apps, libraries, and tools, docs or other when the workspace has any); the language its
513 manifests say it is written in; only projects with
514 [Deployments](/guides/deployments/) on; and archived projects, which are
515 left out unless you ask for them. Each choice shows how many projects it
516 holds.
517- **Sort** by recently updated (its settings or its last push, whichever is
518 later), recently pushed, most active, or name. Most active counts each
519 push, issue or pull request opened or closed, review, comment and
520 deployment, and what happened a week ago counts half as much.
521- **List** or **grid**, 30 projects to a page.
522- The arrow keys (or <kbd>j</kbd> and <kbd>k</kbd>) move between projects,
523 and <kbd>Enter</kbd> opens one.
524
525Everything you choose is in the address, so a filtered list can be
526bookmarked or shared.
527
528## The rail, the sidebar and the page
529
530Signed in, g1t is always about one workspace: the one you are in. On a
531workspace's pages, and on a project in one of your workspaces, that is the
532workspace the page belongs to; anywhere else, even on public pages such as
533[Explore](https://g1t.sh/explore), someone's profile or another
534workspace's public project, it stays the one you chose last.
535
536Each page has three parts:
537
538| Part | Where | What it holds |
539| --- | --- | --- |
540| **The rail** | A narrow column of icons down the left edge | g1t's mark, which goes to [Home](/guides/home/); the built-in apps; the apps you pinned; **Apps**; and at its foot **People**, **Workspace** and your account. Hold the pointer over an icon for its name. |
541| **The sidebar** | Flush against the rail | The workspace and its switcher at the top, **Search or jump to**, then the lists of the app you are in, in named groups. Home and Apps have none. |
542| **The page** | A rounded panel, the rest of the window | Its header: the button that shows or hides the sidebar, where you are, **Search or jump to** (<kbd>Ctrl</kbd> <kbd>K</kbd>, or <kbd>⌘</kbd> <kbd>K</kbd> on a Mac) when the sidebar is hidden or has a search of its own, [your spend this month](/guides/spend/#in-the-top-bar), **Ask g1t**, the [notifications](/guides/notifications/) bell and **Create new**. Then the page itself. |
543
544### The rail
545
546The built-in apps are always in the rail, each an icon with what is
547unread on it:
548
549| App | Opens |
550| --- | --- |
551| **Home** | Where you're needed across the workspace, and what happened while you were away. See [Home](/guides/home/). |
552| **Chat** | Channels and messages. See [Chat](/guides/chat/). |
553| **Notifications** | Reviews, mentions, failures and what agents wait on. See [notifications](/guides/notifications/). |
554| **Agents** | The workspace's agents and their sessions. See [agents](/guides/agents/). |
555| **Code** | Projects, pull requests and checks. Not shown to a member without [Code access](/guides/agent-access/). |
556| **Artifacts** | Documents, decks and pages. See [artifacts](/guides/artifacts/). |
557| **People** | Everyone in the workspace (its people; agents are under Agents); its [teams](/guides/teams/), which agents can be on; the org chart; and, under **Membership**, **Members and invites**. See [people and teams](/guides/people-and-teams/). |
558| **Workspace** | Usage, billing, integrations, policies and settings. |
559
560The app you are in sits on a filled square. Your account is the
561avatar at the foot: your status, your profile and settings,
562[appearance](#appearance), the documentation, support, status, the
563keyboard's shortcuts, and signing out.
564
565### Appearance
566
567g1t comes in a dark theme and a light one. Until you choose, it follows
568your system's setting.
569
570| Choice | What you see |
571| --- | --- |
572| **Auto** | Follows your system's light or dark setting, and changes when it does. |
573| **Light** | A near-white page with white panels and a deeper lavender accent. |
574| **Dark** | g1t's very dark gray with the lavender accent. |
575
576To change it:
577
5781. Select your avatar at the foot of the rail. On a phone, open **More**,
579 then **You and help**.
5802. Under **Appearance**, select **Auto** (the screen icon), **Light** (the
581 sun) or **Dark** (the moon).
582
583The page changes at once. You can also choose under
584[Settings → Account](https://g1t.sh/settings/account), or press
585<kbd>Ctrl</kbd> <kbd>K</kbd> (<kbd>⌘</kbd> <kbd>K</kbd> on a Mac) and run
586**Use light theme**, **Use dark theme** or **Use auto theme**. Signed out,
587the same commands are in ⌘K, and the phone's menu has the switch.
588
589Your choice is kept in this browser, in a `g1t_theme` cookie, so every page
590is drawn in it from the start; another browser or device starts on Auto.
591Product screenshots on g1t.sh's home page, and the g1t mark on agents'
592avatars, stay dark in either theme.
593
594These docs and [status.g1t.sh](https://status.g1t.sh/) also follow your
595system's setting, each with its own switch for this browser: here, the
596**Auto**, **Light** and **Dark** menu at the end of the header (at the foot
597of the menu on a phone); on the status page, the three icons at the top.
598
599### Apps
600
601Apps are what the workspace added from the [Marketplace](/guides/marketplace/)
602that you can use: today, the integrations it connected, such as Sentry or
603GitHub, each opening its own page; installed extensions join them once
604extensions are published. An app you can't use shows **Request access**.
605The built-in apps' own pages are in their sidebars, not in Apps: Code's has
606**Projects**, **Security** and **Packages**; Agents' has **Templates**,
607**Context** and **Memory**; People's has **Everyone**, **Teams**, **Org chart** and
608**Members and invites**; Workspace's has **Usage**,
609**AI Gateway**, **Integrations** and the **Audit log**.
610
611A pinned app shows as its mark under the built-in ones, in the order you
612pinned them. To pin one:
613
6141. Select **Apps** near the foot of the rail, or open the Apps page at
615 `g1t.sh/<workspace>/-/apps`.
6162. Find the app, by name if you like.
6173. Select the pin on its tile. Select it again to unpin it.
618
619When the workspace hasn't added anything yet, the launcher and the Apps
620page say so and lead to the Marketplace. The launcher's **Marketplace**
621link always does.
622
623Your pins are yours alone and each workspace has its own. They are saved
624to your account, so your rail is the same on every browser and device you
625sign in on, in the order you pinned.
626
627### The sidebar
628
629The sidebar's top row names the workspace you are in. Select it to switch
630to another of your workspaces, make a new one, or open your profile or
631settings. The button beside it hides the sidebar, leaving the rail alone
632and the page wider, and the same button at the left of the page's header
633brings it back; <kbd>Ctrl</kbd> <kbd>B</kbd> (<kbd>⌘</kbd> <kbd>B</kbd> on
634a Mac) does both, except while you type. g1t remembers which you chose.
635When the sidebar is hidden, or the app has none, the page's header starts
636with the same switcher. Under the top row, **Search or jump to** opens the
637same palette as <kbd>Ctrl</kbd> <kbd>K</kbd>; in Chat and Artifacts, whose
638sidebars search their own lists, it stays in the page's header.
639
640Below it are the lists of the app you are in, each group under a small
641heading. Code's lists the workspace's
642[projects](#pinned-and-recent-projects), and drills into a project's own
643list when you open one, with **‹ All projects** at the top to go back. Its
644**Settings** opens one level further: **General**, **Deployments**,
645**Domains**, **Agents**, **Guardrails**, **Repository**, **Access**,
646**Branches and merging**, **Secrets and variables** and **Webhooks**, each
647for the roles that can use it. A link straight to any of these pages opens
648the sidebar already there.
649
650Workspace's sidebar lists the workspace's **Overview**; under **Money**,
651[**Spend**](/guides/spend/), **Usage**, **AI Gateway**,
652**Billing and plans**; for owners, **Runners** under **Compute**;
653**Integrations**, its security policies, the
654**Audit log** and **Settings**, which slides over to how the workspace is
655set up:
656
657| Settings | Who | |
658| --- | --- | --- |
659| **General** | Owners | The icon, the display name, a one-line description, the address (the slug), [who can create teams](/guides/teams/#who-can-create-teams), and [data residency](#data-residency). |
660| **Chat** | Members | What members may do in chat. Owners change it. |
661| **Repositories** | Members | The workspace's repositories. Owners also see **Recently deleted**, where a [deleted repository](/guides/managing-repositories/#restore-a-repository) can be restored, or purged, for 30 days. |
662| **Access tokens** | Members | The workspace's own tokens. Owners create and delete them. |
663| **Personal access tokens** | Owners | The workspace's rules for members' tokens, and approving them. |
664| [**Webhooks**](/guides/webhooks/) | Members | Where the workspace's events are sent. Owners add and change them. |
665| **Emoji** | Members | The workspace's own emoji. |
666| [**Secrets and variables**](/guides/secrets-and-variables/) | Members | What runs and deployments are given. Owners change them. |
667| **Actions** | Members | How workflows run in the workspace. |
668| **Runners** | Owners | The workspace's self-hosted machines, their groups and registration tokens. |
669
670**Members and invites** is for every member to see; owners invite, add and
671remove people there, set the
672[base permission](/guides/access-and-roles/#the-base-permission), and see
673the **Outside collaborators** tab. Each member's row also shows the
674[teams](/guides/teams/) they are in that you can see. To find someone, and
675what they work on, use the [People directory](/guides/people-and-teams/#the-directory).
676
677Below 1024px wide, the sidebar opens over the page from the left, from the
678header's button, and closes when you open a page.
679
680### Pinned and recent projects
681
682However many projects a workspace has, Code's sidebar lists a few:
683
684- **Pinned**: the projects you pinned, in your order, up to eight a
685 workspace. Pin one with **Pin** on its page, or the pin on its row of the
686 Projects page or its card on the Overview. Drag a pinned project to move
687 it, or hold <kbd>Alt</kbd> and press the up or down arrow.
688- **Recent**: the projects you opened last that you have not pinned, up to
689 five.
690- **All projects**, with how many there are, opens the Projects page.
691
692Pins and recent projects are yours: nobody else sees them, and each
693workspace has its own. ⌘K finds any project in the workspace, pinned or not.
694From the API, use
695[`GET /user/pinned_projects/{workspace}`](/reference/api/pinned-projects/list-pinned-projects/)
696and the other [pinned projects](/reference/api/pinned-projects/list-pinned-projects/)
697operations, or the `workspace` tool's `list_pinned_projects`,
698`pin_project`, `unpin_project` and `reorder_pinned_projects` actions
699over MCP.
700
701### On your phone
702
703On a screen narrower than a tablet, g1t keeps the same places and moves
704them within reach of your thumb:
705
706| | What it does |
707| --- | --- |
708| **The bar along the bottom** | **Home**, **Chat**, **Notifications**, **Agents** and **Code** (for members with Code access), each with what is unread, and **More**. It steps aside while the keyboard is up and inside a conversation. |
709| **More** | A panel above the bar with **All apps**, the [Marketplace](/guides/marketplace/), your pinned apps, **Artifacts**, **People**, **Workspace**, and **You and help**: your status, profile and settings, [appearance](#appearance), the documentation, support, status, the keyboard's shortcuts and signing out. |
710| **The sidebar button**, at the left of the page's header | Opens the sidebar of the app you are in from the left: the same lists and links as on a computer. Tap outside it, or open a page, and it closes. |
711| **The tab you are already on** | Tap it again to open that app's sidebar too. |
712| **The workspace's name** in the page's header | Switches workspace, or opens your profile or settings. |
713
714Inside a [project](/guides/projects/), its pages (**Overview**, **Code**,
715**Issues**, **Pull requests**, **Agents**, **Workflows**, **Deployments**,
716**Insights** and, for the roles that see them, **Security** and
717**Settings**) run in a row under its name that scrolls sideways, with the
718page you are on kept in view, so issues and pull requests are one tap
719away. Pages with more than one view, such as **Files**, **Commits** and
720**Branches**, show those as a second row of tabs.
721
722Menus stay inside the screen, dialogs rise from the bottom and sit on top
723of the keyboard while you type, and nothing scrolls the page sideways: a
724wide file, diff or table scrolls within its own box.
725
726### Signed out, and signing in
727
728Signing in, signing up, an invite link, the two-factor step, choosing a new
729password and making your first workspace each stand on their own: the g1t
730logo, the form, and links to the terms, privacy policy, docs, status and
731support at the foot. Someone who is not signed in reads public pages, such
732as Explore, a profile or a public project, under a plain header with
733**Explore**, **Docs**, **Sign in** and **Sign up**; a project's pages run in
734the row under its name.
735
736## Mission control
737
738Mission control is Code's **Overview**, at `g1t.sh/<workspace>/-/overview`.
739It shows where you are needed in the workspace's code, what its agents are
740doing, and what landed without you. Signed in, `g1t.sh` itself opens
741[Home](/guides/home/) in the workspace you are in.
742
743Under the greeting, one line sums up the week, such as *Agents landed 37
744of their 39 changes this week without you, and people landed 8 changes of
745their own*. An agent's change landed without you when g1t merged it, by
746auto-merge or from the [merge queue](/guides/merge-queue/), with no person
747pressing merge. People's changes are their merged pull requests and the
748commits they pushed straight to the default branch. A push is a person's
749by the account that signed in to make it, not by the name on its commits:
750pushes by g1t or a workflow job's token, and commits g1t wrote, are not
751counted as people's. **Review N that need you** jumps to the
752list, and **New issue** opens a new issue in the project you pick.
753
754| Across the top | What it counts |
755| --- | --- |
756| **Projects** | The workspace's projects, and how many were added this month. |
757| **Agents** | Agent runs going now, and the hours agents worked in the last 7 days. |
758| **Changes this week** | Pull requests merged in the last 7 days, and commits people pushed straight to the default branch, with the change from the 7 days before. The change is left out when g1t cannot read far enough back to count it. |
759| **Landed without you** | The share of agents' changes that g1t merged with no person pressing merge. People's own changes are not counted in it. |
760| **Need you** | What is waiting on you, and how many of those block work. |
761
762The list has three tabs. Each row opens to say more; the first is open.
763
764| Tab | What it lists |
765| --- | --- |
766| **Needs you** | Pull requests g1t stopped seeing through, reviews asked of you, changes ready for you to merge, failed checks, quiet agents, failed production builds, repository invitations and a usage limit that is close or reached. |
767| **Waiting on agents** | Pull requests in an agent's hands (making the change, checking, reviewing, revising, catching up or in the merge queue), and runs going now. |
768| **Landed today** | Pull requests merged today in your time zone, and whether a person merged them. |
769
770Each row in **Needs you** carries the reason it needs you:
771
772| Reason | Means |
773| --- | --- |
774| `BLOCKING` | Nothing moves until a person acts: a failed production build, a merge g1t could not make, or the usage limit. |
775| `ASKED FOR YOU` | A review or an invitation addressed to you by name. |
776| `CHECKS FAILING` | A required check still fails after the agent revised. |
777| `OUTSIDE GUARDRAILS` | A run reached a cost or time cap set in [Guardrails](/guides/guardrails/). |
778| `NEEDS REVIEW` | The repository wants a person's approval, or the review still asks for changes after the agent revised. |
779| `STALLED` | An agent stopped, or has reported nothing for 10 minutes. |
780| `READY TO MERGE` | Checks passed and it was approved; the repository lands changes only when a person merges them. |
781
782Opened, a row shows **The ask** (what g1t stopped with, and who the work
783was started for), **What the agent already knows** (its checks, the files
784and lines it changes, the test files it touches, how often the agent was
785sent back, and what its runs cost) and **Why this needs you**. From
786there, **Review and respond** opens it, and where it can be done without
787leaving the page you can approve the change, merge it or re-run its failed
788jobs. **By impact** puts the most urgent first; **Newest** sorts by time.
789
790On the right, **This week** charts the changes landed each day, split
791by who did the work: agents on their own, agents with a person merging,
792and people (their pull requests and direct pushes, merges left out), with what
793agents and sandboxes cost over the same days. **Activity** lists what
794moved across the workspace, agents marked apart from people. The page
795refreshes itself while agents are at work.
796
797## Workspace access tokens
798
799A workspace has access tokens of its own, for CI, integrations and agents
800that work for a team. There is no shared service account to create, pay
801for or lose the password to.
802
803| | Personal token | Workspace token |
804| --- | --- | --- |
805| Belongs to | You | The workspace |
806| Acts as | You | The workspace: its name is the author of what it does |
807| Can reach | All your workspaces, one of them, or none ([where a token reaches](/guides/authentication/#where-a-token-reaches)) | That workspace only: all of its repositories, or the ones chosen |
808| Can do | What its [permissions](/guides/authentication/#permissions) allow, never more than you can | What its permissions allow, with Write on the workspace's repositories (Admin with Repositories: admin); it cannot manage people, tokens or workspaces, and holds no account permissions |
809| Expires | 7 days to 1 year, or never where the workspaces it reaches allow | 7 days to 1 year, or never |
810| When its creator leaves | Stops working | Keeps working |
811| Created by | You, in [Settings → Access tokens](https://g1t.sh/settings/tokens) | An owner, under the workspace's **Settings → Access tokens** |
812
813They are the same kind of token and are sent the same way; see
814[access tokens](/guides/authentication/#access-tokens). With git, any
815username works; the token is the password. `GET /user` answers with
816`"kind": "workspace"` for one, and `"kind": "user"` for a personal token.
817
818Every member can see a workspace's tokens: the name, who created each,
819its permissions and repositories, when it was last used and when it
820expires. Only owners can create, change or delete them. An owner selects
821**New token** and fills in the same form as a personal token: a name, an
822expiration (No expiration shows a warning), its repositories (all, or the
823ones chosen) and its permissions, starting on the CI preset. Each token
824shows **Write** or **Admin**: give it **Repositories: admin** to let it
825manage webhooks, secrets, deploy keys and who has access, and teams as an
826owner would. Select a token to change its permissions or repositories, or
827to delete it.
828
829Which of your members' own personal tokens reach the workspace is set under
830**Settings → Personal access tokens**; see
831[a workspace's rules for tokens](/guides/authentication/#a-workspaces-rules-for-tokens).
832
833## Profiles
834
835Every person has a profile at `g1t.sh/u/<username>`, apart from the
836workspaces at `g1t.sh/<workspace>`. Author names on issues and pull
837requests link to it.
838
839**What it shows.** Your picture, name, username, pronouns, bio, location,
840website and when you joined; then your work in three tabs:
841
842- **Overview:** your contribution calendar, then pull requests merged,
843 open pull requests and issues opened, and your most recent activity.
844- **Pull requests** and **Issues:** everything you opened, and what g1t
845 opened for you, newest first,
846 with filters beside the list for state (open, closed, merged), type,
847 repository and sort order. Add `?tab=pulls&state=merged` and the like to
848 link to a filtered list.
849
850**The contribution calendar.** The last year as a square a day, a column a
851week, shaded more strongly the more you did that day, with the total
852above it ("128 contributions in the last year"). A contribution is a
853commit you pushed, an issue or pull request you opened (or g1t opened for
854you), and a review you gave. Days are counted in UTC. Hover over a square,
855or tap it, to see its day, its count and how many were commits ("5
856contributions on Oct 4, 2026, 3 of them commits"). On a narrow screen the
857calendar scrolls sideways inside its card, starting at today.
858
859Commits count like this:
860
861- **Pushed to the default branch, or to `gh-pages`.** Commits on other
862 branches count once they reach the default branch, which is usually a
863 pull request, and the pull request is counted already.
864- **Credited to whoever pushed,** on the day of the push, not to the
865 commits' authors. Pushes with an agent's, a workspace's or a workflow
866 job's token are not counted on anyone's calendar.
867- **The new commits along the branch's own line,** at most 50 a push. A
868 merge commit counts once. The first push of a branch counts one, so
869 importing a long history doesn't fill a single day.
870- **Only from the time this was added:** pushes before 9 October 2026 are
871 not counted.
872
873**Edit it** in [Settings → Profile](https://g1t.sh/settings/profile). Every
874field is optional. The bio takes up to 160 characters and is also what a
875link to your profile says. The website must be an `https://` address;
876`example.com` is saved as `https://example.com`. Your email address is
877never shown.
878
879**Time zone.** Pick the time zone you are in, by city or region (such as
880`America/Denver`), and the [card over your name](#the-card-over-a-name)
881shows your local time, so people can tell whether it is a good moment to
882ask you something. If your browser's time zone differs from the one
883saved, the field offers **Use my browser's time zone**. Choose **Not
884shown** to clear it.
885
886**Who sees what.** A profile is public, but the work and workspaces on it
887are filtered for whoever is looking:
888
889| On the profile | Shown to a visitor when |
890| --- | --- |
891| An issue or pull request, and its title | They can read its repository: it is public, or they are a member of its workspace |
892| The counts, and the contribution calendar | Only what they could see is counted |
893| A workspace | They are a member of it too, or you made a public project in it, whose page shows that already |
894
895Someone signed out sees your public work and the workspaces where you made
896a public project; nothing else, and their calendar counts only work in
897public repositories. The link preview for a profile uses only public work.
898
899**How it is laid out.** Signed out, a profile, Explore and Search are
900shown with g1t's public header (search, Explore, Docs, signing in) and the page
901at full width, with no workspace sidebar. Signed in, the rail stays, but
902no mode is lit and no mode's sidebar opens beside these pages: they are
903nobody's workspace, and the profile's own left column says whose it is.
904
905### The card over a name
906
907Hold the pointer over a person's name or picture anywhere on g1t, or move
908the keyboard focus to their name, and a card opens with their profile at a
909glance:
910
911| On the card | Shown when |
912| --- | --- |
913| Picture, name, username and pronouns | Always |
914| Bio and location | They filled them in |
915| Their local time, such as **3:42 PM local time** | They set a [time zone](#profiles) |
916| **Member of** | The same workspaces their profile shows you, at most three named |
917| **Committed to this repository in the past day**, **week** or **month** | You opened it inside a repository you can read, and their latest commit on its default branch is that recent |
918
919On a touch screen no card opens: a tap goes to the profile. `@g1t` has a
920card of its own, about putting g1t to work. `ghost`, which stands in for
921deleted accounts, has no card.
922
923### Commits and your account
924
925A commit shows as yours, with your username, picture, profile link and
926card, when its author address is one of your
927[confirmed addresses](/guides/authentication/#email-addresses) or your
928noreply address. This holds everywhere a commit appears: the Files page,
929history, a commit, blame, branches, tags, comparisons and the
930Contributors list, which counts every address of yours as one person.
931
932To have commits made on your own machine show as yours without publishing
933your address, commit with your noreply address:
934
9351. Open [Settings → Emails](https://g1t.sh/settings/emails) and copy your
936 noreply address. It looks like
937 `<8 characters of your account id>+<username>@users.noreply.g1t.sh`.
9382. Set it for every repository, or leave out `--global` for one:
939
940 ```sh
941 git config --global user.email "6c1d0efg+sam@users.noreply.g1t.sh"
942 ```
943
9443. Commit and push as usual. Commits you made before keep the address they
945 were made with; add that address to your account and confirm it to have
946 them show as yours.
947
948| A commit's address | Shown as |
949| --- | --- |
950| One of your confirmed addresses, or your noreply address | You |
951| An address added to an account but not confirmed | The name in the commit |
952| An address no account has | The name in the commit, with a plain picture, no link and no card |
953| A deleted account's noreply address, or any of its confirmed addresses during the 30 days it can be restored | `ghost` |
954| g1t's own (`g1t@users.noreply.g1t.sh`) | `g1t` |
955
956`Co-authored-by` trailers are matched the same way, and their pictures sit
957beside the author's. An address itself is never shown on g1t.