Skip to content
1,402 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server in Rust; a public index at the API root1//! REST: each route maps an HTTP request onto one operation.
2
3use serde_json::{Map, Value};
4
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb975use crate::about::AboutOp;
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R26use crate::artifacts::ArtifactsOp;
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca7use crate::deploy_keys::DeployKeysOp;
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb978use crate::deployments::DeploymentsOp;
Merge packages: roles, Actions access, source label, soft delete, API9use crate::packages::PackagesOp;
Merge branch 'worktree-agent-a3abfcce648e87dca'10use crate::protection::ProtectionOp;
API and MCP for a workspace's personal access token rules, members' tokens and approvals11use crate::token_policy::TokenOp;
API and MCP server in Rust; a public index at the API root12use crate::operations::Op;
Merge checks: statuses and check runs on every commit13use crate::checks::ChecksOp;
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge14use crate::rules::RulesOp;
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar15use crate::security::SecurityOp;
API and MCP server in Rust; a public index at the API root16
17pub struct Route {
18 pub method: &'static str,
19 /// Segments starting with `:` are parameters.
20 pub path: &'static str,
21 pub op: Op,
22 /// Query parameters the route reads, as `(name in the URL, input name)`.
23 pub query: &'static [(&'static str, &'static str)],
24}
25
26const fn route(
27 method: &'static str,
28 path: &'static str,
29 op: Op,
30 query: &'static [(&'static str, &'static str)],
31) -> Route {
32 Route {
33 method,
34 path,
35 op,
36 query,
37 }
38}
39
40pub const ROUTES: &[Route] = &[
Agents as a team: lifecycle, merge queue, billing and a new shell41 route("GET", "/user", Op::Whoami, &[]),
42 route("POST", "/workspaces", Op::CreateWorkspace, &[]),
Merge branch 'worktree-agent-ad7c6d88d93adc817'43 route("GET", "/workspaces/:workspace", Op::GetWorkspace, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look44 route("DELETE", "/workspaces/:workspace", Op::DeleteWorkspace, &[]),
45 route("GET", "/user/emails", Op::ListEmails, &[]),
46 route("POST", "/user/emails", Op::AddEmail, &[]),
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)47 route("POST", "/user/emails/confirm", Op::ConfirmEmail, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look48 route("DELETE", "/user/emails/:email", Op::RemoveEmail, &[]),
49 route("PATCH", "/user/email-settings", Op::UpdateEmailSettings, &[]),
50 route("GET", "/user/invites", Op::ListInvites, &[]),
51 route("POST", "/user/invites", Op::CreateInvite, &[]),
52 route("DELETE", "/user/invites/:id", Op::RevokeInvite, &[]),
Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040)53 // Invitations to workspaces waiting for your answer.
54 route("GET", "/user/invitations", Op::ListInvitations, &[]),
55 route("POST", "/user/invitations/:id/accept", Op::AcceptInvitation, &[]),
56 route("POST", "/user/invitations/:id/decline", Op::DeclineInvitation, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look57 route("GET", "/workspaces/:workspace/invitations", Op::ListWorkspaceInvites, &[]),
API and MCP for a workspace's personal access token rules, members' tokens and approvals58 // A workspace's rules for personal access tokens, and its members' tokens.
59 route("GET", "/workspaces/:workspace/personal-access-token-policy", Op::Tokens(TokenOp::GetTokenPolicy), &[]),
60 route("PATCH", "/workspaces/:workspace/personal-access-token-policy", Op::Tokens(TokenOp::SetTokenPolicy), &[]),
61 route("GET", "/workspaces/:workspace/personal-access-tokens", Op::Tokens(TokenOp::ListMemberTokens), &[("kind", "kind")]),
62 route("POST", "/workspaces/:workspace/personal-access-tokens/:id", Op::Tokens(TokenOp::RevokeMemberToken), &[]),
63 route("GET", "/workspaces/:workspace/personal-access-token-requests", Op::Tokens(TokenOp::ListTokenRequests), &[]),
64 route("POST", "/workspaces/:workspace/personal-access-token-requests/:id", Op::Tokens(TokenOp::ReviewTokenRequest), &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look65 route("POST", "/workspaces/:workspace/invitations", Op::InviteMember, &[]),
66 route("DELETE", "/workspaces/:workspace/invitations/:id", Op::RevokeWorkspaceInvite, &[]),
67 // Who has access. GitHub's addresses, but for adding someone, which
68 // takes an email address as well as a username.
69 route("GET", "/repos/:owner/:name/collaborators", Op::ListCollaborators, &[]),
70 route("POST", "/repos/:owner/:name/collaborators", Op::AddCollaborator, &[]),
71 route("PATCH", "/repos/:owner/:name/collaborators/:username", Op::UpdateCollaborator, &[]),
72 route("DELETE", "/repos/:owner/:name/collaborators/:username", Op::RemoveCollaborator, &[]),
73 route(
74 "GET",
75 "/repos/:owner/:name/collaborators/:username/permission",
76 Op::GetCollaboratorPermission,
77 &[],
78 ),
79 route("GET", "/repos/:owner/:name/invitations", Op::ListRepoInvitations, &[]),
80 route("DELETE", "/repos/:owner/:name/invitations/:id", Op::RevokeRepoInvitation, &[]),
81 route("GET", "/user/repository_invitations", Op::ListMyRepoInvitations, &[]),
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca82 // Deploy keys, at GitHub's addresses.
83 route("GET", "/repos/:owner/:name/keys", Op::DeployKeys(DeployKeysOp::ListDeployKeys), &[]),
84 route("POST", "/repos/:owner/:name/keys", Op::DeployKeys(DeployKeysOp::CreateDeployKey), &[]),
85 route("GET", "/repos/:owner/:name/keys/:id", Op::DeployKeys(DeployKeysOp::GetDeployKey), &[]),
86 route("DELETE", "/repos/:owner/:name/keys/:id", Op::DeployKeys(DeployKeysOp::DeleteDeployKey), &[]),
API: notifications over REST and MCP, with notifications scopes87 // Your notifications: threads, marking them, and what you subscribe
88 // to and watch. GitHub's addresses, with g1t's saved and snoozed.
89 route("GET", "/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
90 route("PUT", "/notifications", Op::MarkNotificationsRead, &[]),
91 route("GET", "/notifications/threads/:id", Op::GetNotificationThread, &[]),
92 route("PATCH", "/notifications/threads/:id", Op::MarkThreadRead, &[]),
93 route("DELETE", "/notifications/threads/:id", Op::MarkThreadDone, &[]),
94 route("PUT", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
95 route("DELETE", "/notifications/threads/:id/saved", Op::SaveThread, &[]),
96 route("PUT", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
97 route("DELETE", "/notifications/threads/:id/snooze", Op::SnoozeThread, &[]),
98 route("GET", "/notifications/threads/:id/subscription", Op::GetThreadSubscription, &[]),
99 route("PUT", "/notifications/threads/:id/subscription", Op::SetThreadSubscription, &[]),
100 route("DELETE", "/notifications/threads/:id/subscription", Op::DeleteThreadSubscription, &[]),
101 route("GET", "/repos/:owner/:name/notifications", Op::ListNotifications, &[("all", "all"), ("participating", "participating"), ("view", "view"), ("reason", "reason"), ("severity", "severity"), ("since", "since"), ("before", "before"), ("cursor", "cursor"), ("per_page", "per_page")]),
102 route("PUT", "/repos/:owner/:name/notifications", Op::MarkNotificationsRead, &[]),
103 route("GET", "/repos/:owner/:name/subscription", Op::GetRepoSubscription, &[]),
104 route("PUT", "/repos/:owner/:name/subscription", Op::SetRepoSubscription, &[]),
105 route("DELETE", "/repos/:owner/:name/subscription", Op::DeleteRepoSubscription, &[]),
106 route("GET", "/repos/:owner/:name/issues/:number/subscription", Op::GetThreadSubscription, &[]),
107 route("PUT", "/repos/:owner/:name/issues/:number/subscription", Op::SetThreadSubscription, &[]),
108 route("DELETE", "/repos/:owner/:name/issues/:number/subscription", Op::DeleteThreadSubscription, &[]),
109 route("GET", "/user/subscriptions", Op::ListWatchedRepos, &[]),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97110 // Stars: yours, and who starred a repository.
111 route("GET", "/user/starred", Op::About(AboutOp::ListStarred), &[]),
112 route("GET", "/user/starred/:owner/:name", Op::About(AboutOp::CheckStarred), &[]),
113 route("PUT", "/user/starred/:owner/:name", Op::About(AboutOp::Star), &[]),
114 route("DELETE", "/user/starred/:owner/:name", Op::About(AboutOp::Unstar), &[]),
115 route("GET", "/repos/:owner/:name/stargazers", Op::About(AboutOp::ListStargazers), &[("page", "page")]),
116 // What the default branch says about a repository, kept by commit.
117 route("GET", "/repos/:owner/:name/languages", Op::About(AboutOp::GetLanguages), &[]),
118 route("GET", "/repos/:owner/:name/contributors", Op::About(AboutOp::ListContributors), &[]),
119 route("GET", "/repos/:owner/:name/license", Op::About(AboutOp::GetLicense), &[]),
120 // Releases: `latest` and `tags/…` before an id.
121 route("GET", "/repos/:owner/:name/releases", Op::About(AboutOp::ListReleases), &[]),
122 route("POST", "/repos/:owner/:name/releases", Op::About(AboutOp::CreateRelease), &[]),
123 route("GET", "/repos/:owner/:name/releases/latest", Op::About(AboutOp::GetLatestRelease), &[]),
124 route("GET", "/repos/:owner/:name/releases/tags/:tag", Op::About(AboutOp::GetReleaseByTag), &[]),
125 route("GET", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::GetRelease), &[]),
126 route("PATCH", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::UpdateRelease), &[]),
127 route("DELETE", "/repos/:owner/:name/releases/:id", Op::About(AboutOp::DeleteRelease), &[]),
API: pinned projects over REST and MCP128 // Your pinned projects in a workspace, in your order.
129 route("GET", "/user/pinned_projects/:workspace", Op::ListPinnedProjects, &[]),
130 route("PUT", "/user/pinned_projects/:workspace", Op::ReorderPinnedProjects, &[]),
131 route("PUT", "/user/pinned_projects/:workspace/:project", Op::PinProject, &[]),
132 route("DELETE", "/user/pinned_projects/:workspace/:project", Op::UnpinProject, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look133 route("PATCH", "/user/repository_invitations/:id", Op::AcceptRepoInvitation, &[]),
134 route("DELETE", "/user/repository_invitations/:id", Op::DeclineRepoInvitation, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily135 route("PATCH", "/workspaces/:workspace", Op::UpdateWorkspace, &[]),
Merge main (membership, two-factor, GitHub repo roles) into tokens136 // Members and owners: GitHub's organization members, by username.
137 route("GET", "/workspaces/:workspace/members", Op::ListMembers, &[]),
138 route("PATCH", "/workspaces/:workspace/members/:username", Op::UpdateMember, &[]),
139 route("DELETE", "/workspaces/:workspace/members/:username", Op::RemoveMember, &[]),
140 route("POST", "/workspaces/:workspace/transfer_ownership", Op::TransferOwnership, &[]),
141 route("DELETE", "/user/memberships/:workspace", Op::LeaveWorkspace, &[]),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97142 // A workspace's projects: what each is, where it runs, its links.
143 route("GET", "/workspaces/:workspace/projects", Op::ListProjects, &[]),
144 route("GET", "/workspaces/:workspace/projects/:project", Op::GetProject, &[]),
145 route("PATCH", "/workspaces/:workspace/projects/:project", Op::UpdateProject, &[]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily146 route("PUT", "/workspaces/:workspace/base_permission", Op::SetBasePermission, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look147 route(
148 "GET",
149 "/workspaces/:workspace/outside_collaborators",
150 Op::ListOutsideCollaborators,
151 &[],
152 ),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar153 // Teams: a workspace's groups of members, with roles on repositories.
154 route("GET", "/workspaces/:workspace/teams", Op::ListTeams, &[("q", "query")]),
155 route("POST", "/workspaces/:workspace/teams", Op::CreateTeam, &[]),
156 route("GET", "/workspaces/:workspace/teams/:team", Op::GetTeam, &[]),
157 route("PATCH", "/workspaces/:workspace/teams/:team", Op::UpdateTeam, &[]),
158 route("DELETE", "/workspaces/:workspace/teams/:team", Op::DeleteTeam, &[]),
159 route(
160 "GET",
161 "/workspaces/:workspace/teams/:team/members",
162 Op::ListTeamMembers,
163 &[("include_child_teams", "include_child_teams")],
164 ),
165 route("PUT", "/workspaces/:workspace/teams/:team/members/:username", Op::SetTeamMember, &[]),
166 route("DELETE", "/workspaces/:workspace/teams/:team/members/:username", Op::RemoveTeamMember, &[]),
167 route("GET", "/workspaces/:workspace/teams/:team/teams", Op::ListChildTeams, &[]),
168 route("GET", "/workspaces/:workspace/teams/:team/repos", Op::ListTeamRepos, &[]),
169 route("PUT", "/workspaces/:workspace/teams/:team/repos/:repo", Op::SetTeamRepo, &[]),
170 route("DELETE", "/workspaces/:workspace/teams/:team/repos/:repo", Op::RemoveTeamRepo, &[]),
171 route(
172 "PUT",
173 "/workspaces/:workspace/teams/:team/review_assignment",
174 Op::SetTeamReviewAssignment,
175 &[],
176 ),
177 route("GET", "/workspaces/:workspace/members/:username/teams", Op::ListUserTeams, &[]),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit178 // A workspace's billing: usage, budget, AI credit and invoices.
179 route(
180 "GET",
181 "/workspaces/:workspace/usage",
182 Op::GetUsage,
183 &[("from", "from"), ("until", "until"), ("products", "products"), ("projects", "projects"), ("group_by", "group_by")],
184 ),
185 route("GET", "/workspaces/:workspace/budget", Op::GetBudget, &[]),
186 route("PUT", "/workspaces/:workspace/budget", Op::SetBudget, &[]),
187 route("GET", "/workspaces/:workspace/ai_credit", Op::GetAiCredit, &[]),
188 route("POST", "/workspaces/:workspace/ai_credit/checkout", Op::BuyAiCredit, &[]),
189 route("GET", "/workspaces/:workspace/invoices", Op::ListInvoices, &[]),
190 route("GET", "/workspaces/:workspace/billing_details", Op::GetBillingDetails, &[]),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens191 // The AI Gateway's log of a workspace's requests.
192 route("GET", "/workspaces/:workspace/gateway/requests", Op::ListGatewayRequests, &[("limit", "limit"), ("before", "before")]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar193 // Code owners: the CODEOWNERS file, checked.
194 route("GET", "/repos/:owner/:name/codeowners/errors", Op::GetCodeownersErrors, &[("ref", "ref")]),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily195 // Security alerts: secrets and vulnerable dependencies.
196 route(
197 "GET",
198 "/repos/:owner/:name/security/alerts",
199 Op::ListSecurityAlerts,
200 &[("state", "state"), ("kind", "kind")],
201 ),
202 route("POST", "/repos/:owner/:name/security/alerts/:id/dismiss", Op::DismissSecurityAlert, &[]),
203 route("POST", "/repos/:owner/:name/security/alerts/:id/reopen", Op::ReopenSecurityAlert, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar204 // The security suite: secret scanning, code scanning, vulnerability
205 // alerts and the supply chain, at the common addresses.
206 route("GET", "/repos/:owner/:name/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
207 route("GET", "/workspaces/:workspace/secret-scanning/alerts", Op::Security(SecurityOp::ListSecretAlerts), &[("state", "state"), ("secret_type", "secret_type"), ("validity", "validity"), ("bypassed", "bypassed")]),
208 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::GetSecretAlert), &[]),
209 route("PATCH", "/repos/:owner/:name/secret-scanning/alerts/:id", Op::Security(SecurityOp::UpdateSecretAlert), &[]),
210 route("GET", "/repos/:owner/:name/secret-scanning/alerts/:id/locations", Op::Security(SecurityOp::ListSecretLocations), &[]),
211 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/bypass", Op::Security(SecurityOp::BypassPushProtection), &[]),
212 route("POST", "/repos/:owner/:name/secret-scanning/alerts/:id/validity", Op::Security(SecurityOp::CheckSecretValidity), &[]),
213 route("GET", "/workspaces/:workspace/secret-scanning/bypass-requests", Op::Security(SecurityOp::ListBypassRequests), &[("state", "state"), ("repo", "repo")]),
214 route("PATCH", "/workspaces/:workspace/secret-scanning/bypass-requests/:id", Op::Security(SecurityOp::ReviewBypassRequest), &[]),
215 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
216 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns/dry-run", Op::Security(SecurityOp::DryRunCustomPattern), &[]),
217 route("GET", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
218 route("GET", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::ListCustomPatterns), &[]),
219 route("POST", "/repos/:owner/:name/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
220 route("POST", "/workspaces/:workspace/secret-scanning/custom-patterns", Op::Security(SecurityOp::CreateCustomPattern), &[]),
221 route("PATCH", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
222 route("PATCH", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::UpdateCustomPattern), &[]),
223 route("DELETE", "/repos/:owner/:name/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
224 route("DELETE", "/workspaces/:workspace/secret-scanning/custom-patterns/:id", Op::Security(SecurityOp::DeleteCustomPattern), &[]),
225 route("GET", "/repos/:owner/:name/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
226 route("GET", "/workspaces/:workspace/code-scanning/alerts", Op::Security(SecurityOp::ListCodeAlerts), &[("state", "state"), ("severity", "severity"), ("tool", "tool"), ("rule_id", "rule_id")]),
227 route("GET", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::GetCodeAlert), &[]),
228 route("PATCH", "/repos/:owner/:name/code-scanning/alerts/:number", Op::Security(SecurityOp::UpdateCodeAlert), &[]),
229 route("GET", "/repos/:owner/:name/code-scanning/analyses", Op::Security(SecurityOp::ListAnalyses), &[]),
230 route("POST", "/repos/:owner/:name/code-scanning/sarifs", Op::Security(SecurityOp::UploadSarif), &[]),
231 route("GET", "/repos/:owner/:name/code-scanning/sarifs/:id", Op::Security(SecurityOp::GetSarifUpload), &[]),
232 route("GET", "/repos/:owner/:name/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
233 route("GET", "/workspaces/:workspace/vulnerability-alerts", Op::Security(SecurityOp::ListVulnerabilityAlerts), &[("state", "state"), ("severity", "severity"), ("ecosystem", "ecosystem"), ("package", "package")]),
234 route("GET", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::GetVulnerabilityAlert), &[]),
235 route("PATCH", "/repos/:owner/:name/vulnerability-alerts/:id", Op::Security(SecurityOp::UpdateVulnerabilityAlert), &[]),
236 route("POST", "/repos/:owner/:name/security/alerts/:id/fix", Op::Security(SecurityOp::FixAlert), &[]),
237 route("GET", "/repos/:owner/:name/dependency-graph", Op::Security(SecurityOp::GetDependencyGraph), &[]),
238 route("GET", "/repos/:owner/:name/dependency-graph/sbom", Op::Security(SecurityOp::GetSbom), &[]),
239 route("GET", "/repos/:owner/:name/dependency-graph/compare/:basehead", Op::Security(SecurityOp::CompareDependencies), &[]),
240 route("GET", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::GetSettings), &[]),
241 route("PATCH", "/repos/:owner/:name/security/settings", Op::Security(SecurityOp::UpdateSettings), &[]),
242 route("GET", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::GetWorkspaceSettings), &[]),
243 route("PATCH", "/workspaces/:workspace/security/settings", Op::Security(SecurityOp::UpdateWorkspaceSettings), &[]),
244 route("GET", "/workspaces/:workspace/security/overview", Op::Security(SecurityOp::GetOverview), &[("days", "days")]),
Agents as a team: lifecycle, merge queue, billing and a new shell245 route("GET", "/repos", Op::ListRepos, &[("q", "query")]),
Search across all of g1t, Explore, and a command palette246 route(
247 "GET",
248 "/search",
249 Op::Search,
250 &[("q", "query"), ("type", "type"), ("page", "page"), ("per_page", "per_page")],
251 ),
Agents as a team: lifecycle, merge queue, billing and a new shell252 route("POST", "/repos", Op::CreateRepo, &[]),
253 route("GET", "/repos/:owner/:name", Op::GetRepo, &[]),
254 route("PATCH", "/repos/:owner/:name", Op::UpdateRepo, &[]),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look255 route("POST", "/repos/:owner/:name/transfer", Op::TransferRepo, &[]),
256 route("DELETE", "/repos/:owner/:name", Op::DeleteRepo, &[]),
257 route(
258 "GET",
259 "/workspaces/:workspace/repos/deleted",
260 Op::ListDeletedRepos,
261 &[],
262 ),
263 route("POST", "/repos/:owner/:name/restore", Op::RestoreRepo, &[]),
264 route("POST", "/repos/:owner/:name/purge", Op::PurgeRepo, &[]),
265 route("POST", "/repos/:owner/:name/rename", Op::RenameRepo, &[]),
266 route("POST", "/repos/:owner/:name/archive", Op::ArchiveRepo, &[]),
267 route("POST", "/repos/:owner/:name/unarchive", Op::UnarchiveRepo, &[]),
268 route(
269 "POST",
270 "/repos/:owner/:name/visibility",
271 Op::SetRepoVisibility,
272 &[],
273 ),
274 route(
275 "POST",
276 "/repos/:owner/:name/branches/:branch/rename",
277 Op::RenameBranch,
278 &[],
279 ),
Agents as a team: lifecycle, merge queue, billing and a new shell280 route(
281 "GET",
282 "/repos/:owner/:name/settings",
283 Op::GetRepoSettings,
284 &[],
285 ),
286 route(
287 "PATCH",
288 "/repos/:owner/:name/settings",
289 Op::UpdateRepoSettings,
290 &[],
291 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents292 route("GET", "/repos/:owner/:name/check-names", Op::ListCheckNames, &[]),
Merge checks: statuses and check runs on every commit293 // Checks: GitHub's addresses for statuses, check runs and check suites.
294 route("POST", "/repos/:owner/:name/statuses/:sha", Op::Checks(ChecksOp::CreateCommitStatus), &[]),
295 route("GET", "/repos/:owner/:name/commits/:ref/statuses", Op::Checks(ChecksOp::ListCommitStatuses), &[]),
296 route("GET", "/repos/:owner/:name/commits/:ref/status", Op::Checks(ChecksOp::GetCombinedStatus), &[]),
297 route(
298 "GET",
299 "/repos/:owner/:name/commits/:ref/check-runs",
300 Op::Checks(ChecksOp::ListCheckRunsForRef),
301 &[("check_name", "check_name"), ("status", "status"), ("app", "app"), ("filter", "filter")],
302 ),
303 route(
304 "GET",
305 "/repos/:owner/:name/commits/:ref/check-suites",
306 Op::Checks(ChecksOp::ListCheckSuitesForRef),
307 &[("app", "app"), ("check_name", "check_name")],
308 ),
309 route("POST", "/repos/:owner/:name/check-runs", Op::Checks(ChecksOp::CreateCheckRun), &[]),
310 route("GET", "/repos/:owner/:name/check-runs/:id", Op::Checks(ChecksOp::GetCheckRun), &[]),
311 route("PATCH", "/repos/:owner/:name/check-runs/:id", Op::Checks(ChecksOp::UpdateCheckRun), &[]),
312 route("GET", "/repos/:owner/:name/check-runs/:id/annotations", Op::Checks(ChecksOp::ListCheckRunAnnotations), &[]),
313 route("POST", "/repos/:owner/:name/check-runs/:id/rerequest", Op::Checks(ChecksOp::RerequestCheckRun), &[]),
314 route("GET", "/repos/:owner/:name/check-suites/:id", Op::Checks(ChecksOp::GetCheckSuite), &[]),
315 route("POST", "/repos/:owner/:name/check-suites/:id/rerequest", Op::Checks(ChecksOp::RerequestCheckSuite), &[]),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge316 // Rulesets: a repository's, a workspace's, the rules of one branch,
317 // and how they judged pushes and merges.
318 route("GET", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::ListRepoRulesets), &[("include_parents", "include_parents")]),
319 route("POST", "/repos/:owner/:name/rulesets", Op::Rules(RulesOp::CreateRepoRuleset), &[]),
320 route("GET", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::GetRepoRuleset), &[]),
321 route("PUT", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::UpdateRepoRuleset), &[]),
322 route("DELETE", "/repos/:owner/:name/rulesets/:id", Op::Rules(RulesOp::DeleteRepoRuleset), &[]),
323 route("GET", "/repos/:owner/:name/rules/branches/:branch", Op::Rules(RulesOp::GetBranchRules), &[("target", "target")]),
324 route(
325 "GET",
326 "/repos/:owner/:name/rules/evaluations",
327 Op::Rules(RulesOp::ListRuleEvaluations),
328 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
329 ),
330 route("GET", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::ListWorkspaceRulesets), &[]),
331 route("POST", "/workspaces/:workspace/rulesets", Op::Rules(RulesOp::CreateWorkspaceRuleset), &[]),
332 route("GET", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::GetWorkspaceRuleset), &[]),
333 route("PUT", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::UpdateWorkspaceRuleset), &[]),
334 route("DELETE", "/workspaces/:workspace/rulesets/:id", Op::Rules(RulesOp::DeleteWorkspaceRuleset), &[]),
335 route(
336 "GET",
337 "/workspaces/:workspace/rules/evaluations",
338 Op::Rules(RulesOp::ListWorkspaceRuleEvaluations),
339 &[("ruleset_id", "ruleset_id"), ("verdict", "verdict"), ("problems_only", "problems_only"), ("before", "before"), ("limit", "limit")],
340 ),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97341 // Deployments wherever they run, their statuses, and environments.
342 route(
343 "GET",
344 "/repos/:owner/:name/deployments",
345 Op::Deployments(DeploymentsOp::ListDeployments),
346 &[("environment", "environment"), ("ref", "ref"), ("sha", "sha"), ("task", "task"), ("state", "state"), ("source", "source"), ("creator", "creator"), ("page", "page"), ("per_page", "per_page")],
347 ),
348 route("POST", "/repos/:owner/:name/deployments", Op::Deployments(DeploymentsOp::CreateDeployment), &[]),
349 route("GET", "/repos/:owner/:name/deployments/:id", Op::Deployments(DeploymentsOp::GetDeployment), &[]),
350 route("GET", "/repos/:owner/:name/deployments/:id/statuses", Op::Deployments(DeploymentsOp::ListDeploymentStatuses), &[]),
351 route("POST", "/repos/:owner/:name/deployments/:id/statuses", Op::Deployments(DeploymentsOp::CreateDeploymentStatus), &[]),
352 route("GET", "/repos/:owner/:name/environments", Op::Deployments(DeploymentsOp::ListEnvironments), &[]),
353 route("GET", "/repos/:owner/:name/environments/:environment", Op::Deployments(DeploymentsOp::GetEnvironment), &[]),
Merge branch 'worktree-agent-a3abfcce648e87dca'354 // Environments' protection rules, and the runs they hold.
355 route("PUT", "/repos/:owner/:name/environments/:environment", Op::Protection(ProtectionOp::UpdateEnvironment), &[]),
356 route("DELETE", "/repos/:owner/:name/environments/:environment", Op::Protection(ProtectionOp::DeleteEnvironment), &[]),
357 route(
358 "GET",
359 "/repos/:owner/:name/actions/runs/:id/pending_deployments",
360 Op::Protection(ProtectionOp::GetPendingDeployments),
361 &[],
362 ),
363 route(
364 "POST",
365 "/repos/:owner/:name/actions/runs/:id/pending_deployments",
366 Op::Protection(ProtectionOp::ReviewPendingDeployments),
367 &[],
368 ),
369 route("POST", "/repos/:owner/:name/actions/runs/:id/approve", Op::Protection(ProtectionOp::ApproveWorkflowRun), &[]),
370 route("GET", "/repos/:owner/:name/actions/permissions/workflow", Op::Protection(ProtectionOp::GetWorkflowPermissions), &[]),
371 route("PUT", "/repos/:owner/:name/actions/permissions/workflow", Op::Protection(ProtectionOp::SetWorkflowPermissions), &[]),
372 route(
373 "GET",
374 "/repos/:owner/:name/actions/permissions/fork-pr-contributor-approval",
375 Op::Protection(ProtectionOp::GetForkPrApproval),
376 &[],
377 ),
378 route(
379 "PUT",
380 "/repos/:owner/:name/actions/permissions/fork-pr-contributor-approval",
381 Op::Protection(ProtectionOp::SetForkPrApproval),
382 &[],
383 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts384 route("GET", "/repos/:owner/:name/actions/permissions/access", Op::Protection(ProtectionOp::GetActionsAccess), &[]),
385 route("PUT", "/repos/:owner/:name/actions/permissions/access", Op::Protection(ProtectionOp::SetActionsAccess), &[]),
Merge branch 'worktree-agent-a3abfcce648e87dca'386 route("POST", "/repos/:owner/:name/dispatches", Op::Protection(ProtectionOp::CreateRepositoryDispatch), &[]),
387 route(
388 "GET",
389 "/workspaces/:workspace/actions/permissions/workflow",
390 Op::Protection(ProtectionOp::GetWorkspaceWorkflowPermissions),
391 &[],
392 ),
393 route(
394 "PUT",
395 "/workspaces/:workspace/actions/permissions/workflow",
396 Op::Protection(ProtectionOp::SetWorkspaceWorkflowPermissions),
397 &[],
398 ),
Agents as a team: lifecycle, merge queue, billing and a new shell399 route("GET", "/repos/:owner/:name/queue", Op::GetMergeQueue, &[]),
API and MCP server in Rust; a public index at the API root400 route(
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request401 "POST",
402 "/repos/:owner/:name/pulls/:number/messages",
403 Op::MessageAgent,
404 &[],
405 ),
406 route(
407 "POST",
408 "/repos/:owner/:name/pulls/:number/messages/take",
409 Op::TakeMessages,
410 &[],
411 ),
412 route(
Docs worth reading, and kept that way413 "POST",
414 "/repos/:owner/:name/messages/:id/answer",
415 Op::AnswerMessage,
416 &[],
417 ),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains418 route("POST", "/repos/:owner/:name/memory", Op::Remember, &[]),
419 route(
420 "GET",
421 "/repos/:owner/:name/memory",
422 Op::Recall,
423 &[("q", "query"), ("limit", "limit")],
424 ),
Docs worth reading, and kept that way425 route(
API and MCP server in Rust; a public index at the API root426 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell427 "/repos/:owner/:name/events",
API and MCP server in Rust; a public index at the API root428 Op::ListEvents,
429 &[("before", "before")],
430 ),
Agents as a team: lifecycle, merge queue, billing and a new shell431 route("GET", "/repos/:owner/:name/labels", Op::ListLabels, &[]),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar432 route("POST", "/repos/:owner/:name/labels", Op::CreateLabel, &[]),
433 route("POST", "/repos/:owner/:name/labels/defaults", Op::AddDefaultLabels, &[]),
434 route("PATCH", "/repos/:owner/:name/labels/:label", Op::UpdateLabel, &[]),
435 route("DELETE", "/repos/:owner/:name/labels/:label", Op::DeleteLabel, &[]),
436 route("GET", "/repos/:owner/:name/issues/:number/labels", Op::ListIssueLabels, &[]),
437 route("POST", "/repos/:owner/:name/issues/:number/labels", Op::AddIssueLabels, &[]),
438 route("PUT", "/repos/:owner/:name/issues/:number/labels", Op::SetIssueLabels, &[]),
439 route("DELETE", "/repos/:owner/:name/issues/:number/labels", Op::RemoveIssueLabels, &[]),
440 route("DELETE", "/repos/:owner/:name/issues/:number/labels/:label", Op::RemoveIssueLabels, &[]),
441 route("GET", "/repos/:owner/:name/milestones", Op::ListMilestones, &[("state", "state")]),
442 route("POST", "/repos/:owner/:name/milestones", Op::CreateMilestone, &[]),
443 route("GET", "/repos/:owner/:name/milestones/:milestone", Op::GetMilestone, &[]),
444 route("PATCH", "/repos/:owner/:name/milestones/:milestone", Op::UpdateMilestone, &[]),
445 route("DELETE", "/repos/:owner/:name/milestones/:milestone", Op::DeleteMilestone, &[]),
API and MCP server in Rust; a public index at the API root446 route(
447 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell448 "/repos/:owner/:name/issues",
API and MCP server in Rust; a public index at the API root449 Op::ListIssues,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar450 &[("state", "state"), ("label", "label"), ("milestone", "milestone")],
API and MCP server in Rust; a public index at the API root451 ),
Agents as a team: lifecycle, merge queue, billing and a new shell452 route("POST", "/repos/:owner/:name/issues", Op::CreateIssue, &[]),
API and MCP server in Rust; a public index at the API root453 route(
454 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell455 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root456 Op::GetIssue,
457 &[],
458 ),
459 route(
460 "PATCH",
Agents as a team: lifecycle, merge queue, billing and a new shell461 "/repos/:owner/:name/issues/:number",
API and MCP server in Rust; a public index at the API root462 Op::UpdateIssue,
463 &[],
464 ),
465 route(
466 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell467 "/repos/:owner/:name/issues/:number/close",
API and MCP server in Rust; a public index at the API root468 Op::CloseIssue,
469 &[],
470 ),
471 route(
472 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell473 "/repos/:owner/:name/issues/:number/reopen",
API and MCP server in Rust; a public index at the API root474 Op::ReopenIssue,
475 &[],
476 ),
477 route(
478 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell479 "/repos/:owner/:name/issues/:number/assign",
480 Op::AssignIssue,
481 &[],
482 ),
Integrations: your own model provider, alerts that open issues, tickets agents read483 route(
484 "POST",
485 "/repos/:owner/:name/issues/import",
486 Op::ImportIssue,
487 &[],
488 ),
489 route(
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step490 "POST",
491 "/repos/:owner/:name/issues/delegate",
492 Op::Delegate,
493 &[],
494 ),
495 route(
Integrations: your own model provider, alerts that open issues, tickets agents read496 "GET",
497 "/repos/:owner/:name/context",
498 Op::GetContext,
499 &[("reference", "reference")],
500 ),
501 route(
502 "GET",
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API503 "/workspaces/:workspace/context/search",
504 Op::SearchContext,
505 &[("q", "query"), ("project", "project"), ("kinds", "kinds"), ("limit", "limit")],
506 ),
507 route(
508 "GET",
509 "/workspaces/:workspace/context/:kind/:id",
510 Op::GetEntity,
511 &[],
512 ),
513 route(
514 "GET",
Integrations: your own model provider, alerts that open issues, tickets agents read515 "/workspaces/:workspace/integrations",
516 Op::ListIntegrations,
517 &[],
518 ),
519 route(
520 "POST",
521 "/workspaces/:workspace/integrations",
522 Op::ConnectIntegration,
523 &[],
524 ),
525 route(
Models per workspace: several providers, routed by kind of work526 "GET",
Webhooks: every event, to your own addresses, signed and retried527 "/repos/:owner/:name/hooks",
528 Op::ListWebhooks,
529 &[],
530 ),
531 route(
532 "POST",
533 "/repos/:owner/:name/hooks",
534 Op::CreateWebhook,
535 &[],
536 ),
537 route(
538 "PATCH",
539 "/repos/:owner/:name/hooks/:id",
540 Op::UpdateWebhook,
541 &[],
542 ),
543 route(
544 "DELETE",
545 "/repos/:owner/:name/hooks/:id",
546 Op::DeleteWebhook,
547 &[],
548 ),
549 route(
550 "POST",
551 "/repos/:owner/:name/hooks/:id/pings",
552 Op::PingWebhook,
553 &[],
554 ),
555 route(
556 "GET",
557 "/repos/:owner/:name/hooks/:id/deliveries",
558 Op::ListWebhookDeliveries,
559 &[],
560 ),
561 route(
562 "POST",
563 "/repos/:owner/:name/hooks/:id/deliveries/:delivery/redeliver",
564 Op::RedeliverWebhook,
565 &[],
566 ),
567 route(
568 "GET",
569 "/workspaces/:workspace/hooks",
570 Op::ListWebhooks,
571 &[],
572 ),
573 route(
574 "POST",
575 "/workspaces/:workspace/hooks",
576 Op::CreateWebhook,
577 &[],
578 ),
579 route(
580 "PATCH",
581 "/workspaces/:workspace/hooks/:id",
582 Op::UpdateWebhook,
583 &[],
584 ),
585 route(
586 "DELETE",
587 "/workspaces/:workspace/hooks/:id",
588 Op::DeleteWebhook,
589 &[],
590 ),
591 route(
592 "POST",
593 "/workspaces/:workspace/hooks/:id/pings",
594 Op::PingWebhook,
595 &[],
596 ),
597 route(
598 "GET",
599 "/workspaces/:workspace/hooks/:id/deliveries",
600 Op::ListWebhookDeliveries,
601 &[],
602 ),
603 route(
604 "POST",
605 "/workspaces/:workspace/hooks/:id/deliveries/:delivery/redeliver",
606 Op::RedeliverWebhook,
607 &[],
608 ),
609 route(
610 "GET",
Models per workspace: several providers, routed by kind of work611 "/workspaces/:workspace/model-routes",
612 Op::GetModelRoutes,
613 &[],
614 ),
615 route(
616 "PUT",
617 "/workspaces/:workspace/model-routes",
618 Op::SetModelRoutes,
619 &[],
620 ),
621 route(
AI Gateway: OpenAI's format, open models, and your own providers622 "PATCH",
623 "/workspaces/:workspace/integrations/:id",
624 Op::UpdateIntegration,
625 &[],
626 ),
627 route(
Integrations: your own model provider, alerts that open issues, tickets agents read628 "DELETE",
629 "/workspaces/:workspace/integrations/:id",
630 Op::DisconnectIntegration,
631 &[],
632 ),
633 route(
634 "POST",
635 "/workspaces/:workspace/integrations/:id/test",
636 Op::TestIntegration,
637 &[],
638 ),
Automations: rules in .g1t/automations that act when something happens639 route(
640 "GET",
GitHub Actions on g1t, part two: running workflows641 "/repos/:owner/:name/actions/workflows",
642 Op::ListWorkflows,
643 &[],
644 ),
645 route(
646 "GET",
647 "/repos/:owner/:name/actions/workflows/:workflow/runs",
648 Op::ListWorkflowRuns,
649 &[("branch", "branch"), ("event", "event"), ("per_page", "limit")],
650 ),
651 route(
652 "POST",
653 "/repos/:owner/:name/actions/workflows/:workflow/dispatches",
654 Op::DispatchWorkflow,
655 &[],
656 ),
657 route(
658 "PATCH",
659 "/repos/:owner/:name/actions/workflows/:workflow",
660 Op::UpdateWorkflow,
661 &[],
662 ),
663 route(
664 "PUT",
665 "/repos/:owner/:name/actions/workflows/:workflow/enable",
666 Op::UpdateWorkflow,
667 &[],
668 ),
669 route(
670 "PUT",
671 "/repos/:owner/:name/actions/workflows/:workflow/disable",
672 Op::UpdateWorkflow,
673 &[],
674 ),
675 route(
676 "GET",
677 "/repos/:owner/:name/actions/runs",
678 Op::ListWorkflowRuns,
679 &[("workflow", "workflow"), ("branch", "branch"), ("event", "event"), ("pull", "pull"), ("head_sha", "sha"), ("per_page", "limit")],
680 ),
681 route(
682 "GET",
683 "/repos/:owner/:name/actions/runs/:id",
684 Op::GetWorkflowRun,
685 &[],
686 ),
687 route(
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)688 "GET",
689 "/repos/:owner/:name/actions/runs/:id/attempts/:attempt",
690 Op::GetWorkflowRun,
691 &[],
692 ),
693 route(
GitHub Actions on g1t, part two: running workflows694 "POST",
695 "/repos/:owner/:name/actions/runs/:id/cancel",
696 Op::CancelWorkflowRun,
697 &[],
698 ),
699 route(
700 "POST",
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)701 "/repos/:owner/:name/actions/runs/:id/force-cancel",
702 Op::CancelWorkflowRun,
703 &[],
704 ),
705 route(
706 "POST",
GitHub Actions on g1t, part two: running workflows707 "/repos/:owner/:name/actions/runs/:id/rerun",
708 Op::RerunWorkflowRun,
709 &[],
710 ),
711 route(
712 "POST",
713 "/repos/:owner/:name/actions/runs/:id/rerun-failed-jobs",
714 Op::RerunWorkflowRun,
715 &[],
716 ),
717 route(
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)718 "POST",
719 "/repos/:owner/:name/actions/jobs/:job/rerun",
720 Op::RerunWorkflowRun,
721 &[],
722 ),
723 route(
GitHub Actions on g1t, part two: running workflows724 "GET",
725 "/repos/:owner/:name/actions/jobs/:job/logs",
726 Op::GetJobLogs,
727 &[("after", "after")],
728 ),
Merge packages: roles, Actions access, source label, soft delete, API729 // Packages, at GitHub's addresses with the workspace in place of the
730 // organization. A name with a slash is one URL-encoded segment.
731 route("GET", "/workspaces/:workspace/packages", Op::Packages(PackagesOp::ListPackages), &[("package_type", "package_type"), ("q", "q"), ("state", "state")]),
732 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::GetPackage), &[]),
733 route("PATCH", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::UpdatePackage), &[]),
734 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name", Op::Packages(PackagesOp::DeletePackage), &[]),
735 route("POST", "/workspaces/:workspace/packages/:package_type/:package_name/restore", Op::Packages(PackagesOp::RestorePackage), &[]),
736 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/versions", Op::Packages(PackagesOp::ListVersions), &[("state", "state")]),
737 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id", Op::Packages(PackagesOp::GetVersion), &[]),
738 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id", Op::Packages(PackagesOp::DeleteVersion), &[]),
739 route("POST", "/workspaces/:workspace/packages/:package_type/:package_name/versions/:version_id/restore", Op::Packages(PackagesOp::RestoreVersion), &[]),
740 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/repository", Op::Packages(PackagesOp::LinkPackage), &[]),
741 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/repository", Op::Packages(PackagesOp::UnlinkPackage), &[]),
742 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::ListAccess), &[]),
743 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::SetAccess), &[]),
744 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/access", Op::Packages(PackagesOp::RemoveAccess), &[("username", "username"), ("team", "team")]),
745 route("GET", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access", Op::Packages(PackagesOp::ListActionsAccess), &[]),
746 route("PUT", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access", Op::Packages(PackagesOp::SetActionsAccess), &[]),
747 route("DELETE", "/workspaces/:workspace/packages/:package_type/:package_name/actions-access/:repository", Op::Packages(PackagesOp::RemoveActionsAccess), &[]),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2748 // Artifacts, at GitHub's addresses. `…/zip` answers with a redirect to
749 // a signed link (lib.rs).
750 route("GET", "/repos/:owner/:name/actions/artifacts", Op::Artifacts(ArtifactsOp::ListArtifacts), &[("name", "name"), ("page", "page"), ("per_page", "per_page")]),
751 route("GET", "/repos/:owner/:name/actions/runs/:id/artifacts", Op::Artifacts(ArtifactsOp::ListRunArtifacts), &[("name", "name")]),
752 route("GET", "/repos/:owner/:name/actions/artifacts/:id", Op::Artifacts(ArtifactsOp::GetArtifact), &[]),
753 route("GET", "/repos/:owner/:name/actions/artifacts/:id/zip", Op::Artifacts(ArtifactsOp::DownloadArtifact), &[]),
754 route("DELETE", "/repos/:owner/:name/actions/artifacts/:id", Op::Artifacts(ArtifactsOp::DeleteArtifact), &[]),
755 route("GET", "/repos/:owner/:name/actions/permissions/artifact-and-log-retention", Op::Artifacts(ArtifactsOp::GetArtifactRetention), &[]),
756 route("PUT", "/repos/:owner/:name/actions/permissions/artifact-and-log-retention", Op::Artifacts(ArtifactsOp::SetArtifactRetention), &[]),
GitHub Actions on g1t, part two: running workflows757 route(
758 "GET",
759 "/repos/:owner/:name/actions/secrets",
760 Op::ListActionsSecrets,
761 &[],
762 ),
763 route(
764 "PUT",
765 "/repos/:owner/:name/actions/secrets/:setting",
766 Op::SetActionsSecret,
767 &[],
768 ),
769 route(
770 "DELETE",
771 "/repos/:owner/:name/actions/secrets/:setting",
772 Op::DeleteActionsSecret,
773 &[],
774 ),
775 route(
776 "GET",
777 "/repos/:owner/:name/actions/variables",
778 Op::ListActionsVariables,
779 &[],
780 ),
781 route(
782 "POST",
783 "/repos/:owner/:name/actions/variables",
784 Op::SetActionsVariable,
785 &[],
786 ),
787 route(
788 "PATCH",
789 "/repos/:owner/:name/actions/variables/:setting",
790 Op::SetActionsVariable,
791 &[],
792 ),
793 route(
794 "DELETE",
795 "/repos/:owner/:name/actions/variables/:setting",
796 Op::DeleteActionsVariable,
797 &[],
798 ),
799 route(
800 "GET",
801 "/workspaces/:workspace/actions/secrets",
802 Op::ListActionsSecrets,
803 &[],
804 ),
805 route(
806 "PUT",
807 "/workspaces/:workspace/actions/secrets/:setting",
808 Op::SetActionsSecret,
809 &[],
810 ),
811 route(
812 "DELETE",
813 "/workspaces/:workspace/actions/secrets/:setting",
814 Op::DeleteActionsSecret,
815 &[],
816 ),
817 route(
818 "GET",
819 "/workspaces/:workspace/actions/variables",
820 Op::ListActionsVariables,
821 &[],
822 ),
823 route(
824 "POST",
825 "/workspaces/:workspace/actions/variables",
826 Op::SetActionsVariable,
827 &[],
828 ),
829 route(
830 "PATCH",
831 "/workspaces/:workspace/actions/variables/:setting",
832 Op::SetActionsVariable,
833 &[],
834 ),
835 route(
836 "DELETE",
837 "/workspaces/:workspace/actions/variables/:setting",
838 Op::DeleteActionsVariable,
839 &[],
840 ),
Fast pages, required checks on the branch, self-hosted runners, honest incidents841 // Self-hosted runners: a repository's own, or a workspace's.
842 route("GET", "/repos/:owner/:name/actions/runners", Op::ListRunners, &[]),
843 route("POST", "/repos/:owner/:name/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
844 route("DELETE", "/repos/:owner/:name/actions/runners/:id", Op::RemoveRunner, &[]),
845 route("GET", "/repos/:owner/:name/actions/runner-settings", Op::GetRunnerSettings, &[]),
846 route("PATCH", "/repos/:owner/:name/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
847 route("GET", "/workspaces/:workspace/actions/runners", Op::ListRunners, &[]),
848 route("POST", "/workspaces/:workspace/actions/runners/registration-token", Op::CreateRunnerRegistrationToken, &[]),
849 route("DELETE", "/workspaces/:workspace/actions/runners/:id", Op::RemoveRunner, &[]),
850 route("GET", "/workspaces/:workspace/actions/runner-settings", Op::GetRunnerSettings, &[]),
851 route("PATCH", "/workspaces/:workspace/actions/runner-settings", Op::UpdateRunnerSettings, &[]),
852 route("GET", "/workspaces/:workspace/actions/runner-groups", Op::ListRunnerGroups, &[]),
853 route("POST", "/workspaces/:workspace/actions/runner-groups", Op::CreateRunnerGroup, &[]),
854 route("PATCH", "/workspaces/:workspace/actions/runner-groups/:id", Op::UpdateRunnerGroup, &[]),
855 route("DELETE", "/workspaces/:workspace/actions/runner-groups/:id", Op::DeleteRunnerGroup, &[]),
Agents as a team: lifecycle, merge queue, billing and a new shell856 route("POST", "/repos/:owner/:name/plans", Op::PlanWork, &[]),
857 route("GET", "/repos/:owner/:name/plans/:plan", Op::GetPlan, &[]),
858 route(
859 "POST",
860 "/repos/:owner/:name/plans/:plan/apply",
861 Op::ApplyPlan,
862 &[],
863 ),
864 route(
865 "POST",
866 "/repos/:owner/:name/issues/:number/comments",
API and MCP server in Rust; a public index at the API root867 Op::AddComment,
868 &[],
869 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts870 route("PATCH", "/repos/:owner/:name/issues/comments/:comment_id", Op::EditComment, &[]),
871 route("DELETE", "/repos/:owner/:name/issues/comments/:comment_id", Op::DeleteComment, &[]),
API and MCP server in Rust; a public index at the API root872 route(
873 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell874 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root875 Op::ListPullRequests,
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar876 &[("state", "state"), ("label", "label"), ("milestone", "milestone"), ("base", "base")],
API and MCP server in Rust; a public index at the API root877 ),
878 route(
879 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell880 "/repos/:owner/:name/pulls",
API and MCP server in Rust; a public index at the API root881 Op::CreatePullRequest,
882 &[],
883 ),
884 route(
885 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell886 "/repos/:owner/:name/pulls/:number",
API and MCP server in Rust; a public index at the API root887 Op::GetPullRequest,
888 &[],
889 ),
890 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar891 "PATCH",
892 "/repos/:owner/:name/pulls/:number",
893 Op::UpdatePullRequest,
894 &[],
895 ),
896 route(
API and MCP server in Rust; a public index at the API root897 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell898 "/repos/:owner/:name/pulls/:number/changes",
API and MCP server in Rust; a public index at the API root899 Op::GetPullRequestChanges,
900 &[],
901 ),
902 route(
Acceptance checks in sandboxes, line comments and review verdicts903 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell904 "/repos/:owner/:name/pulls/:number/reviews",
Acceptance checks in sandboxes, line comments and review verdicts905 Op::ReviewPullRequest,
906 &[],
907 ),
908 route(
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar909 "POST",
910 "/repos/:owner/:name/pulls/:number/requested_reviewers",
911 Op::RequestReviewers,
912 &[],
913 ),
914 route(
915 "DELETE",
916 "/repos/:owner/:name/pulls/:number/requested_reviewers",
917 Op::RemoveRequestedReviewers,
918 &[],
919 ),
920 route(
API and MCP server in Rust; a public index at the API root921 "GET",
Agents as a team: lifecycle, merge queue, billing and a new shell922 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root923 Op::ReadSession,
924 &[("after", "after")],
925 ),
926 route(
927 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell928 "/repos/:owner/:name/pulls/:number/session",
API and MCP server in Rust; a public index at the API root929 Op::RecordSession,
930 &[],
931 ),
932 route(
933 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell934 "/repos/:owner/:name/pulls/:number/ready",
API and MCP server in Rust; a public index at the API root935 Op::MarkPullRequestReady,
936 &[],
937 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts938 route("POST", "/repos/:owner/:name/pulls/:number/draft", Op::ConvertPullRequestToDraft, &[]),
API and MCP server in Rust; a public index at the API root939 route(
940 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell941 "/repos/:owner/:name/pulls/:number/close",
API and MCP server in Rust; a public index at the API root942 Op::ClosePullRequest,
943 &[],
944 ),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts945 route("POST", "/repos/:owner/:name/pulls/:number/reopen", Op::ReopenPullRequest, &[]),
API and MCP server in Rust; a public index at the API root946 route(
947 "POST",
Agents as a team: lifecycle, merge queue, billing and a new shell948 "/repos/:owner/:name/pulls/:number/merge",
API and MCP server in Rust; a public index at the API root949 Op::MergePullRequest,
950 &[],
951 ),
952];
953
954impl Route {
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts955 /// Whether the route answers success with `204` and no body, as
956 /// GitHub's address for the same does. MCP still answers `true`.
957 pub fn no_content(&self) -> bool {
958 self.op == Op::DeleteComment
959 }
960
API and MCP server in Rust; a public index at the API root961 /// The names of the route's path parameters, in order.
962 pub fn params(&self) -> impl Iterator<Item = &'static str> {
963 self.path
964 .split('/')
965 .filter_map(|segment| segment.strip_prefix(':'))
966 }
967
968 /// The values of the path parameters, if `path` is this route's.
969 fn matches<'a>(&self, path: &'a str) -> Option<Vec<(&'static str, &'a str)>> {
970 let mut values = Vec::new();
971 let mut actual = path.trim_end_matches('/').split('/');
972 for expected in self.path.split('/') {
973 let segment = actual.next()?;
974 match expected.strip_prefix(':') {
975 Some(name) if !segment.is_empty() => values.push((name, segment)),
976 Some(_) => return None,
977 None if expected == segment => {}
978 None => return None,
979 }
980 }
981 actual.next().is_none().then_some(values)
982 }
983}
984
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look985/// A path segment with its `%XX` escapes decoded; as given when that is not
986/// UTF-8.
987fn percent_decoded(segment: &str) -> String {
988 let bytes = segment.as_bytes();
989 let mut out = Vec::with_capacity(bytes.len());
990 let mut i = 0;
991 while i < bytes.len() {
992 let escaped = (bytes[i] == b'%')
993 .then(|| segment.get(i + 1..i + 3))
994 .flatten()
995 .filter(|hex| hex.bytes().all(|byte| byte.is_ascii_hexdigit()))
996 .and_then(|hex| u8::from_str_radix(hex, 16).ok());
997 match escaped {
998 Some(byte) => {
999 out.push(byte);
1000 i += 3;
1001 }
1002 None => {
1003 out.push(bytes[i]);
1004 i += 1;
1005 }
1006 }
1007 }
1008 String::from_utf8(out).unwrap_or_else(|_| segment.to_owned())
1009}
1010
API and MCP server in Rust; a public index at the API root1011/// The route for a request, and the operation input it describes.
1012///
1013/// The input is the JSON body, overlaid with the query parameters the route
1014/// reads and then with what the path names: `owner` and `name` become
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1015/// `repo`, as does a team's `repo` with its `workspace`, and `number`
1016/// becomes an integer.
API and MCP server in Rust; a public index at the API root1017pub fn resolve(
1018 method: &str,
1019 path: &str,
1020 query: &[(String, String)],
1021 body: Value,
1022) -> Option<(&'static Route, Value)> {
1023 let (route, params) = ROUTES
1024 .iter()
1025 .filter(|route| route.method == method)
1026 .find_map(|route| Some((route, route.matches(path)?)))?;
1027
1028 let mut input = match body {
1029 Value::Object(fields) => fields,
1030 _ => Map::new(),
1031 };
1032 for (name, key) in route.query {
1033 if let Some((_, value)) = query.iter().find(|(query_name, _)| query_name == name) {
1034 input.insert((*key).to_owned(), Value::String(value.clone()));
1035 }
1036 }
1037 let param = |wanted: &str| {
1038 params
1039 .iter()
1040 .find(|(name, _)| *name == wanted)
1041 .map(|(_, value)| *value)
1042 };
1043 if let (Some(owner), Some(name)) = (param("owner"), param("name")) {
1044 input.insert("repo".to_owned(), Value::String(format!("{owner}/{name}")));
1045 }
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971046 // Every other name the path gives, under that name; the ones below that
1047 // need more (a repository, a number, an encoded name) are set after.
1048 for (key, value) in &params {
1049 if !matches!(*key, "owner" | "name") {
1050 input.insert((*key).to_owned(), Value::String(percent_decoded(value)));
Docs worth reading, and kept that way1051 }
Agents as a team: lifecycle, merge queue, billing and a new shell1052 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1053 // A repository of a team's workspace, named by itself.
1054 if let (Some(workspace), Some(name)) = (param("workspace"), param("repo")) {
1055 input.insert("repo".to_owned(), Value::String(format!("{workspace}/{name}")));
1056 }
1057 // A branch name may hold slashes, sent URL-encoded as one segment, and
1058 // a label's name spaces.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1059 if let Some(branch) = param("branch") {
1060 input.insert("branch".to_owned(), Value::String(percent_decoded(branch)));
1061 }
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971062 // An environment's name may hold slashes and spaces, URL-encoded.
1063 if let Some(environment) = param("environment") {
1064 input.insert("environment".to_owned(), Value::String(percent_decoded(environment)));
1065 }
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1066 if let Some(label) = param("label") {
1067 input.insert("label".to_owned(), Value::String(percent_decoded(label)));
1068 }
1069 if let Some(milestone) = param("milestone") {
1070 // Not a number: zero, which no milestone has.
1071 input.insert("milestone".to_owned(), milestone.parse::<u32>().unwrap_or(0).into());
1072 }
GitHub Actions on g1t, part two: running workflows1073 // GitHub says some things with the path alone.
1074 if route.path.ends_with("/enable") || route.path.ends_with("/disable") {
1075 input.insert("enabled".to_owned(), Value::Bool(route.path.ends_with("/enable")));
1076 }
1077 if route.path.ends_with("/rerun-failed-jobs") {
1078 input.insert("failed_only".to_owned(), Value::Bool(true));
1079 }
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)1080 if route.path.ends_with("/force-cancel") {
1081 input.insert("force".to_owned(), Value::Bool(true));
1082 }
API: notifications over REST and MCP, with notifications scopes1083 // Unsaving and waking a thread are a DELETE of what PUT made.
1084 if route.method == "DELETE" && route.path.ends_with("/saved") {
1085 input.insert("saved".to_owned(), Value::Bool(false));
1086 }
1087 if route.method == "DELETE" && route.path.ends_with("/snooze") {
1088 input.remove("until");
1089 }
API and MCP server in Rust; a public index at the API root1090 if let Some(number) = param("number") {
1091 // Not a number: zero, which no issue or pull request has.
1092 input.insert(
1093 "number".to_owned(),
1094 number.parse::<u32>().unwrap_or(0).into(),
1095 );
1096 }
1097 Some((route, Value::Object(input)))
1098}
1099
1100#[cfg(test)]
1101mod tests {
1102 use serde_json::json;
1103
1104 use super::*;
1105
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb971106 /// Every name a route's path gives reaches the operation: a name left
1107 /// off the lists above is dropped, and the operation answers that it
1108 /// was not given (the project routes were, until this test).
1109 #[test]
1110 fn every_path_parameter_reaches_the_input() {
1111 for route in ROUTES.iter() {
1112 let names: Vec<&str> = route.path.split('/').filter_map(|part| part.strip_prefix(':')).collect();
1113 if names.is_empty() {
1114 continue;
1115 }
1116 let path: String = route
1117 .path
1118 .split('/')
1119 .map(|part| match part.strip_prefix(':') {
1120 Some("number" | "milestone") => "7".to_owned(),
1121 Some(name) => format!("{name}-x"),
1122 None => part.to_owned(),
1123 })
1124 .collect::<Vec<_>>()
1125 .join("/");
1126 let (found, input) = resolve(route.method, &path, &[], json!({})).unwrap();
1127 // A path two routes could take is checked under the first.
1128 if found.path != route.path {
1129 continue;
1130 }
1131 for name in names {
1132 let key = match name {
1133 "owner" | "name" => "repo",
1134 "repo" if names_has_workspace(route.path) => "repo",
1135 other => other,
1136 };
1137 assert!(
1138 input.get(key).is_some_and(|value| !value.is_null()),
1139 "{} {}: :{name} does not reach the input",
1140 route.method,
1141 route.path
1142 );
1143 }
1144 }
1145 }
1146
1147 fn names_has_workspace(path: &str) -> bool {
1148 path.split('/').any(|part| part == ":workspace")
1149 }
1150
API and MCP server in Rust; a public index at the API root1151 #[test]
1152 fn a_path_resolves_to_its_operation_and_input() {
1153 let (route, input) = resolve(
1154 "POST",
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1155 "/repos/flagon-io/hello/pulls/14/merge",
API and MCP server in Rust; a public index at the API root1156 &[],
1157 json!({ "keep_issue_open": true, "number": 99, "repo": "someone/else" }),
1158 )
1159 .unwrap();
1160 assert_eq!(route.op, Op::MergePullRequest);
1161 // What the path names wins over the body.
1162 assert_eq!(
1163 input,
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1164 json!({ "keep_issue_open": true, "number": 14, "repo": "flagon-io/hello" })
API and MCP server in Rust; a public index at the API root1165 );
1166 }
1167
1168 #[test]
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look1169 fn a_branch_with_slashes_is_one_encoded_segment() {
1170 let (route, input) = resolve(
1171 "POST",
1172 "/repos/flagon-io/hello/branches/feature%2Flogin/rename",
1173 &[],
1174 json!({ "new_name": "feature/sign-in" }),
1175 )
1176 .unwrap();
1177 assert_eq!(route.op, Op::RenameBranch);
1178 assert_eq!(
1179 input,
1180 json!({ "new_name": "feature/sign-in", "branch": "feature/login", "repo": "flagon-io/hello" })
1181 );
1182 assert_eq!(percent_decoded("100%"), "100%");
1183 assert_eq!(percent_decoded("a%2bb%zz"), "a+b%zz");
1184 }
1185
1186 #[test]
1187 fn a_collaborator_is_named_by_username() {
1188 let (route, input) = resolve(
1189 "PATCH",
1190 "/repos/flagon-io/hello/collaborators/ada",
1191 &[],
1192 json!({ "role": "maintain" }),
1193 )
1194 .unwrap();
1195 assert_eq!(route.op, Op::UpdateCollaborator);
1196 assert_eq!(input, json!({ "role": "maintain", "username": "ada", "repo": "flagon-io/hello" }));
1197 let (route, input) = resolve("DELETE", "/user/repository_invitations/rin_1", &[], Value::Null).unwrap();
1198 assert_eq!(route.op, Op::DeclineRepoInvitation);
1199 assert_eq!(input, json!({ "id": "rin_1" }));
1200 }
1201
1202 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1203 fn teams_are_addressed_by_workspace_and_slug() {
1204 let query = [("q".to_owned(), "back".to_owned())];
1205 let (route, input) = resolve("GET", "/workspaces/acme/teams", &query, Value::Null).unwrap();
1206 assert_eq!(route.op, Op::ListTeams);
1207 assert_eq!(input, json!({ "query": "back", "workspace": "acme" }));
1208 let (route, input) = resolve("PATCH", "/workspaces/acme/teams/backend", &[], json!({ "name": "Back end" })).unwrap();
1209 assert_eq!(route.op, Op::UpdateTeam);
1210 assert_eq!(input, json!({ "name": "Back end", "workspace": "acme", "team": "backend" }));
1211 let (route, input) =
1212 resolve("PUT", "/workspaces/acme/teams/backend/members/ana", &[], json!({ "role": "maintainer" })).unwrap();
1213 assert_eq!(route.op, Op::SetTeamMember);
1214 assert_eq!(input, json!({ "role": "maintainer", "workspace": "acme", "team": "backend", "username": "ana" }));
1215 let query = [("include_child_teams".to_owned(), "true".to_owned())];
1216 let (route, input) = resolve("GET", "/workspaces/acme/teams/backend/members", &query, Value::Null).unwrap();
1217 assert_eq!(route.op, Op::ListTeamMembers);
1218 assert_eq!(input, json!({ "include_child_teams": "true", "workspace": "acme", "team": "backend" }));
1219 // A repository is named by itself, in the team's workspace.
1220 let (route, input) =
1221 resolve("PUT", "/workspaces/acme/teams/backend/repos/rocket", &[], json!({ "role": "write" })).unwrap();
1222 assert_eq!(route.op, Op::SetTeamRepo);
1223 assert_eq!(input, json!({ "role": "write", "workspace": "acme", "team": "backend", "repo": "acme/rocket" }));
1224 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1225 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/repos/rocket"), Op::RemoveTeamRepo);
1226 assert_eq!(op("GET", "/workspaces/acme/teams/backend/teams"), Op::ListChildTeams);
1227 assert_eq!(op("GET", "/workspaces/acme/teams/backend/repos"), Op::ListTeamRepos);
1228 assert_eq!(op("PUT", "/workspaces/acme/teams/backend/review_assignment"), Op::SetTeamReviewAssignment);
1229 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend"), Op::DeleteTeam);
1230 assert_eq!(op("POST", "/workspaces/acme/teams"), Op::CreateTeam);
1231 assert_eq!(op("GET", "/workspaces/acme/teams/backend"), Op::GetTeam);
1232 assert_eq!(op("DELETE", "/workspaces/acme/teams/backend/members/ana"), Op::RemoveTeamMember);
1233 let (route, input) = resolve("GET", "/workspaces/acme/members/ana/teams", &[], Value::Null).unwrap();
1234 assert_eq!(route.op, Op::ListUserTeams);
1235 assert_eq!(input, json!({ "workspace": "acme", "username": "ana" }));
1236 }
1237
1238 #[test]
1239 fn reviewers_are_requested_and_code_owners_checked_on_a_repository() {
1240 let body = json!({ "reviewers": ["ana"], "team_reviewers": ["backend"] });
1241 let (route, input) = resolve("POST", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body.clone()).unwrap();
1242 assert_eq!(route.op, Op::RequestReviewers);
1243 assert_eq!(
1244 input,
1245 json!({ "reviewers": ["ana"], "team_reviewers": ["backend"], "repo": "acme/rocket", "number": 7 })
1246 );
1247 let (route, _) = resolve("DELETE", "/repos/acme/rocket/pulls/7/requested_reviewers", &[], body).unwrap();
1248 assert_eq!(route.op, Op::RemoveRequestedReviewers);
1249 let query = [("ref".to_owned(), "main".to_owned())];
1250 let (route, input) = resolve("GET", "/repos/acme/rocket/codeowners/errors", &query, Value::Null).unwrap();
1251 assert_eq!(route.op, Op::GetCodeownersErrors);
1252 assert_eq!(input, json!({ "ref": "main", "repo": "acme/rocket" }));
1253 }
1254
1255 #[test]
API: notifications over REST and MCP, with notifications scopes1256 fn notifications_are_addressed_as_threads_and_by_issue() {
1257 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1", &[], Value::Null).unwrap();
1258 assert_eq!(route.op, Op::MarkThreadDone);
1259 assert_eq!(input, json!({ "id": "ntf_1" }));
1260 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/saved", &[], Value::Null).unwrap();
1261 assert_eq!(route.op, Op::SaveThread);
1262 assert_eq!(input, json!({ "id": "ntf_1", "saved": false }));
1263 let (route, input) = resolve("DELETE", "/notifications/threads/ntf_1/snooze", &[], json!({ "until": "x" })).unwrap();
1264 assert_eq!(route.op, Op::SnoozeThread);
1265 assert_eq!(input, json!({ "id": "ntf_1" }));
1266 let query = [("all".to_owned(), "true".to_owned()), ("per_page".to_owned(), "50".to_owned())];
1267 let (route, input) = resolve("GET", "/repos/acme/rocket/notifications", &query, Value::Null).unwrap();
1268 assert_eq!(route.op, Op::ListNotifications);
1269 assert_eq!(input, json!({ "all": "true", "per_page": "50", "repo": "acme/rocket" }));
1270 let (route, input) = resolve("PUT", "/repos/acme/rocket/issues/7/subscription", &[], json!({ "ignored": true })).unwrap();
1271 assert_eq!(route.op, Op::SetThreadSubscription);
1272 assert_eq!(input, json!({ "ignored": true, "number": 7, "repo": "acme/rocket" }));
1273 assert_eq!(resolve("GET", "/user/subscriptions", &[], Value::Null).unwrap().0.op, Op::ListWatchedRepos);
1274 }
1275
1276 #[test]
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar1277 fn labels_and_milestones_are_named_in_the_path() {
1278 let (route, input) = resolve("PATCH", "/repos/acme/web/labels/good%20first%20issue", &[], json!({ "color": "7057ff" })).unwrap();
1279 assert_eq!(route.op, Op::UpdateLabel);
1280 assert_eq!(input, json!({ "color": "7057ff", "label": "good first issue", "repo": "acme/web" }));
1281 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels/bug", &[], Value::Null).unwrap();
1282 assert_eq!(route.op, Op::RemoveIssueLabels);
1283 assert_eq!(input, json!({ "label": "bug", "number": 7, "repo": "acme/web" }));
1284 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/7/labels", &[], Value::Null).unwrap();
1285 assert_eq!(route.op, Op::RemoveIssueLabels);
1286 assert_eq!(input, json!({ "number": 7, "repo": "acme/web" }));
1287 let (route, _) = resolve("POST", "/repos/acme/web/labels/defaults", &[], Value::Null).unwrap();
1288 assert_eq!(route.op, Op::AddDefaultLabels);
1289 let (route, input) = resolve("PATCH", "/repos/acme/web/milestones/3", &[], json!({ "state": "closed" })).unwrap();
1290 assert_eq!(route.op, Op::UpdateMilestone);
1291 assert_eq!(input, json!({ "state": "closed", "milestone": 3, "repo": "acme/web" }));
1292 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "base": "release" })).unwrap();
1293 assert_eq!(route.op, Op::UpdatePullRequest);
1294 assert_eq!(input, json!({ "base": "release", "number": 9, "repo": "acme/web" }));
1295 }
1296
1297 #[test]
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts1298 fn pull_requests_reopen_and_turn_draft_and_comments_are_named_by_id() {
1299 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1300 assert_eq!(op("POST", "/repos/acme/web/pulls/9/reopen"), Op::ReopenPullRequest);
1301 assert_eq!(op("POST", "/repos/acme/web/pulls/9/draft"), Op::ConvertPullRequestToDraft);
1302 assert_eq!(op("POST", "/repos/acme/web/pulls/9/close"), Op::ClosePullRequest);
1303 // Reopening and closing with a PATCH, as `state`.
1304 let (route, input) = resolve("PATCH", "/repos/acme/web/pulls/9", &[], json!({ "state": "open" })).unwrap();
1305 assert_eq!(route.op, Op::UpdatePullRequest);
1306 assert_eq!(input, json!({ "state": "open", "number": 9, "repo": "acme/web" }));
1307 let (route, input) =
1308 resolve("PATCH", "/repos/acme/web/issues/comments/cmt_1", &[], json!({ "body": "Better" })).unwrap();
1309 assert_eq!(route.op, Op::EditComment);
1310 assert_eq!(input, json!({ "body": "Better", "comment_id": "cmt_1", "repo": "acme/web" }));
1311 let (route, input) = resolve("DELETE", "/repos/acme/web/issues/comments/cmt_1", &[], Value::Null).unwrap();
1312 assert_eq!(route.op, Op::DeleteComment);
1313 assert_eq!(input, json!({ "comment_id": "cmt_1", "repo": "acme/web" }));
1314 // Still an issue's comments, labels and subscription.
1315 assert_eq!(op("POST", "/repos/acme/web/issues/7/comments"), Op::AddComment);
1316 assert_eq!(op("DELETE", "/repos/acme/web/issues/7/labels"), Op::RemoveIssueLabels);
1317 assert_eq!(op("DELETE", "/repos/acme/web/issues/7/subscription"), Op::DeleteThreadSubscription);
1318 }
1319
1320 #[test]
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1321 fn billing_is_addressed_by_workspace() {
1322 let query = [("from".to_owned(), "2026-10-01".to_owned()), ("products".to_owned(), "agent,sandboxes".to_owned())];
1323 let (route, input) = resolve("GET", "/workspaces/acme/usage", &query, Value::Null).unwrap();
1324 assert_eq!(route.op, Op::GetUsage);
1325 assert_eq!(input, json!({ "from": "2026-10-01", "products": "agent,sandboxes", "workspace": "acme" }));
1326 let (route, input) = resolve("PUT", "/workspaces/acme/budget", &[], json!({ "alerts": [50] })).unwrap();
1327 assert_eq!(route.op, Op::SetBudget);
1328 assert_eq!(input, json!({ "alerts": [50], "workspace": "acme" }));
1329 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1330 assert_eq!(op("GET", "/workspaces/acme/budget"), Op::GetBudget);
1331 assert_eq!(op("GET", "/workspaces/acme/ai_credit"), Op::GetAiCredit);
1332 assert_eq!(op("POST", "/workspaces/acme/ai_credit/checkout"), Op::BuyAiCredit);
1333 assert_eq!(op("GET", "/workspaces/acme/invoices"), Op::ListInvoices);
1334 assert_eq!(op("GET", "/workspaces/acme/billing_details"), Op::GetBillingDetails);
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens1335 assert_eq!(op("GET", "/workspaces/acme/gateway/requests"), Op::ListGatewayRequests);
Usage, Billing settings and prepaid AI credit; fixes from the UX audit1336 }
1337
1338 #[test]
Merge checks: statuses and check runs on every commit1339 fn checks_are_at_githubs_addresses() {
1340 let sha = "a".repeat(40);
1341 let body = json!({ "state": "success", "context": "ci/build" });
1342 let (route, input) = resolve("POST", &format!("/repos/acme/web/statuses/{sha}"), &[], body).unwrap();
1343 assert_eq!(route.op, Op::Checks(ChecksOp::CreateCommitStatus));
1344 assert_eq!(input, json!({ "state": "success", "context": "ci/build", "sha": sha, "repo": "acme/web" }));
1345 let (route, input) = resolve("GET", "/repos/acme/web/commits/release%2F1.x/status", &[], Value::Null).unwrap();
1346 assert_eq!(route.op, Op::Checks(ChecksOp::GetCombinedStatus));
1347 assert_eq!(input, json!({ "ref": "release/1.x", "repo": "acme/web" }));
1348 let query = [("check_name".to_owned(), "lint".to_owned())];
1349 let (route, input) = resolve("GET", "/repos/acme/web/commits/main/check-runs", &query, Value::Null).unwrap();
1350 assert_eq!(route.op, Op::Checks(ChecksOp::ListCheckRunsForRef));
1351 assert_eq!(input, json!({ "check_name": "lint", "ref": "main", "repo": "acme/web" }));
1352 let (route, input) = resolve("PATCH", "/repos/acme/web/check-runs/cr_1", &[], json!({ "conclusion": "success" })).unwrap();
1353 assert_eq!(route.op, Op::Checks(ChecksOp::UpdateCheckRun));
1354 assert_eq!(input, json!({ "conclusion": "success", "id": "cr_1", "repo": "acme/web" }));
1355 let op = |method: &str, path: &str| resolve(method, path, &[], Value::Null).unwrap().0.op;
1356 assert_eq!(op("POST", "/repos/acme/web/check-runs"), Op::Checks(ChecksOp::CreateCheckRun));
1357 assert_eq!(op("GET", "/repos/acme/web/check-runs/cr_1/annotations"), Op::Checks(ChecksOp::ListCheckRunAnnotations));
1358 assert_eq!(op("POST", "/repos/acme/web/check-suites/cs_1/rerequest"), Op::Checks(ChecksOp::RerequestCheckSuite));
1359 assert_eq!(op("GET", "/repos/acme/web/commits/main/check-suites"), Op::Checks(ChecksOp::ListCheckSuitesForRef));
1360 }
1361
1362 #[test]
API and MCP server in Rust; a public index at the API root1363 fn query_parameters_are_renamed() {
1364 let query = [
1365 ("q".to_owned(), "parser".to_owned()),
1366 ("x".to_owned(), "y".to_owned()),
1367 ];
Agents as a team: lifecycle, merge queue, billing and a new shell1368 let (route, input) = resolve("GET", "/repos", &query, Value::Null).unwrap();
API and MCP server in Rust; a public index at the API root1369 assert_eq!(route.op, Op::ListRepos);
1370 assert_eq!(input, json!({ "query": "parser" }));
1371 }
1372
1373 #[test]
1374 fn method_and_shape_must_match() {
Agents as a team: lifecycle, merge queue, billing and a new shell1375 assert!(resolve("GET", "/repos/a/b/issues/1/close", &[], Value::Null).is_none());
1376 assert!(resolve("GET", "/repos/a", &[], Value::Null).is_none());
1377 assert!(resolve("GET", "/repos/a/b/issues/1/extra", &[], Value::Null).is_none());
1378 assert!(resolve("GET", "/repos/a/b/", &[], Value::Null).is_some());
API and MCP server in Rust; a public index at the API root1379 }
1380
1381 #[test]
1382 fn every_parameter_and_query_name_is_an_input() {
1383 for route in ROUTES {
1384 let properties = route.op.properties();
1385 for (_, key) in route.query {
1386 assert!(properties.contains_key(*key), "{}: {key}", route.path);
1387 }
1388 for name in route.params() {
1389 let covered = matches!(name, "owner" | "name") && properties.contains_key("repo")
1390 || properties.contains_key(name);
1391 assert!(covered, "{}: {name}", route.path);
1392 }
1393 }
1394 }
1395
1396 #[test]
1397 fn every_operation_has_a_route() {
1398 for op in Op::ALL {
1399 assert!(ROUTES.iter().any(|route| route.op == op), "{}", op.name());
1400 }
1401 }
1402}

This file's history is long; its oldest lines are credited to the oldest commit read.