Skip to content
930 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs1import type { ActionsApi } from "./actions";
Billing accounts, terms and enterprises; g1t is no longer free2import type { BillingAdminApi, BillingApi } from "./billing";
Deployments: a preview for every pull request, production on g1t.page3import type { DeploymentsApi } from "./deployments";
Projects: what a workspace builds and runs, first on every page4import type { ProjectsApi } from "./projects";
Events service in Rust, with RFC 3339 times and accurate push events5import type { EventsApi } from "./events";
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace6import type { IdentityAdminApi, IdentityApi } from "./identity";
Integrations: your own model provider, alerts that open issues, tickets agents read7import type { IntegrationsApi } from "./integrations";
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member8import type { PackagesApi } from "./packages";
Webhooks: every event, to your own addresses, signed and retried9import type { WebhooksApi } from "./webhooks";
Rust repos service with shipping; pull requests kept in the model10import type { ReposApi } from "./repos";
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar11import type { PullDetail, WorkApi } from "./work";
12import type { Result } from "./result";
Fast pages, required checks on the branch, self-hosted runners, honest incidents13import type { RunnersApi } from "./runners";
API and MCP server, Rust identity service, registration, site redesign14
15/** A service binding, as far as these clients need it. */
16export type ServiceBinding = {
17 fetch(input: string, init?: RequestInit): Promise<Response>;
18};
19
20/**
21 * Calls a method on a service that speaks the JSON protocol used by the
22 * Rust services: `POST /rpc/<method>` with the arguments as the body.
23 */
24async function rpc<T>(
25 service: ServiceBinding,
26 method: string,
27 args: object,
28): Promise<T> {
29 // The hostname is ignored; a service binding always reaches its service.
30 const response = await service.fetch(`https://service/rpc/${method}`, {
31 method: "POST",
32 headers: { "content-type": "application/json" },
33 body: JSON.stringify(args),
34 });
35 if (!response.ok) {
36 throw new Error(`${method} failed with status ${response.status}`);
37 }
Agents as a team: lifecycle, merge queue, billing and a new shell38 return (await response.json()) as T;
API and MCP server, Rust identity service, registration, site redesign39}
40
41export function identityClient(service: ServiceBinding): IdentityApi {
42 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
43 return {
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look44 register: (username, email, password, inviteCode, client) =>
45 call("register", { username, email, password, invite_code: inviteCode ?? null, client: client ?? null }),
46 signIn: (username, password, client) => call("sign_in", { username, password, client: client ?? null }),
Merge main (membership, two-factor, GitHub repo roles) into tokens47 twoFactorSignIn: (challenge, code, client) => call("two_factor_sign_in", { challenge, code, client: client ?? null }),
API and MCP server, Rust identity service, registration, site redesign48 signOut: (sessionToken) => call("sign_out", { sessionToken }),
Email verification, password reset, and Git for AI scale positioning49 resendVerification: (user) => call("resend_verification", { user }),
50 verifyEmail: (token) => call("verify_email", { token }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look51 requestPasswordReset: (email, client) => call("request_password_reset", { email, client: client ?? null }),
Email verification, password reset, and Git for AI scale positioning52 resetPassword: (token, password) =>
53 call("reset_password", { token, password }),
Device sign-in replaces registering and minting tokens over the API54 deviceStart: (clientName) => call("device_start", { clientName }),
55 deviceLookup: (userCode) => call("device_lookup", { userCode }),
56 deviceResolve: (userCode, user, approve) =>
57 call("device_resolve", { userCode, user, approve }),
58 deviceClaim: (deviceCode) => call("device_claim", { deviceCode }),
OAuth 2.1 sign-in for MCP clients and other applications59 oauthAuthorize: (user, approval) => call("oauth_authorize", { user, ...approval }),
60 oauthExchange: (code, codeVerifier, clientId, redirectUri) =>
61 call("oauth_exchange", { code, codeVerifier, clientId, redirectUri }),
62 oauthRefresh: (refreshToken, clientId) =>
63 call("oauth_refresh", { refreshToken, clientId }),
64 listOAuthGrants: (user) => call("list_oauth_grants", { user }),
65 revokeOAuthGrant: (user, id) => call("revoke_oauth_grant", { user, id }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step66 updateOAuthGrant: (user, id, grant) =>
67 call("update_oauth_grant", { user, id, scopes: grant.scopes }),
Workspaces own repositories68 createWorkspace: (user, slug, name) => call("create_workspace", { user, slug, name }),
69 getWorkspace: (slug) => call("get_workspace", { slug }),
Merge branch 'worktree-agent-a2013627e5ea4ab13'70 workspaceResidency: (slug) => call("workspace_residency", { slug }),
71 setWorkspaceResidency: (actor, slug, residency) => call("set_workspace_residency", { actor, slug, residency }),
Workspaces own repositories72 listMembers: (slug, viewer) => call("list_members", { slug, viewer }),
73 addMember: (actor, slug, username) => call("add_member", { actor, slug, username }),
74 removeMember: (actor, slug, username) =>
Merge main (membership, two-factor, GitHub repo roles) into tokens75 call("remove_member", { actor, slug, username, surface: "web" }),
76 updateMember: (actor, slug, username, change) =>
77 call("update_member", { actor, slug, username, role: change.role ?? null, org_roles: change.org_roles ?? null, surface: "web" }),
78 transferOwnership: (actor, slug, username) => call("transfer_ownership", { actor, slug, username, surface: "web" }),
79 leaveWorkspace: (user, slug) => call("leave_workspace", { user, slug, surface: "web" }),
80 setMemberPrivileges: (actor, slug, change) => call("set_member_privileges", { actor, slug, privileges: change, surface: "web" }),
81 setTwoFactorRequirement: (actor, slug, required) =>
82 call("set_two_factor_requirement", { actor, slug, required, surface: "web" }),
Agents as a team: lifecycle, merge queue, billing and a new shell83 updateWorkspace: (actor, slug, details) =>
84 call("update_workspace", { actor, slug, ...details }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains85 renameWorkspace: (actor, slug, newSlug) => call("rename_workspace", { actor, slug, newSlug }),
86 checkWorkspaceRename: (actor, slug, newSlug) =>
87 call("check_workspace_rename", { actor, slug, newSlug }),
88 resolveSlug: (slug) => call("resolve_slug", { slug }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look89 deleteWorkspace: (actor, slug, confirm) => call("delete_workspace", { actor, slug, confirm }),
90 checkWorkspaceDeletion: (actor, slug) => call("check_workspace_deletion", { actor, slug }),
Workspace names and icons, and a component kit for every control91 setWorkspaceAvatar: (actor, slug, image) => call("set_workspace_avatar", { actor, slug, image }),
92 setUserAvatar: (user, image) => call("set_user_avatar", { user, image }),
Agents as a team: lifecycle, merge queue, billing and a new shell93 listWorkspaceTokens: (slug, viewer) => call("list_workspace_tokens", { slug, viewer }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step94 createWorkspaceToken: (actor, slug, name, grant) =>
95 call("create_workspace_token", {
96 actor,
97 slug,
98 name,
99 scopes: grant?.scopes ?? null,
100 ttl_seconds: grant?.ttlSeconds ?? null,
Settings: fine-grained tokens, workspace token Admin, workspace personal access token rules101 admin: grant?.admin ?? false,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step102 }),
Agents as a team: lifecycle, merge queue, billing and a new shell103 removeWorkspaceToken: (actor, slug, id) =>
104 call("remove_workspace_token", { actor, slug, id }),
Settings: fine-grained tokens, workspace token Admin, workspace personal access token rules105 createFineGrainedToken: (user, input) =>
106 call("create_fine_grained_token", {
107 user,
108 name: input.name,
109 description: input.description ?? null,
110 ttl_seconds: input.ttlSeconds,
111 workspace: input.workspace,
112 repository_selection: input.repositorySelection,
113 repositories: input.repositories,
114 permissions: input.permissions,
115 }),
116 updateFineGrainedToken: (user, id, change) =>
117 call("update_fine_grained_token", {
118 user,
119 id,
120 name: change.name ?? null,
121 description: change.description ?? null,
122 repository_selection: change.repositorySelection ?? null,
123 repositories: change.repositories ?? null,
124 permissions: change.permissions ?? null,
125 }),
126 getTokenPolicy: (slug, viewer) => call("get_token_policy", { slug, viewer }),
127 setTokenPolicy: (actor, slug, change) =>
128 call("set_token_policy", {
129 actor,
130 slug,
131 allow_classic: change.allowClassic ?? null,
132 allow_fine_grained: change.allowFineGrained ?? null,
133 require_approval: change.requireApproval ?? null,
134 max_lifetime_days: change.maxLifetimeDays ?? null,
135 forbid_no_expiry: change.forbidNoExpiry ?? null,
136 surface: "web",
137 }),
138 listMemberTokens: (actor, slug, filter = {}) =>
139 call("list_member_tokens", { actor, slug, status: filter.status ?? null, kind: filter.kind ?? null }),
140 reviewTokenRequest: (actor, slug, id, approve, reason) =>
141 call("review_token_request", { actor, slug, id, approve, reason: reason ?? null, surface: "web" }),
142 revokeMemberToken: (actor, slug, id, reason) =>
143 call("revoke_member_token", { actor, slug, id, reason: reason ?? null, surface: "web" }),
API and MCP server, Rust identity service, registration, site redesign144 userForSession: (sessionToken) => call("user_for_session", { sessionToken }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look145 registration: () => call("registration", {}),
146 listInvites: (user) => call("list_invites", { user }),
147 createInvite: (user, options = {}) =>
148 call("create_invite", { user, email: options.email ?? null, workspace: options.workspace ?? null }),
149 revokeInvite: (user, id) => call("revoke_invite", { user, id }),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas150 checkInvite: (code, client, options = {}) =>
151 call("check_invite", {
152 code,
153 client: client ?? null,
154 viewer: options.viewer ?? null,
155 any_status: options.anyStatus ?? false,
156 }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look157 acceptInvite: (user, code) => call("accept_invite", { user, code }),
158 inviteMember: (actor, slug, email) => call("invite_member", { actor, slug, email }),
159 workspaceInvites: (slug, viewer) => call("workspace_invites", { slug, viewer }),
160 revokeWorkspaceInvite: (actor, slug, id) => call("revoke_workspace_invite", { actor, slug, id }),
161 requestAccess: (email, about, client) => call("request_access", { email, about, client: client ?? null }),
API and MCP server, Rust identity service, registration, site redesign162 userForGitCredentials: (username, secret) =>
163 call("user_for_git_credentials", { username, secret }),
164 userForAccessToken: (token) => call("user_for_access_token", { token }),
165 userForSshKey: (fingerprint) => call("user_for_ssh_key", { fingerprint }),
166 userByUsername: (username) => call("user_by_username", { username }),
What happened across an outcome, as a feed beside its graph167 usernames: (ids) => call("usernames", { ids }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains168 profile: (username) => call("profile", { username }),
169 updateProfile: (actor, fields) => call("update_profile", { actor, ...fields }),
170 profileWorkspaces: (username, viewer, publicIn) =>
171 call("profile_workspaces", { username, viewer, public: publicIn }),
API and MCP server, Rust identity service, registration, site redesign172 listSshKeys: (user) => call("list_ssh_keys", { user }),
173 addSshKey: (user, title, publicKey) =>
174 call("add_ssh_key", { user, title, publicKey }),
175 removeSshKey: (user, id) => call("remove_ssh_key", { user, id }),
176 listAccessTokens: (user) => call("list_access_tokens", { user }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step177 createAccessToken: (user, name, ttlSeconds, grant) =>
178 call("create_access_token", {
179 user,
180 name,
181 ttlSeconds,
182 scopes: grant?.scopes ?? null,
183 listed: grant?.listed ?? false,
184 }),
185 updateAccessToken: (user, id, grant) =>
186 call("update_access_token", { user, id, scopes: grant.scopes }),
Agents as a team: lifecycle, merge queue, billing and a new shell187 createAgentToken: (onBehalfOf, scope, ttlSeconds) =>
188 call("create_agent_token", { onBehalfOf, scope, ttlSeconds }),
API and MCP server, Rust identity service, registration, site redesign189 removeAccessToken: (user, id) => call("remove_access_token", { user, id }),
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API190 createRunCredential: (input) => call("create_run_credential", input),
191 bindRunCredentials: (tokenHashes, runId) => call("bind_run_credentials", { tokenHashes, runId }),
192 revokeRunCredentials: (target) => call("revoke_run_credentials", target),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look193 // Who has access to a repository; see access.ts.
194 repoAccess: (owner, name, viewer) => call("repo_access", { viewer, path: { namespace: owner, name } }),
195 addCollaborator: (actor, owner, name, invitee, role) =>
196 call("add_collaborator", { actor, path: { namespace: owner, name }, invitee, role }),
197 setCollaboratorRole: (actor, owner, name, username, role) =>
198 call("set_collaborator_role", { actor, path: { namespace: owner, name }, username, role }),
199 removeCollaborator: (actor, owner, name, username) =>
200 call("remove_collaborator", { actor, path: { namespace: owner, name }, username }),
201 collaboratorPermission: (viewer, owner, name, username) =>
202 call("collaborator_permission", { viewer, path: { namespace: owner, name }, username }),
203 myRepoInvitations: (user) => call("my_repo_invitations", { user }),
204 respondRepoInvitation: (user, id, accept) => call("respond_repo_invitation", { user, id, accept }),
205 revokeRepoInvitation: (actor, owner, name, id) =>
206 call("revoke_repo_invitation", { actor, path: { namespace: owner, name }, id }),
207 setBasePermission: (actor, slug, base) => call("set_base_permission", { actor, slug, base_permission: base }),
208 outsideCollaborators: (viewer, slug) => call("outside_collaborators", { viewer, slug }),
Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca209 // A repository's deploy keys; see deploy-keys.ts.
210 listDeployKeys: (viewer, owner, name) => call("list_deploy_keys", { viewer, path: { namespace: owner, name } }),
211 addDeployKey: (actor, owner, name, key) =>
212 call("add_deploy_key", { actor, path: { namespace: owner, name }, title: key.title, key: key.key, read_only: key.readOnly }),
213 removeDeployKey: (actor, owner, name, id) => call("remove_deploy_key", { actor, path: { namespace: owner, name }, id }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar214 // Teams; see teams.ts.
215 listTeams: (viewer, workspace, query) => call("list_teams", { viewer, workspace, query: query ?? null }),
216 getTeam: (viewer, workspace, team) => call("get_team", { viewer, workspace, team }),
217 createTeam: (actor, workspace, team) => call("create_team", { actor, workspace, ...team }),
Merge branch 'worktree-agent-ad7c6d88d93adc817'218 setTeamCreation: (actor, slug, setting) => call("set_team_creation", { actor, slug, team_creation: setting }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar219 updateTeam: (actor, workspace, team, changes) => call("update_team", { actor, workspace, team, ...changes }),
220 deleteTeam: (actor, workspace, team) => call("delete_team", { actor, workspace, team }),
221 teamMembers: (viewer, workspace, team, includeChildTeams) =>
222 call("team_members", { viewer, workspace, team, include_child_teams: includeChildTeams ?? false }),
223 setTeamMember: (actor, workspace, team, username, role) =>
224 call("set_team_member", { actor, workspace, team, username, role }),
225 removeTeamMember: (actor, workspace, team, username) =>
226 call("remove_team_member", { actor, workspace, team, username }),
227 childTeams: (viewer, workspace, team) => call("child_teams", { viewer, workspace, team }),
228 teamRepos: (viewer, workspace, team) => call("team_repos", { viewer, workspace, team }),
229 setTeamRepo: (actor, workspace, team, owner, name, role) =>
230 call("set_team_repo", { actor, workspace, team, repo: { namespace: owner, name }, role }),
231 removeTeamRepo: (actor, workspace, team, owner, name) =>
232 call("remove_team_repo", { actor, workspace, team, repo: { namespace: owner, name } }),
233 userTeams: (viewer, workspace, username) => call("user_teams", { viewer, workspace, username }),
234 teamMemberships: (viewer, workspace) => call("team_memberships", { viewer, workspace }),
API and MCP server, Rust identity service, registration, site redesign235 };
236}
Rust repos service with shipping; pull requests kept in the model237
Agents and memory, checks and conflicts, profiles, slug renames, custom domains238/**
239 * The slug a renamed workspace has now, for a `workspace.renamed` handler:
240 * asked of identity by the workspace's id, so that renames delivered twice
241 * or out of order converge. Falls back to the event's `to`.
242 */
243export async function currentWorkspaceSlug(
244 identity: ServiceBinding,
245 renamed: { workspaceId: string; to: string },
246): Promise<string> {
247 const names = await identityClient(identity).usernames([renamed.workspaceId]);
248 return names[renamed.workspaceId] ?? renamed.to;
249}
250
251/** The slugs whose rows move to `current`: the two a rename names, less `current`. */
252export function staleSlugs(renamed: { from: string; to: string }, current: string): string[] {
253 return [...new Set([renamed.from, renamed.to])].filter((slug) => slug !== current);
254}
255
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look256/**
257 * Where a transferred repository is now, as `namespace/name`, for a
258 * `repo.transferred` handler: asked of repos by id, so transfers delivered
259 * twice or out of order converge. Falls back to the event's destination.
260 */
261export async function currentRepoPath(
262 repos: ServiceBinding,
263 transferred: { repoId: string; name: string; to: string },
264): Promise<string> {
265 const path = await rpc<{ namespace: string; name: string } | null>(repos, "path_by_id", { id: transferred.repoId });
266 return path ? `${path.namespace}/${path.name}` : `${transferred.to}/${transferred.name}`;
267}
268
269/** The paths whose rows move to `current`: the two a transfer names, less `current`. */
270export function stalePaths(transferred: { name: string; from: string; to: string }, current: string): string[] {
271 return [...new Set([transferred.from, transferred.to].map((ns) => `${ns}/${transferred.name}`))].filter(
272 (path) => path !== current,
273 );
274}
275
276/**
277 * A repository's path change, from `repo.transferred` or `repo.renamed`,
278 * read the same way: the two paths (`namespace/name`) the event names, old
279 * then new. Null for any other event.
280 */
281export type RepoMove = { repoId: string; paths: [string, string] };
282
283export function repoMove(event: { type: string; data: unknown }): RepoMove | null {
284 const data = event.data as Record<string, string>;
285 if (event.type === "repo.transferred") {
286 return { repoId: data.repoId!, paths: [`${data.from}/${data.name}`, `${data.to}/${data.name}`] };
287 }
288 if (event.type === "repo.renamed") {
289 return { repoId: data.repoId!, paths: [`${data.namespace}/${data.from}`, `${data.namespace}/${data.to}`] };
290 }
291 return null;
292}
293
294/**
295 * Where a moved repository is now, as `namespace/name`: asked of repos by
296 * id, so moves delivered twice or out of order converge. Falls back to the
297 * event's new path.
298 */
299export async function currentMovedPath(repos: ServiceBinding, move: RepoMove): Promise<string> {
300 const path = await rpc<{ namespace: string; name: string } | null>(repos, "path_by_id", { id: move.repoId });
301 return path ? `${path.namespace}/${path.name}` : move.paths[1];
302}
303
304/** The paths whose rows move to `current`: the two a move names, less `current`. */
305export function staleMovedPaths(move: RepoMove, current: string): string[] {
306 return [...new Set(move.paths)].filter((path) => path !== current);
307}
308
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace309/** Staff-only identity. Only sudo binds to it; see `IdentityAdminApi`. */
310export function identityAdminClient(service: ServiceBinding): IdentityAdminApi {
311 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
312 return {
313 workspaces: (query) => call("admin_workspaces", { query: query ?? null }),
314 workspace: (slug) => call("admin_workspace", { slug }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look315 waitlist: (query, status) => call("admin_waitlist", { query: query ?? null, status: status ?? null }),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas316 waitlistPending: () => call("admin_waitlist_pending", {}),
317 decideWaitlist: (id, approve, staff, note) => call("admin_decide_waitlist", { id, approve, staff, note: note ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look318 invites: (query) => call("admin_invites", { query: query ?? null }),
319 revokeInvite: (id, staff) => call("admin_revoke_invite", { id, staff }),
320 mintInvite: (email, staff) => call("admin_mint_invite", { email, staff }),
321 grantInvites: (target, name, amount, note, staff) =>
322 call("admin_grant_invites", { target, name, amount, note, staff }),
323 inviteTree: (username) => call("admin_invite_tree", { username }),
324 workspaceInvites: (slug) => call("admin_workspace_invites", { slug }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member325 deletedWorkspaces: () => call("admin_deleted_workspaces", {}),
326 restoreWorkspace: (workspaceId, staff) => call("admin_restore_workspace", { workspaceId, staff }),
327 purgeWorkspace: (workspaceId, staff, confirm) => call("admin_purge_workspace", { workspaceId, staff, confirm }),
Merge branch 'worktree-agent-a8385d293d42c913a'328 aliases: () => call("admin_aliases", {}),
329 setAlias: (alias, workspace, note, staff) => call("admin_set_alias", { alias, workspace, note, staff }),
330 removeAlias: (alias, reason, staff) => call("admin_remove_alias", { alias, reason, staff }),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace331 };
332}
333
Rust repos service with shipping; pull requests kept in the model334export function reposClient(service: ServiceBinding): ReposApi {
335 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
336 return {
337 get: (path, viewer) => call("get", { path, viewer }),
338 getById: (id, viewer) => call("get_by_id", { id, viewer }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents339 readable: (ids, viewer) => call("readable", { ids, viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains340 publicNamespaces: (ownerId) => call("public_namespaces", { ownerId }),
Rust repos service with shipping; pull requests kept in the model341 list: (viewer, options = {}) => call("list", { viewer, ...options }),
342 create: (owner, input) => call("create", { owner, ...input }),
Agents as a team: lifecycle, merge queue, billing and a new shell343 update: (actor, path, changes) => call("update", { actor, path, ...changes }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look344 transfer: (actor, path, to) => call("transfer", { actor, path, to }),
345 delete: (actor, path, confirm) => call("delete", { actor, path, confirm }),
346 deleted: (viewer, namespace) => call("deleted", { viewer, namespace }),
347 restore: (actor, path) => call("restore", { actor, path }),
348 purge: (actor, path, confirm) => call("purge", { actor, path, confirm }),
349 rename: (actor, path, name) => call("rename", { actor, path, name }),
350 archive: (actor, path, archived) => call("archive", { actor, path, archived }),
351 setVisibility: (actor, path, isPrivate, confirm) => call("set_visibility", { actor, path, isPrivate, confirm }),
352 setDefaultBranch: (actor, path, branch) => call("set_default_branch", { actor, path, branch }),
353 renameBranch: (actor, path, from, to) => call("rename_branch", { actor, path, from, to }),
354 resolveBranch: (repoId, branch) => call("resolve_branch", { repoId, branch }),
355 statusById: (id) => call("status_by_id", { id }),
Merge branch 'worktree-agent-a2013627e5ea4ab13'356 storageOptions: () => call("storage_options", {}),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look357 resolvePath: (path) => call("resolve_path", { path }),
Rust repos service with shipping; pull requests kept in the model358 tree: (path, viewer, ref, treePath) =>
359 call("tree", { path, viewer, ref, treePath }),
360 blob: (path, viewer, ref, filePath) =>
361 call("blob", { path, viewer, ref, filePath }),
362 log: (path, viewer, ref, limit) => call("log", { path, viewer, ref, limit }),
Agents as a team: lifecycle, merge queue, billing and a new shell363 blame: (path, viewer, ref, filePath) => call("blame", { path, viewer, ref, filePath }),
Issues and pull requests replace intents and attempts364 forkForPull: (sourceId, pullId, actor) =>
365 call("fork_for_pull", { sourceId, pullId, actor }),
Rust repos service with shipping; pull requests kept in the model366 gitAccess: (path, viewer, service) =>
367 call("git_access", { path, viewer, service }),
Pull requests from branches368 branches: (path, viewer) => call("branches", { path, viewer }),
Branches and Tags pages, each file's last commit, and the branch menu on files369 lastCommits: (path, viewer, ref, treePath) => call("last_commits", { path, viewer, ref, treePath }),
370 tags: (path, viewer) => call("tags", { path, viewer }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97371 about: (path, viewer) => call("about", { path, viewer }),
372 languages: (path, viewer) => call("languages", { path, viewer }),
373 contributors: (path, viewer) => call("contributors", { path, viewer }),
374 license: (path, viewer) => call("license", { path, viewer }),
375 stars: (path, viewer) => call("stars", { path, viewer }),
376 star: (actor, path, starred) => call("star", { path, actor, starred }),
377 stargazers: (path, viewer, page) => call("stargazers", { path, viewer, page: page ?? null }),
378 starred: (username, viewer) => call("starred", { username, viewer }),
379 releases: (path, viewer) => call("releases", { path, viewer }),
380 release: (path, viewer, which) => call("release", { path, viewer, id: which.id ?? null, tag: which.tag ?? null, latest: which.latest ?? false }),
381 createRelease: (actor, path, release) => call("create_release", { path, actor, ...release }),
382 updateRelease: (actor, path, id, change) => call("update_release", { path, actor, id, ...change }),
383 deleteRelease: (actor, path, id) => call("delete_release", { path, actor, id }),
Download ZIP from the Code button; a slimmer lifecycle panel; agent steps say what was done, not sandbox paths384 listFiles: (repoId, ref, limit) => call("list_files", { repoId, ref, skipDirs: [], limit }),
385 rawBlobs: (repoId, hashes, maxBytes) => call("raw_blobs", { repoId, hashes, maxBytes }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents386 commitFile: (repo, actor, file) => call("commit_file", { repo, actor, ...file }),
Pull requests from branches387 land: (sourceId, actor, branch) => call("land", { sourceId, actor, branch }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar388 compare: (repoId, viewer, base, head, baseBranch) => call("compare", { repoId, viewer, base, head, baseBranch }),
Merge branch 'worktree-agent-ac5b181a013e54348'389 claimBackups: (limit, maxRunning) => call("claim_backups", { limit, maxRunning }),
390 // The sandbox's own calls are snake_case (they come through the API).
391 failBackup: (jobId, token, error) => call("backup_fail", { job_id: jobId, token, error }),
Rust repos service with shipping; pull requests kept in the model392 };
393}
Work service in Rust, with RFC 3339 timestamps394
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar395/**
396 * `PullDetail`'s own fields that the work service writes in snake_case:
397 * `g1t_contracts::work::PullDetail` has no camelCase renaming, though what
398 * it holds (`Pull`, `CheckRun` and the rest) does. Each with its name here.
399 */
400const PULL_DETAIL_FIELDS = [
401 ["review_pending", "reviewPending"],
402 ["earlier_checks", "earlierChecks"],
403 ["required_checks", "requiredChecks"],
404 ["code_owners", "codeOwners"],
405] as const;
406
407/**
408 * A pull request's detail as the work service sent it, with its own fields
409 * in the camelCase this package uses: read at the edge, by `workClient`'s
410 * `getPull`. Either spelling is taken, so a service that already sends
411 * camelCase reads the same.
412 */
413export function pullDetailFromWire(raw: Record<string, unknown>): PullDetail {
414 const detail: Record<string, unknown> = { ...raw };
415 for (const [snake, camel] of PULL_DETAIL_FIELDS) {
416 if (snake in detail) {
417 if (!(camel in detail)) detail[camel] = detail[snake];
418 delete detail[snake];
419 }
420 }
421 if (typeof detail.reviewPending !== "boolean") detail.reviewPending = false;
422 return detail as PullDetail;
423}
424
Work service in Rust, with RFC 3339 timestamps425export function workClient(service: ServiceBinding): WorkApi {
426 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
427 return {
Issues and pull requests replace intents and attempts428 openIssue: (actor, repo, input) => call("open_issue", { actor, repo, ...input }),
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step429 delegateIssue: (actor, repo, input) => call("delegate_issue", { actor, repo, ...input }),
Issues and pull requests replace intents and attempts430 listIssues: (repo, viewer, filter = {}) => call("list_issues", { repo, viewer, ...filter }),
431 getIssue: (repo, number, viewer) => call("get_issue", { repo, number, viewer }),
432 updateIssue: (actor, repo, number, input) =>
433 call("update_issue", { actor, repo, number, ...input }),
434 closeIssue: (actor, repo, number, reason) =>
435 call("close_issue", { actor, repo, number, reason }),
436 reopenIssue: (actor, repo, number) => call("reopen_issue", { actor, repo, number }),
437 listLabels: (repo, viewer) => call("list_labels", { repo, viewer }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar438 saveLabel: (actor, repo, label) => call("save_label", { actor, repo, ...label }),
439 deleteLabel: (actor, repo, name) => call("delete_label", { actor, repo, name }),
440 addDefaultLabels: (actor, repo) => call("add_default_labels", { actor, repo }),
441 setLabels: (actor, repo, number, labels, change = "set") =>
442 call("set_labels", { actor, repo, number, labels, change }),
443 listMilestones: (repo, viewer, state) => call("list_milestones", { repo, viewer, state }),
444 getMilestone: (repo, number, viewer) => call("get_milestone", { repo, number, viewer }),
445 saveMilestone: (actor, repo, milestone) => call("save_milestone", { actor, repo, ...milestone }),
446 deleteMilestone: (actor, repo, number) => call("delete_milestone", { actor, repo, number }),
Issues and pull requests replace intents and attempts447 counts: (repo, viewer) => call("counts", { repo, viewer }),
Acceptance checks in sandboxes, line comments and review verdicts448 addComment: (actor, repo, number, comment) =>
449 call("add_comment", { actor, repo, number, ...comment }),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts450 editComment: (actor, repo, commentId, body) => call("edit_comment", { actor, repo, commentId, body }),
451 deleteComment: (actor, repo, commentId) => call("delete_comment", { actor, repo, commentId }),
Acceptance checks in sandboxes, line comments and review verdicts452 startChecks: (pullId) => call("start_checks", { pullId }),
453 reportChecks: (runId, token, report) =>
454 call("report_checks", { runId, token, ...report }),
Agents as a team: lifecycle, merge queue, billing and a new shell455 startReview: (pullId) => call("start_review", { pullId }),
456 failReview: (runId, token, error) => call("report_review", { runId, token, error }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains457 startMergecheck: (pullId) => call("start_mergecheck", { pullId }),
458 failMergecheck: (pullId, token, error) => call("report_mergecheck", { pullId, token, error }),
Agents as a team: lifecycle, merge queue, billing and a new shell459 advance: (pullId) => call("advance", { pullId }),
460 stall: (pullId, reason) => call("stall", { pullId, reason }),
461 managedPulls: (repoId) => call("managed_pulls", { repoId }),
462 queue: (repo, viewer) => call("queue", { repo, viewer }),
463 queueBuild: (repoId) => call("queue_build", { repoId }),
464 failQueue: (entryId, token, error) => call("report_queue", { entryId, token, error }),
465 removeFromQueue: (actor, repo, number) => call("remove_from_queue", { actor, repo, number }),
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request466 messageAgent: (actor, repo, number, body) => call("message_agent", { actor, repo, number, body }),
Agents as a team: lifecycle, merge queue, billing and a new shell467 catchUpJob: (pullId) => call("catch_up_job", { pullId }),
Agents asked while not at work are woken to answer468 wakeForMessages: (pullId) => call("wake_for_messages", { pullId }),
Agents as a team: lifecycle, merge queue, billing and a new shell469 getSettings: (repo, viewer) => call("get_settings", { repo, viewer }),
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge470 // Rulesets travel in snake_case (rules.ts).
471 listRulesets: (owner, viewer, includeParents = false) =>
472 call("list_rulesets", { viewer, ...owner, include_parents: includeParents }),
473 getRuleset: (owner, id, viewer) => call("get_ruleset", { viewer, ...owner, id }),
474 saveRuleset: (actor, owner, ruleset, id) => call("save_ruleset", { actor, ...owner, id: id ?? null, ruleset }),
475 deleteRuleset: (actor, owner, id) => call("delete_ruleset", { actor, ...owner, id }),
476 effectiveRules: (repo, name, viewer, target = "branch") => call("effective_rules", { viewer, repo, name, target }),
477 ruleEvaluations: (owner, viewer, filter = {}) => call("rule_evaluations", { viewer, ...owner, ...filter }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents478 seenChecks: (repo, viewer) => call("seen_checks", { repo, viewer }),
Merge checks: statuses and check runs on every commit479 commitChecks: (repo, viewer, shas) => call("commit_checks", { repo, viewer, shas }),
480 getCheckRun: (repo, id, viewer) => call("get_check_run", { repo, id, viewer }),
481 checkRunAnnotations: (repo, id, viewer) => call("check_run_annotations", { repo, id, viewer }),
482 requestCheckAction: (actor, repo, id, identifier) => call("request_check_action", { actor, repo, id, identifier }),
483 rerequestCheckRun: (actor, repo, id) => call("rerequest_check_run", { actor, repo, id }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar484 codeownersErrors: (repo, viewer, ref) => call("codeowners_errors", { repo, viewer, ref: ref ?? null }),
Agents as a team: lifecycle, merge queue, billing and a new shell485 updateSettings: (actor, repo, settings) =>
486 call("update_settings", { actor, repo, settings }),
Issues and pull requests replace intents and attempts487 openPull: (actor, repo, input) => call("open_pull", { actor, repo, ...input }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar488 listPulls: (repo, viewer, state, filter = {}) => call("list_pulls", { repo, viewer, state, ...filter }),
Fast pages, required checks on the branch, self-hosted runners, honest incidents489 pullsForRepos: (repoIds, viewer, limit) => call("pulls_for_repos", { repoIds, viewer, limit }),
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar490 // Its own fields arrive in snake_case: read into camelCase here.
491 getPull: (repo, number, viewer) =>
492 call<Result<Record<string, unknown>>>("get_pull", { repo, number, viewer }).then(
493 (found): Result<PullDetail> => (found.ok ? { ok: true, value: pullDetailFromWire(found.value) } : found),
494 ),
Agents as a team: lifecycle, merge queue, billing and a new shell495 updatePull: (actor, repo, number, changes) =>
496 call("update_pull", { actor, repo, number, ...changes }),
Catching up with main takes seconds when the two sides touched different files497 catchUpPull: (actor, repo, number) => call("catch_up_pull", { actor, repo, number }),
Issues and pull requests replace intents and attempts498 readyPull: (actor, repo, number, summary) =>
499 call("ready_pull", { actor, repo, number, summary }),
500 closePull: (actor, repo, number) => call("close_pull", { actor, repo, number }),
Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts501 reopenPull: (actor, repo, number) => call("reopen_pull", { actor, repo, number }),
502 convertPullToDraft: (actor, repo, number) => call("convert_pull_to_draft", { actor, repo, number }),
Acceptance checks in sandboxes, line comments and review verdicts503 mergePull: (actor, repo, number, options = {}) =>
504 call("merge_pull", { actor, repo, number, ...options }),
Issues and pull requests replace intents and attempts505 listActivePulls: (viewer) => call("list_active_pulls", { viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains506 byAuthor: (username, viewer, filter = {}) => call("by_author", { username, viewer, ...filter }),
Agents as a team: lifecycle, merge queue, billing and a new shell507 startPlan: (actor, repo, brief) => call("start_plan", { actor, repo, brief }),
508 failPlan: (planId, token, error) => call("report_plan", { planId, token, error }),
509 getPlan: (repo, viewer, id) => call("get_plan", { repo, viewer, id }),
510 listPlans: (repo, viewer) => call("list_plans", { repo, viewer }),
511 applyPlan: (actor, repo, id, options = {}) =>
512 call("apply_plan", { actor, repo, id, ...options }),
513 queueIssue: (actor, repo, number, queued) =>
514 call("queue_issue", { actor, repo, number, queued }),
515 readyIssues: (repoId) => call("ready_issues", { repoId }),
516 listAssignedIssues: (viewer) => call("list_assigned_issues", { viewer }),
Issues and pull requests replace intents and attempts517 appendSession: (actor, repo, number, entries) =>
518 call("append_session", { actor, repo, number, entries }),
519 readSession: (repo, number, viewer, afterSeq = 0) =>
520 call("read_session", { repo, number, viewer, afterSeq }),
Work service in Rust, with RFC 3339 timestamps521 };
522}
Events service in Rust, with RFC 3339 times and accurate push events523
Agents as a team: lifecycle, merge queue, billing and a new shell524export function billingClient(service: ServiceBinding): BillingApi {
525 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
526 return {
527 status: () => call("status", {}),
528 account: (workspace, viewer) => call("account", { workspace, viewer }),
529 ledger: (workspace, viewer) => call("ledger", { workspace, viewer }),
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging530 credits: (workspace, viewer) => call("credits", { workspace, viewer }),
The statement is a month at a time, a line per kind of charge531 statement: (workspace, viewer, month = null, group = "day") => call("statement", { workspace, viewer, month, group }),
532 statementEntries: (workspace, viewer, filter) =>
533 call("statement_entries", {
534 workspace,
535 viewer,
536 month: filter.month,
537 kind: filter.kind,
538 day: filter.day ?? null,
539 project: filter.project ?? null,
540 before: filter.before ?? null,
541 }),
Usage, like a hosting provider's: what agents cost, per day, task, repository and pull request542 usage: (workspace, viewer, since) => call("usage", { workspace, viewer, since }),
Mission control shows model usage, yours and the workspace's: tokens, cost, active days, cache share, each day, and the mix543 tokenUsage: (workspace, viewer, options = {}) =>
544 call("token_usage", { workspace, viewer, person: options.person ?? null, days: options.days ?? null }),
545 recordTokens: (usage) => call("record_tokens", usage),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens546 gatewayModels: () => call("gateway_models", {}),
Merge branch 'main' into actions-toolkit-oidc-artifacts547 modelDefaults: () => call("model_defaults", {}),
548 recordDiscovery: (provider, models, by, error = null) => call("record_discovery", { provider, models, by, error }),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens549 gatewayAdmit: (workspace) => call("gateway_admit", { workspace }),
550 recordGateway: (record) => call("record_gateway", record),
551 gatewayRequests: (workspace, viewer, options = {}) =>
552 call("gateway_requests", { workspace, viewer, limit: options.limit ?? null, before: options.before ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look553 checkout: (actor, workspace, amountCents, returnUrl, method = "card") =>
554 call("checkout", { actor, workspace, amountCents, returnUrl, method }),
Agents as a team: lifecycle, merge queue, billing and a new shell555 confirm: (workspace, viewer, session) => call("confirm", { workspace, viewer, session }),
556 canStart: (workspace) => call("can_start", { workspace }),
A free allowance on g1t's models, so anyone can try its agents557 trial: (workspace, exempt) => call("trial", { workspace, exempt }),
Agents as a team: lifecycle, merge queue, billing and a new shell558 startRun: (run) => call("start_run", run),
Paid features: a workspace turns on Deployments with a monthly plan559 features: (workspace, viewer) => call("features", { workspace, viewer }),
560 subscribe: (actor, workspace, feature, returnUrl) =>
561 call("subscribe", { actor, workspace, feature, returnUrl }),
562 confirmSubscription: (workspace, viewer, session) =>
563 call("confirm_subscription", { workspace, viewer, session }),
564 cancelSubscription: (actor, workspace, feature, resume = false) =>
565 call("cancel_subscription", { actor, workspace, feature, resume }),
566 hasFeature: (workspace, feature) => call("has_feature", { workspace, feature }),
Merge Stripe Tax, the card fee on card payments, and one free workspace per person567 freeWorkspaces: (workspaces) => call("free_workspaces", { workspaces }),
Paid features: a workspace turns on Deployments with a monthly plan568 chargeFeature: (charge) => call("charge_feature", charge),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace569 billingPortal: (actor, workspace, returnUrl) => call("billing_portal", { actor, workspace, return_url: returnUrl }),
Every sandbox is metered by the second570 recordSandbox: (usage) => call("record_sandbox", usage),
Usage limits: unpaid usage can only go so far571 limit: (workspace, viewer) => call("limit", { workspace, viewer }),
572 checkLimit: (workspace) => call("check_limit", { workspace }),
Prices keep themselves current with what g1t pays573 prices: () => call("prices", {}),
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas574 notePending: (workspace, source, costMicros, detail = null) => call("note_pending", { workspace, source, costMicros, detail }),
575 usageMeters: (workspace, viewer) => call("usage_meters", { workspace, viewer }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look576 setSpendLimit: (actor, workspace, spendLimitMicros, useFullLimit = false, raiseOnce = false) =>
577 call("set_spend_limit", { actor, workspace, spendLimitMicros, use_full_limit: useFullLimit, raise_once: raiseOnce }),
Two limits, real invoices, trust that grows by itself, sales signals578 invoices: (workspace, viewer) => call("invoices", { workspace, viewer }),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put579 entitlements: (workspace) => call("entitlements", { workspace }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look580 reserve: (reservation) => call("reserve", reservation),
581 settle: (reservationId, actualMicros) => call("settle", { reservationId, actualMicros }),
582 cardCheck: (actor, workspace, returnUrl) => call("card_check", { actor, workspace, returnUrl }),
583 confirmCardCheck: (workspace, viewer, session) => call("confirm_card_check", { workspace, viewer, session }),
584 requestLimit: (actor, workspace, request) => call("request_limit", { actor, workspace, ...request }),
585 limitRequests: (workspace, viewer) => call("limit_requests", { workspace, viewer }),
586 confirmSpike: (actor, workspace, keepGoing) => call("confirm_spike", { actor, workspace, keepGoing }),
587 setCaps: (actor, workspace, caps) => call("set_caps", { actor, workspace, ...caps }),
Usage, Billing settings and prepaid AI credit; fixes from the UX audit588 usageReport: (workspace, viewer, range) =>
589 call("usage_report", { workspace, viewer, from: range.from, until: range.until, products: range.products ?? [], projects: range.projects ?? [] }),
590 aiCredit: (workspace, viewer) => call("ai_credit", { workspace, viewer }),
591 buyAiCredit: (actor, workspace, amountCents, returnUrl) => call("buy_ai_credit", { actor, workspace, amountCents, returnUrl }),
592 confirmAiCredit: (workspace, viewer, session) => call("confirm_ai_credit", { workspace, viewer, session }),
593 setAiReload: (actor, workspace, reload) => call("set_ai_reload", { actor, workspace, ...reload }),
594 setBudget: (actor, workspace, budget) => call("set_budget", { actor, workspace, ...budget }),
595 billingDetails: (workspace, viewer) => call("billing_details", { workspace, viewer }),
596 setBillingDetails: (actor, workspace, details) => call("set_billing_details", { actor, workspace, ...details }),
Agents as a team: lifecycle, merge queue, billing and a new shell597 };
598}
599
Billing accounts, terms and enterprises; g1t is no longer free600export function billingAdminClient(service: ServiceBinding): BillingAdminApi {
601 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
602 return {
603 accounts: (query) => call("admin_accounts", { query: query ?? null }),
604 account: (id) => call("admin_account", { id }),
605 setTerms: (id, terms, by) => call("admin_set_terms", { id, terms, by }),
Team plan, an open-source pool, monthly trials and honest metering; the sidebar for everyone; a workspace that stays put606 setAllowances: (id, allowances, note, by) => call("admin_set_allowances", { id, allowances, note, by }),
Billing accounts, terms and enterprises; g1t is no longer free607 createEnterprise: (name, workspaces, by) => call("admin_create_enterprise", { name, workspaces, by }),
608 attach: (workspace, account, by) => call("admin_attach", { workspace, account, by }),
Billing: credits with a kind and expiry, discounts instead of comped, and safer charging609 credit: (workspace, amountMicros, note, by, options = { kind: "goodwill" }) =>
610 call("admin_credit", {
611 workspace,
612 amount_micros: amountMicros,
613 note,
614 by,
615 kind: options.kind,
616 expires_at: options.expiresAt ?? null,
617 refund_for: options.refundFor ?? null,
618 refund_day: options.refundDay ?? null,
619 }),
620 credits: (filter = {}) =>
621 call("admin_credits", {
622 workspace: filter.workspace ?? null,
623 kind: filter.kind ?? null,
624 month: filter.month ?? null,
625 by: filter.by ?? null,
626 }),
627 revokeCredit: (id, note, by) => call("admin_revoke_credit", { id, note, by }),
sudo: reset a test workspace's billing so it starts again as a new customer; refused on a live Stripe key, for comped workspaces and for an enterprise's628 resetBilling: (workspace, confirm, note, by) => call("admin_reset_billing", { workspace, confirm, note, by }),
Billing on Stripe's pages, month-end charges, warnings; sudo by workspace629 billingLink: (workspace, by) => call("admin_billing_link", { workspace, by }),
Stripe's webhook secret is a Worker secret, STRIPE_WEBHOOK_SECRET, from a destination made in Stripe's dashboard630 stripe: (fix = false, by) => call("admin_stripe", { fix, by: by ?? null }),
Stripe webhooks, enterprise invoices, and sudo for both631 enterpriseBilling: (id, email, by) => call("admin_enterprise_billing", { id, email, by }),
Merge Stripe Tax, the card fee on card payments, and one free workspace per person632 enterpriseAddress: (id, address, taxIdType, taxId, by) => call("admin_enterprise_address", { id, address, taxIdType, taxId, by }),
Stripe webhooks, enterprise invoices, and sudo for both633 invoiceEnterprise: (id, by) => call("admin_invoice_enterprise", { id, by }),
634 accountsFor: (workspaces) => call("admin_accounts", { query: null, workspaces }),
Two limits, real invoices, trust that grows by itself, sales signals635 signals: () => call("admin_signals", {}),
636 overview: () => call("admin_overview", {}),
637 sales: (workspace) => call("admin_sales", { workspace }),
638 setSales: (workspace, record, by) =>
639 call("admin_set_sales", {
640 workspace,
641 stage: record.stage,
642 owner: record.owner ?? null,
643 next_step: record.nextStep ?? null,
644 next_at: record.nextAt ?? null,
645 by,
646 }),
647 addNote: (workspace, text, by) => call("admin_add_note", { workspace, text, by }),
648 workspaceInvoices: (workspace) => call("admin_workspace_invoices", { workspace }),
Billing lists every invoice and every staff change; signals carry follow-ups649 allInvoices: (filter = {}) => call("admin_invoices", { status: filter.status ?? null, month: filter.month ?? null }),
650 audit: (filter = {}) =>
651 call("admin_audit", { by: filter.by ?? null, action: filter.action ?? null, before: filter.before ?? null }),
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look652 limitRequests: (status = "open") => call("admin_limit_requests", { status }),
653 decideLimitRequest: (id, decision, amountMicros, note, by) =>
654 call("admin_decide_limit_request", { id, decision, amount_micros: amountMicros, note, by }),
655 overages: () => call("admin_overages", {}),
656 goodwill: (workspace, amountMicros, reason, by, day = null) =>
657 call("admin_goodwill", { workspace, amount_micros: amountMicros, reason, by, day }),
658 velocity: () => call("admin_velocity", {}),
659 recordPayment: (workspace, amountMicros, reference, note, by) =>
660 call("admin_record_payment", { workspace, amount_micros: amountMicros, reference, note, by }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily661 costs: (days) => call("admin_costs", { days: days ?? null }),
662 costAlerts: () => call("admin_cost_alerts", {}),
Spend caps: a monthly budget for comped workspaces and a daily breaker on what g1t pays663 spendCaps: () => call("admin_spend_caps", {}),
664 liftBreaker: (note, by) => call("admin_lift_breaker", { note, by }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily665 decideProposal: (id, decision, note, by) => call("admin_decide_proposal", { id, decision, note, by }),
666 setCostSettings: (settings, by) => call("admin_set_cost_settings", { settings, by }),
667 setCostMapping: (mapping, by) =>
668 call("admin_set_cost_mapping", {
669 product: mapping.product,
670 meter: mapping.meter,
671 bucket: mapping.bucket ?? "",
672 price_meter: mapping.priceMeter ?? null,
673 own_meter: mapping.ownMeter ?? null,
674 scale_to_own: mapping.scaleToOwn ?? false,
675 drift_percent: mapping.driftPercent ?? null,
676 note: mapping.note ?? "",
677 remove: mapping.remove ?? false,
678 by,
679 }),
680 runCosts: (by) => call("admin_run_costs", { by }),
Merge branch 'main' into actions-toolkit-oidc-artifacts681 models: () => call("admin_models", {}),
682 decideModel: (model, decision, details, reason, by) =>
683 call("admin_decide_model", {
684 model,
685 decision,
686 name: details.name ?? null,
687 tier_hint: details.tierHint ?? null,
688 prices: details.prices
689 ? {
690 input_micros: details.prices.inputMicros,
691 output_micros: details.prices.outputMicros,
692 cache_read_micros: details.prices.cacheReadMicros,
693 cache_write_micros: details.prices.cacheWriteMicros,
694 cache_write_1h_micros: details.prices.cacheWrite1hMicros,
695 threshold: details.prices.threshold,
696 over_input_micros: details.prices.overInputMicros,
697 over_output_micros: details.prices.overOutputMicros,
698 over_cache_read_micros: details.prices.overCacheReadMicros,
699 over_cache_write_micros: details.prices.overCacheWriteMicros,
700 over_cache_write_1h_micros: details.prices.overCacheWrite1hMicros,
701 }
702 : null,
703 reason,
704 by,
705 }),
706 setModelDefault: (purpose, value, reason, by) =>
707 call("admin_set_model_default", {
708 purpose,
709 model: value.model ?? null,
710 tier: value.tier ?? null,
711 effort: value.effort ?? null,
712 reason,
713 by,
714 }),
Billing accounts, terms and enterprises; g1t is no longer free715 };
716}
717
Events service in Rust, with RFC 3339 times and accurate push events718export function eventsClient(service: ServiceBinding): EventsApi {
719 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
720 return {
721 publish: (events) => call("publish", { events }),
722 list: (query) => call("list", query),
723 };
724}
Integrations: your own model provider, alerts that open issues, tickets agents read725
726export function integrationsClient(service: ServiceBinding): IntegrationsApi {
727 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
728 return {
729 list: (workspace, viewer) => call("list", { workspace, viewer }),
730 connect: (actor, workspace, input) => call("connect", { actor, workspace, ...input }),
731 update: (actor, workspace, id, input) => call("update", { actor, workspace, id, ...input }),
732 disconnect: (actor, workspace, id) => call("disconnect", { actor, workspace, id }),
733 test: (actor, workspace, id) => call("test", { actor, workspace, id }),
734 deliveries: (workspace, viewer, id) => call("deliveries", { workspace, viewer, id }),
735 resolve: (workspace, viewer, reference) => call("resolve", { workspace, viewer, reference }),
736 references: (workspace, text, limit) => call("references", { workspace, text, limit }),
737 import: (actor, repo, reference, assign) => call("import", { actor, repo, reference, assign }),
738 links: (repo, number) => call("links", { repo, number }),
739 modelProvider: (workspace) => call("model_provider", { workspace }),
740 openModelSession: (run) => call("open_model_session", run),
741 modelUpstream: (token) => call("model_upstream", { token }),
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens742 gatewayUpstream: (workspace) => call("gateway_upstream", { workspace }),
AI Gateway: OpenAI's format, open models, and your own providers743 gatewayProviders: (workspace) => call("gateway_providers", { workspace }),
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily744 closeModelSessions: (tokenHashes) => call("close_model_sessions", { token_hashes: tokenHashes }),
Models per workspace: several providers, routed by kind of work745 routes: (workspace, viewer) => call("routes", { workspace, viewer }),
746 setRoutes: (actor, workspace, routes) => call("set_routes", { actor, workspace, routes }),
Integrations: your own model provider, alerts that open issues, tickets agents read747 };
748}
Webhooks: every event, to your own addresses, signed and retried749
750export function webhooksClient(service: ServiceBinding): WebhooksApi {
751 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
752 return {
753 list: (viewer, owner) => call("list", { viewer, ...owner }),
754 create: (actor, owner, input) => call("create", { actor, ...owner, ...input }),
755 update: (actor, owner, id, input) => call("update", { actor, ...owner, id, ...input }),
756 delete: (actor, owner, id) => call("delete", { actor, ...owner, id }),
757 ping: (actor, owner, id) => call("ping", { actor, ...owner, id }),
758 deliveries: (viewer, owner, id) => call("deliveries", { viewer, ...owner, id }),
759 redeliver: (actor, owner, deliveryId) => call("redeliver", { actor, ...owner, deliveryId }),
760 };
761}
Automations: rules in .g1t/automations that act when something happens762
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs763export function actionsClient(service: ServiceBinding): ActionsApi {
764 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
765 return {
766 workflows: (repo, viewer) => call("workflows", { repo, viewer }),
767 runs: (repo, viewer, filter = {}) => call("runs", { repo, viewer, ...filter }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)768 run: (repo, viewer, id, attempt) => call("run", { repo, viewer, id, attempt: attempt ?? null }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs769 logs: (repo, viewer, job, after = 0) => call("logs", { repo, viewer, job, after }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)770 summaries: (repo, viewer, id, attempt) => call("summaries", { repo, viewer, id, attempt: attempt ?? null }),
771 jobLogText: (repo, viewer, job) => call("job_log_text", { repo, viewer, job }),
772 runLogs: (repo, viewer, id, attempt) => call("run_logs", { repo, viewer, id, attempt: attempt ?? null }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs773 dispatch: (actor, repo, workflow, ref, inputs) => call("dispatch", { actor, repo, workflow, ref, inputs }),
Merge Actions runs: summaries, attempts and re-runs, graceful cancel, log downloads, badges (actions 0009)774 cancel: (actor, repo, id, force = false) => call("cancel", { actor, repo, id, force }),
775 rerun: (actor, repo, id, failedOnly = false, options = {}) =>
776 call("rerun", { actor, repo, id, failed_only: failedOnly, job: options.job ?? null, debug: options.debug ?? false }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs777 setWorkflowEnabled: (actor, repo, workflow, enabled) =>
778 call("set_workflow_enabled", { actor, repo, workflow, enabled }),
779 settings: (actor, owner, kind) => call("settings", { actor, ...owner, kind }),
Secrets and variables: one list, rows per environment, for workflows and deployments780 setSetting: (actor, owner, kind, name, value, options = {}) =>
781 call("set_setting", { actor, ...owner, kind, name, value, ...options }),
782 deleteSetting: (actor, owner, kind, name, id) => call("delete_setting", { actor, ...owner, kind, name, id }),
Merge branch 'worktree-agent-a3abfcce648e87dca'783 approveRun: (actor, repo, id) => call("approve_run", { actor, repo, id }),
784 pendingDeployments: (repo, viewer, id) => call("pending_deployments", { repo, viewer, id }),
785 reviewDeployments: (actor, repo, id, state, environments = [], comment) =>
786 call("review_deployments", { actor, repo, id, state, environments, comment: comment ?? null }),
787 actionsSettings: (repo, viewer) => call("actions_settings", { repo, viewer }),
788 setActionsSettings: (actor, repo, change) => call("set_actions_settings", { actor, repo, ...change }),
789 workspaceActionsSettings: (workspace, viewer) => call("workspace_actions_settings", { workspace, viewer }),
790 setWorkspaceActionsSettings: (actor, workspace, change) =>
791 call("set_workspace_actions_settings", { actor, workspace, ...change }),
792 environments: (repo, viewer) => call("environments", { repo, viewer }),
793 setEnvironment: (actor, repo, name, change) => call("set_environment", { actor, repo, name, ...change }),
794 deleteEnvironment: (actor, repo, name) => call("delete_environment", { actor, repo, name }),
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2795 artifacts: (repo, viewer, filter = {}) => call("artifacts", { repo, viewer, ...filter }),
796 artifactDownload: (repo, viewer, by) => call("artifact_download", { repo, viewer, ...by }),
797 deleteArtifact: (actor, repo, id) => call("delete_artifact", { actor, repo, id }),
798 artifactRetention: (repo, viewer, days) => call("artifact_retention", { repo, viewer, days }),
GitHub Actions on g1t, part three: .g1t/workflows, the pages, the docs799 };
800}
801
Deployments: a preview for every pull request, production on g1t.page802
Fast pages, required checks on the branch, self-hosted runners, honest incidents803/** Self-hosted runners, kept by the actions service. */
804export function runnersClient(service: ServiceBinding): RunnersApi {
805 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
806 return {
807 stuck: (viewer) => call("stuck_jobs", { viewer }),
808 list: (actor, owner) => call("runners", { actor, ...owner }),
809 createToken: (actor, owner, group) => call("create_registration_token", { actor, ...owner, group }),
810 remove: (actor, owner, id) => call("remove_runner", { actor, ...owner, id }),
811 groups: (actor, workspace) => call("runner_groups", { actor, workspace }),
812 setGroup: (actor, workspace, group) => call("set_runner_group", { actor, workspace, ...group }),
813 deleteGroup: (actor, workspace, id) => call("delete_runner_group", { actor, workspace, id }),
814 settings: (actor, owner) => call("runner_settings", { actor, ...owner }),
815 setSettings: (actor, owner, change) => call("set_runner_settings", { actor, ...owner, ...change }),
816 };
817}
818
Deployments: a preview for every pull request, production on g1t.page819export function deploymentsClient(service: ServiceBinding): DeploymentsApi {
820 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
821 return {
Projects: what a workspace builds and runs, first on every page822 settings: (project, viewer) => call("settings", { project, viewer }),
823 updateSettings: (actor, project, changes) => call("update_settings", { actor, project, changes }),
824 list: (project, viewer) => call("list", { project, viewer }),
825 get: (project, id, viewer) => call("get", { project, id, viewer }),
826 redeploy: (actor, project, branch) => call("redeploy", { actor, project, branch }),
827 takeDown: (actor, project, branch) => call("take_down", { actor, project, branch }),
Project dependencies: addresses, preview stacks, Affects, and agents who know828 stack: (actor, project, branch) => call("stack", { actor, project, branch }),
Projects: what a workspace builds and runs, first on every page829 overview: (workspace, viewer) => call("overview", { workspace, viewer }),
Deployments: a preview for every pull request, production on g1t.page830 usage: (workspace, viewer) => call("usage", { workspace, viewer }),
Agents and memory, checks and conflicts, profiles, slug renames, custom domains831 domains: (project, viewer) => call("domains", { project, viewer }),
832 addDomain: (actor, project, hostname, options = {}) =>
833 call("add_domain", { actor, project, hostname, twin: !!options.twin }),
834 removeDomain: (actor, project, id) => call("remove_domain", { actor, project, id }),
835 refreshDomain: (actor, project, id) => call("refresh_domain", { actor, project, id }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97836 repoDeployments: (repo, viewer, filter = {}) => call("list_deployments", { repo, viewer, ...filter }),
837 repoDeployment: (repo, id, viewer) => call("get_deployment", { repo, id, viewer }),
838 environments: (repo, viewer) => call("list_environments", { repo, viewer }),
839 createDeployment: (actor, repo, input) => call("create_deployment", { repo, actor, ...input }),
840 createDeploymentStatus: (actor, repo, id, input) => call("create_deployment_status", { repo, actor, id, ...input }),
Deployments: a preview for every pull request, production on g1t.page841 };
842}
Projects: what a workspace builds and runs, first on every page843
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member844/** Packages: the registries beside the code (services/packages). */
845export function packagesClient(service: ServiceBinding): PackagesApi {
846 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
847 return {
848 list: (workspace, viewer, filter = {}) =>
849 call("list_packages", {
850 workspace,
851 viewer,
852 ecosystem: filter.ecosystem ?? null,
853 repo_id: filter.repoId ?? null,
854 query: filter.query ?? null,
855 }),
856 get: (workspace, ecosystem, name, viewer) => call("get_package", { workspace, ecosystem, name, viewer }),
857 deleteVersion: (actor, workspace, ecosystem, name, version, surface) =>
858 call("delete_version", { actor, workspace, ecosystem, name, version, surface: surface ?? null }),
859 deletePackage: (actor, workspace, ecosystem, name, surface) =>
860 call("delete_package", { actor, workspace, ecosystem, name, surface: surface ?? null }),
861 set: (actor, workspace, ecosystem, name, change, surface) =>
862 call("set_package", {
863 actor,
864 workspace,
865 ecosystem,
866 name,
867 visibility: change.visibility ?? null,
868 link: change.link ?? null,
869 unlink: change.unlink ?? false,
Merge packages: roles, Actions access, source label, soft delete, API870 inherit_access: change.inheritAccess ?? null,
871 surface: surface ?? null,
872 }),
873 settings: (workspace, ecosystem, name, viewer) => call("package_settings", { workspace, ecosystem, name, viewer }),
874 deleted: (workspace, viewer) => call("deleted_packages", { workspace, viewer }),
875 restorePackage: (actor, workspace, ecosystem, name, surface) =>
876 call("restore_package", { actor, workspace, ecosystem, name, surface: surface ?? null }),
877 restoreVersion: (actor, workspace, ecosystem, name, version, surface) =>
878 call("restore_version", { actor, workspace, ecosystem, name, version, surface: surface ?? null }),
879 setAccess: (actor, workspace, ecosystem, name, who, role, surface) =>
880 call("set_package_access", {
881 actor,
882 workspace,
883 ecosystem,
884 name,
885 user: "user" in who ? who.user : null,
886 team: "team" in who ? who.team : null,
887 role,
888 surface: surface ?? null,
889 }),
890 removeAccess: (actor, workspace, ecosystem, name, who, surface) =>
891 call("remove_package_access", {
892 actor,
893 workspace,
894 ecosystem,
895 name,
896 user: "user" in who ? who.user : null,
897 team: "team" in who ? who.team : null,
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member898 surface: surface ?? null,
899 }),
Merge packages: roles, Actions access, source label, soft delete, API900 setActionsAccess: (actor, workspace, ecosystem, name, repo, role, surface) =>
901 call("set_actions_access", { actor, workspace, ecosystem, name, repo, role, surface: surface ?? null }),
902 removeActionsAccess: (actor, workspace, ecosystem, name, repo, surface) =>
903 call("remove_actions_access", { actor, workspace, ecosystem, name, repo, surface: surface ?? null }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member904 storage: (workspace) => call("storage", { workspace }),
905 storageAll: () => call("storage_all", {}),
Composer from the workspace's own repositories, and go get from g1t.sh906 syncComposer: (repoId) => call("sync_composer", { repo_id: repoId }),
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member907 };
908}
909
Projects: what a workspace builds and runs, first on every page910export function projectsClient(service: ServiceBinding): ProjectsApi {
911 const call = <T>(method: string, args: object) => rpc<T>(service, method, args);
912 return {
913 list: (workspace, viewer) => call("list", { workspace, viewer }),
914 get: (workspace, slug, viewer) => call("get", { workspace, slug, viewer }),
915 byRepo: (repoId) => call("by_repo", { repoId }),
916 create: (actor, workspace, input) => call("create", { actor, workspace, input }),
917 update: (actor, workspace, slug, changes) => call("update", { actor, workspace, slug, changes }),
A project is an app or a library: libraries show their package and how to ship a release, not production918 deploymentsChanged: (projectId, enabled) => call("deployments_changed", { projectId, enabled }),
Project dependencies: addresses, preview stacks, Affects, and agents who know919 dependencies: (workspace, slug, viewer) => call("dependencies", { workspace, slug, viewer }),
920 addDependency: (actor, workspace, slug, on, as) => call("add_dependency", { actor, workspace, slug, on, as }),
921 removeDependency: (actor, workspace, slug, on) => call("remove_dependency", { actor, workspace, slug, on }),
922 graph: (projectId) => call("graph", { projectId }),
Projects: pinned and recent projects, per person per workspace923 shortcuts: (workspace, viewer) => call("shortcuts", { workspace, viewer }),
924 pin: (actor, workspace, slug, position) => call("pin", { actor, workspace, slug, position: position ?? null }),
925 unpin: (actor, workspace, slug) => call("unpin", { actor, workspace, slug }),
926 reorderPins: (actor, workspace, slugs) => call("reorder_pins", { actor, workspace, slugs }),
927 visited: (actor, projectId) => call("visited", { actor, projectId }),
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97928 publicLinks: (repos) => call("public_links", { repos }),
Projects: what a workspace builds and runs, first on every page929 };
930}

This file's history is long; its oldest lines are credited to the oldest commit read.