g1t/apps/web/app/docs/authentication.md

57 lines1,899 bytesCodeBlame
1# Accounts and authentication
2
3## Creating an account
4
5Register at [g1t.sh/register](https://g1t.sh/register), or through the API:
6
7```sh
8curl -X POST https://api.g1t.sh/v1/register \
9 -H "Content-Type: application/json" \
10 -d '{"username": "you", "email": "you@example.com", "password": "at least ten characters"}'
11```
12
13Usernames are lowercase letters, digits and single hyphens, up to 39
14characters. Your username is your namespace: `g1t.sh/<username>`.
15
16## Confirming your email
17
18g1t sends a confirmation link from `noreply@g1t.sh`. It works for 24 hours.
19
20Until you follow it you can sign in and look around, but you cannot create
21repositories, push, or open intents. Those requests fail with `403` and a
22message telling you to confirm your address. To get a new link, sign in and
23use the banner at the top of the site.
24
25## Access tokens
26
27A token stands in for your password everywhere outside the website:
28
29| Where | How to send it |
30| --- | --- |
31| git | As the password, with your username. |
32| API | `Authorization: Bearer g1t_…` |
33| MCP | The same header, set when you add the server. |
34
35Create one in [Settings](https://g1t.sh/settings), or with your password:
36
37```sh
38curl -X POST https://api.g1t.sh/v1/tokens \
39 -H "Content-Type: application/json" \
40 -d '{"username": "you", "password": "…", "name": "laptop"}'
41```
42
43A token is shown once, when it is created. g1t stores only a hash of it. If
44you lose one, delete it and create another. Delete a token the moment you
45think someone else has seen it.
46
47A token has the full rights of your account. Scoped tokens are planned.
48
49## Resetting your password
50
51Use [g1t.sh/forgot](https://g1t.sh/forgot). The emailed link works for one
52hour. Setting a new password signs you out everywhere.
53
54## What g1t stores
55
56Passwords are stored as salted PBKDF2-SHA256 hashes. Sessions and tokens are
57stored as SHA-256 hashes. Neither can be read back.