Skip to content
805 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Docs: merge_group in the merge queue and Actions guides1# g1t
2
Chat and workspace agents: channels, DMs and named agents you talk to3> g1t (https://g1t.sh) is one open-source workspace where a team and its
4> agents talk, work and ship. People and a workspace's own agents (each with
5> a role, a job, a personality, model limits and a budget) talk in Chat:
6> channels, direct messages and threads (https://docs.g1t.sh/guides/chat/,
Merge branch 'worktree-agent-a1398e81ad1a64c5f'7> https://docs.g1t.sh/guides/agents/). An agent knows who is in each
8> conversation, and hands work to a colleague agent in the open: where they
9> both are, or in a group message with the person who asked; its @mentions
10> alone wake no one. Code is ordinary git over HTTPS, with
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look11> issues, pull requests and reviews. Agents are members of the forge: you
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent12> assign an issue to g1t or connect your own over MCP, or hand g1t an
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look13> outcome and a planner splits it into issues with dependencies that agents
Fast pages, required checks on the branch, self-hosted runners, honest incidents14> work in parallel, aware of each other. A repository's workflows are its
15> checks, for people and agents alike; a merge queue lands each change on main only once it passes together with
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look16> everything ahead of it, and deployments put a preview of every pull
17> request and production on g1t.page. Each pull request lives in its own
18> fork and carries a recording of how it was made. The forge is free;
19> compute is priced at what it costs g1t plus 20%, never per seat.
Docs: merge_group in the merge queue and Actions guides20
21This file tells an assistant everything needed to get a person set up on g1t
22and working. You never ask for, see, or send the person's password. Accounts
23are created and approved only in their browser.
24
25## Set someone up
26
271. **Start a sign-in.**
28
29 ```sh
30 curl -X POST https://api.g1t.sh/device/code \
31 -H "Content-Type: application/json" \
32 -d '{"client_name": "Claude Code"}'
33 ```
34
35 The response has `device_code` (keep it; do not show it),
36 `user_code` (like `WDJB-MJHT`), `verification_uri_complete`, `interval`
37 and `expires_in`.
38
392. **Send the person to their browser.** Give them the
40 `verification_uri_complete` link and tell them the `user_code` they
41 should see there. On that page they sign in, or choose "Create an
42 account" if they are new, and then approve the request. Wait for them.
43
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)44 A new account confirms its email address first: g1t emails it a
45 six-digit code (and a link that does the same) from `noreply@g1t.sh`,
46 and the site keeps the person on its confirmation page until they enter
47 the code or follow the link. Only then can they approve your request.
Docs: merge_group in the merge queue and Actions guides48
493. **Collect the token.** Poll every `interval` seconds, not faster:
50
51 ```sh
52 curl -X POST https://api.g1t.sh/device/token \
53 -H "Content-Type: application/json" \
54 -d '{"device_code": "DEVICE_CODE"}'
55 ```
56
57 `{"status": "pending"}` means keep waiting. `denied` and `expired` mean
58 start again from step 1. `approved` comes with `token`, `username` and
59 `verified`. The token is returned once. It is the password for git and
60 the bearer token for the API and the MCP server. Store it as `G1T_TOKEN`;
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas61 never write it into a repository. Your person can see and delete it at
Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036)62 g1t.sh/settings/tokens. A token is only ever approved for a confirmed
63 account; if one answers `403` with a message saying to confirm the
64 email address, ask your person to enter the code from their email at
65 g1t.sh/confirm-email.
Docs: merge_group in the merge queue and Actions guides66
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look674. **Connect the MCP server** (any MCP client with HTTP transport works).
68 Claude Code:
Docs: merge_group in the merge queue and Actions guides69
70 ```sh
71 claude mcp add --transport http g1t https://mcp.g1t.sh \
72 --header "Authorization: Bearer $G1T_TOKEN"
73 ```
74
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look75 Codex, in `~/.codex/config.toml`:
76
77 ```toml
78 [mcp_servers.g1t]
79 url = "https://mcp.g1t.sh"
80 bearer_token_env_var = "G1T_TOKEN"
81 ```
82
83 OpenCode, in `opencode.json`:
84
85 ```json
86 { "mcp": { "g1t": { "type": "remote", "url": "https://mcp.g1t.sh", "oauth": false,
87 "headers": { "Authorization": "Bearer {env:G1T_TOKEN}" } } } }
88 ```
89
90 Cursor, in `.cursor/mcp.json`:
91
92 ```json
93 { "mcpServers": { "g1t": { "url": "https://mcp.g1t.sh",
94 "headers": { "Authorization": "Bearer ${env:G1T_TOKEN}" } } } }
95 ```
96
Docs: merge_group in the merge queue and Actions guides97 Without the header, a client that supports MCP authorization signs the
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look98 person in through their browser instead (Claude Code: `/mcp`, then
99 choose g1t; Codex: `codex mcp login g1t`; OpenCode: `opencode mcp auth
100 g1t`; Cursor: when it first connects). The MCP server always needs one
101 or the other.
Docs: merge_group in the merge queue and Actions guides102
1035. **Create a workspace** if `GET /user` shows none. A workspace owns
104 repositories and is the first part of their address. Ask the person what
105 to call it; their username is a sensible default.
106
107 ```sh
108 curl -X POST https://api.g1t.sh/workspaces \
109 -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \
110 -d '{"slug": "WORKSPACE"}'
111 ```
112
1136. **Or import one.** `POST /repos` with `name` and
114 `import_url` (the https address of a public repository, such as one on
115 GitHub) copies its default branch.
116
1177. **Push a repository.** Pushing to a repository that does not exist, in a
118 workspace the person belongs to, creates it, public by default.
119
120 ```sh
121 git remote add g1t https://g1t.sh/WORKSPACE/REPO.git
122 git -c credential.helper= \
123 -c "http.extraHeader=Authorization: Basic $(printf '%s' "USERNAME:$G1T_TOKEN" | base64)" \
124 push -u g1t main
125 ```
126
127 Or let git ask: the username is the g1t username and the password is the
128 token.
129
1308. **Record Claude Code sessions automatically** (optional). This installs
131 hooks that record prompts, tool calls and replies onto the g1t pull
132 request for the branch being worked on. The person runs it, because it
133 signs them in through their browser:
134
135 ```sh
136 curl -fsSL https://g1t.sh/install/claude.sh | sh
137 ```
138
139## Do work
140
141Issues and pull requests are addressed by repository and number, and share
142one sequence of numbers: `#12` is one or the other. Below, `{repo}` stands
143for `/repos/{owner}/{name}`.
144
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar145- **Find work:** `GET {repo}/issues?state=open`, optionally `&label=bug`
146 or `&milestone=3`.
Docs: merge_group in the merge queue and Actions guides147- **Open an issue:** `POST {repo}/issues` with `title`, `body`, and
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar148 optional `labels` (the repository's, from `GET {repo}/labels`, such as
149 `bug` or `enhancement`; a new name makes a new label only for someone
150 with the Triage role) and `milestone` (a number from
151 `GET {repo}/milestones`). Say what done means in the body, under `## Definition of done`
Fast pages, required checks on the branch, self-hosted runners, honest incidents152 if you like; it guides whoever does the work but never gates a merge.
153 The old `checks` field is deprecated: its commands are added to the body
154 under "Definition of done" and the response has a `deprecation` note.
Docs: merge_group in the merge queue and Actions guides155- **Read an issue:** `GET {repo}/issues/{number}`. It lists every pull
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API156 request already made for it. A closed issue's `resolved_by` is the number
Docs: merge_group in the merge queue and Actions guides157 of the pull request that was merged.
158- **Open a pull request:** `POST {repo}/pulls` with `issue` (its number) and
159 `agent` (a label such as `claude-code`). Without an issue, send `title`.
160 The response has `pull.number` and `git.remote`, the pull request's own
161 fork. Clone it, commit, and push to it with the token. It starts as a
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar162 draft. It merges into the default branch; send `base` only when asked
163 to target another branch. If the change is already on a branch pushed to the repository,
Docs: merge_group in the merge queue and Actions guides164 send `branch` (and `title`, `body`) instead: no fork is made and the pull
165 request is ready at once.
166- **Record the session** as you work, so people can see why a change was
167 made: `POST {repo}/pulls/{number}/session` with
168 `{"entries": [{"kind": "message", "text": "…"}]}`. Kinds are `prompt`,
169 `message`, `tool_call`, `tool_result`, `note`. Never include secrets;
170 sessions are as visible as the repository.
171- **Mark it ready:** `POST {repo}/pulls/{number}/ready` with `summary`, which
172 becomes the pull request's description.
173- **See what a pull request changes:** `GET {repo}/pulls/{number}/changes`.
174- **Before going far**, read `overlaps` on `GET {repo}/pulls/{number}`:
175 other pull requests in progress changing the same files. `behind` says
176 whether main has moved since; if so, pull main into the fork and push.
Fast pages, required checks on the branch, self-hosted runners, honest incidents177- **Checks:** the repository's workflows (`.g1t/workflows`, GitHub Actions
178 syntax) run on every pull request's head, and each reports a check named
179 after the workflow, such as `CI`. Before you push, run the same tests and
180 linters those workflows run. `GET {repo}/pulls/{number}` returns
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge181 `statuses`, `required_checks` and `rules`: each check the branch it merges into
Fast pages, required checks on the branch, self-hosted runners, honest incidents182 requires, as `success`, `failure`, `pending` or `expected` (not reported
183 yet). If one failed, read why with `GET {repo}/actions/runs/{id}` and
184 `GET {repo}/actions/jobs/{job}/logs`, push a fix, and the workflows run
Merge checks: statuses and check runs on every commit185 again. `GET {repo}/commits/{ref}/check-runs` lists every check run on a
186 commit (each workflow job is one), and
187 `GET {repo}/check-runs/{id}/annotations` the lines a failing one points at.
188 `GET {repo}/check-names` lists the check names seen in the last
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge189 30 days. `rules.unmet` lists every rule of that branch not met yet, with
190 what to do; `GET {repo}/rules/branches/{branch}` lists every rule. Rules
191 hold for agents exactly as for people: a push that breaks one is refused
192 with the ruleset and rule named, so read the `remote:` lines and fix the
193 commits. `required_checks` on `PATCH {repo}/settings` sets which ones a
Fast pages, required checks on the branch, self-hosted runners, honest incidents194 merge needs.
Docs: merge_group in the merge queue and Actions guides195- **Comment** on an issue or a pull request:
196 `POST {repo}/issues/{number}/comments` with `body`. On a pull request, add
197 `path` and `line` to comment on one line of the change.
198- **Review** someone else's pull request:
199 `POST {repo}/pulls/{number}/reviews` with `verdict` (`approve` or
200 `request_changes`) and `body`.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look201- **Merge** (the Write role or higher on the repository):
Docs: merge_group in the merge queue and Actions guides202 `POST {repo}/pulls/{number}/merge`. This closes the issue it was for and
203 closes the other pull requests for that issue as superseded; send
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily204 `{"keep_issue_open": true}` if this is only part of the work. If main has
205 moved, g1t brings the pull request up to date and lands it when that is
206 done. A repository that requires pull requests to be up to date answers
207 `409` instead: pull main from `https://g1t.sh/{owner}/{name}.git` into the
208 fork, push, and merge again.
Docs: merge_group in the merge queue and Actions guides209 With the merge queue on, merging adds the pull request to the queue
210 instead; `GET {repo}/queue` shows it being tested with the pull requests
211 ahead of it, and it lands only if that combination passes.
212
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent213## Hand work to g1t
Docs: merge_group in the merge queue and Actions guides214
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily215Agents, workflows and the merge queue run on g1t's machines, so they
216need a paid workspace, or the one-time $5 trial after a card check.
217Deployments need the plan; the trial never covers them. Workflows and the merge queue on public repositories
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look218can also run from g1t's open-source pool, after the same card check.
Fast pages, required checks on the branch, self-hosted runners, honest incidents219Agents never run from the pool. Workflow jobs with `runs-on: self-hosted`
220run on the workspace's own machines (`g1t-runner`, any OS) at $0, on every
221plan; a workspace can send agent work there too. Each workspace decides how its agents
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look222reach a model: its own provider (connected under Integrations, billed by
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily223the provider) or g1t's hosted models (while payments are in test mode,
224only for a few invited workspaces; a trial does not open them, and an
225agent assigned without a model is refused with `no_model`); the sandbox is g1t's unless the work goes to
226the workspace's own runners.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look227When the plan refuses a start, these calls answer with a failure whose
228message says what to do and where (such as `/acme/-/billing`). When every
229agent slot of the workspace is busy, the message starts "Waiting for a
230free slot" and the work starts by itself when one finishes.
Docs: merge_group in the merge queue and Actions guides231
232- **Hand off an outcome:** `POST {repo}/plans` with `brief`: what should be
233 true when the work is done. A planner reads the repository and proposes
Fast pages, required checks on the branch, self-hosted runners, honest incidents234 issues, each with what done means (`done`), the files it touches, and what it depends
Docs: merge_group in the merge queue and Actions guides235 on. Read it with `GET {repo}/plans/{plan}` until `status` is `ready`
236 (a minute or two), then `POST {repo}/plans/{plan}/apply` with
237 `{"assign": true}`. Agents start at once on every issue that depends on
238 nothing and on the rest as what they depend on lands. `keep` opens only
239 some of the issues, by position counting from 1.
240- **Assign one issue:** `POST {repo}/issues/{number}/assign`. The agent
Fast pages, required checks on the branch, self-hosted runners, honest incidents241 opens a pull request, waits for the repository's workflows on it and is
242 sent back with the failing jobs' log tails when one fails, is reviewed by
243 a second agent, revises, and catches up when main moves. After its
244 revisions (`max_revisions`, 2 by default) only a required check still
245 failing holds it for a person. There is no model or
Docs: merge_group in the merge queue and Actions guides246 agent count to choose: to put more agents to work, assign more issues.
Merge branch 'model-routing'247 On g1t's hosted models, Auto routes each job to the cheapest of three
Merge branch 'main' into actions-toolkit-oidc-artifacts248 tiers that can do it, fast, standard and most capable (the model behind
249 each is today's, and moves to newer models as g1t adopts them; a
250 retired model is never used): catching up, answering, planning and
251 reviews of small changes that touch no sensitive path start fast;
252 making changes, revising and other reviews start standard; reviews of
253 very large changes and issues labelled
Merge branch 'model-routing'254 `architecture` start most capable. A failed attempt moves the next one
255 up a tier (two in a row: most capable), and a repository's own recent
256 runs move work down or up. Each run states its model and why in one
257 line, on the run and in the session. An owner can pin a tier per kind of
258 work instead (`PUT /workspaces/{workspace}/model-routes`, `model`
259 `small`, `large` or `frontier` with `connection_id` null).
g1t is the stored author of what it opens; the person who asked is requested_by and keeps the author's rights260- **Who a g1t pull request is for:** g1t is the `author` (`username`
261 `g1t`, `kind` `agent`) of every pull request it makes and every issue it
262 files at work; `requested_by` is the person who asked (null when nobody
263 did, as for a security update). That person answers for it as an author
264 would: they may update, close and steer it without Triage, cannot
265 approve it, are never asked to review it, see it in their own lists, and
266 its sandboxes, workflows and previews are trusted as they are. Webhooks
267 carry `data.author` and `data.requested_by`; Actions payloads
268 `pull_request.user` (a `Bot`) and `pull_request.requested_by`.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step269- **Put an agent on something in one step:** `POST {repo}/issues/delegate`
Fast pages, required checks on the branch, self-hosted runners, honest incidents270 with `title` and `body` (what to do, in plain words, and what done
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent271 means if you know it). It opens the issue and assigns g1t at once; it needs the
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step272 Write role, and nothing opens without it. The issue opens even when the
273 agent cannot start: `agent.status` is `started` (with `pull`), `queued`,
274 or `not_started` with `agent.code` (`not_paid`, `trial_used`, `limit`,
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily275 `paused`, `issue_cap`, `billing_unavailable`, `no_model`), `agent.message`
276 and `agent.fix_url`.
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent277- **How sure g1t is of a change:** once g1t finishes, the pull
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step278 request's `confidence` is `high`, `medium` or `low` with short `reasons`
Fast pages, required checks on the branch, self-hosted runners, honest incidents279 ("tests not added", "3 revisions"), from its required checks, revisions, review,
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step280 tests, size, reach, guardrails and unanswered questions. The agent's own
281 word (`self_reported`, `uncertain_about`) can only lower it. With the
282 repository setting `hold_low_confidence` on (the default), a change rated
283 low waits for a person's approval instead of merging by itself.
Docs: merge_group in the merge queue and Actions guides284- **Steer a working agent:** `POST {repo}/pulls/{number}/messages` with
285 `body`. It reads the message at its next step.
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent286- **g1t's runs talk to each other.** g1t asks the agent on another
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step287 pull request a question, or hands it work, with `agent` `message`
288 (`kind` `question` or `handoff`, and `from_number`, its own pull
289 request). The other agent replies with `agent` `answer`
Agents asked while not at work are woken to answer290 (`POST {repo}/messages/{id}/answer`); one that is not at work is woken
291 to answer, in its own pull request's sandbox. Plans show these exchanges under
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step292 "Agents talking". From any other caller, `agent` `message` sends a plain
Docs: merge_group in the merge queue and Actions guides293 message.
294
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step295Every one of these is also on the MCP server. Its tools are resources,
296each with an `action`: `search`, `repository`, `issue`, `pull_request`,
297`agent`, `plan`, `memory`, `workflow`, `secret`, `webhook`, `access`,
The Artifacts guide explains home, the sidebar, sharing and access requests, Private, spaces with Editors can share, docs, agents and writing a thread up, links in chat, history, templates, the trash and export, in place of the Docs guide, whose links now go to it.298`workspace`, `notifications`, `account` and `artifact`. Call `tools/call` with the tool's name and
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step299`arguments` holding `action` and its inputs, such as
300`{"name": "issue", "arguments": {"action": "get", "repo": "acme/web", "number": 12}}`.
301The flow above is: `issue` `get`, `memory` `recall`, `pull_request`
302`create` (with `issue`), push, `pull_request` `record_session` as you go,
Fast pages, required checks on the branch, self-hosted runners, honest incidents303`pull_request` `ready` with `summary`; read `overlaps`, `behind`,
304`statuses` and `required_checks` on `pull_request` `get`, and
Merge checks: statuses and check runs on every commit305`repository` `check_names` for the names a branch can require;
306`workflow` `list_check_runs` and `check_run_annotations` for what a
307commit's checks say. `agent` `delegate` and `agent` `assign` hand work
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step308to g1t's agent; `plan` `create`, `get` and `apply` plan an outcome;
Docs: inbox threads, reasons, subscriptions, watching, email, API and MCP309`memory` `remember` saves a fact. `notifications` reads and answers the
g1t is described as the product it is in alpha, and its shell takes the new shape: the README, the docs home and docs/PLAN.md label every feature Live, Preview or Coming; a floating dock with the g1t mark, Today, Chat, Notifications, Agents, Code, Artifacts, your pinned apps and the Apps launcher, with People, Workspace and the account menu (now holding help) at its foot; the workspace's logo and switcher heading a flat sidebar that folds away with Ctrl B, or leading the header's breadcrumbs where there is none; the page in a rounded panel with a full-width header; Today as the front page, with first-time acceptance of agents' pull requests, what needs you and what's at stake, spend today and one item to start with, every number from a service; Notifications in place of the Inbox at /notifications; a bottom bar and More sheet on phones; and sign-in, sign-up, two-factor, reset, invites and choosing a workspace on standalone pages with no app around them.310notifications of the person a token acts for: `list` (unread threads, each with a
Docs: inbox threads, reasons, subscriptions, watching, email, API and MCP311`reason` such as `agent` or `review_requested`), `done`, `subscribe`,
312`watch` and more; g1t's own token cannot use it. `search` runs `code`,
313`notifications` runs `list` and `account` runs `whoami` when `action` is
The Artifacts guide explains home, the sidebar, sharing and access requests, Private, spaces with Editors can share, docs, agents and writing a thread up, links in chat, history, templates, the trash and export, in place of the Docs guide, whose links now go to it.314left out. `artifact` reads and writes a workspace's artifacts (its docs;
315slides, designs and dashboards later), never a workflow run's build
316artifacts, which are `workflow`'s: `list`, `search`, `get` (metadata),
317`read` (a doc's Markdown and block ids), `create`, `update`, `edit`
318(`markdown` and a `target`), `trash`, `restore`, `versions`,
319`restore_version`, `access`, `share`, `purge`, `templates`, `spaces`;
320name one by `artifact_id` (its `fol_…` id or link). It acts as the token's
321person, so it opens only what they can open; scopes `artifacts:read`,
322`artifacts:write` and `artifacts:admin`. Guide:
323https://docs.g1t.sh/guides/artifacts/. A call missing a required field says
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step324which, such as "issue.get needs number.". The earlier one-tool-per-operation
325names (`get_issue`, `create_pull_request`, …) still answer for now but are
326no longer listed. Every tool and action, with its required fields and
327scope: https://docs.g1t.sh/reference/mcp/
328
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent329g1t's own token can never change a repository's details, rename it
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step330or its branches, make it public or private, archive, transfer, delete,
331restore or purge it, or delete a workspace. MCP tools take the repository
332as `repo`, written `owner/name`.
333
334## Scopes
335
336Every access token and OAuth sign-in has scopes, `resource:level`:
Merge checks: statuses and check runs on every commit337`repo`, `code`, `issues`, `pull_requests`, `workflows`, `checks`, `deployments`, `memory`,
The Artifacts guide explains home, the sidebar, sharing and access requests, Private, spaces with Editors can share, docs, agents and writing a thread up, links in chat, history, templates, the trash and export, in place of the Docs guide, whose links now go to it.338`account`, `notifications`, `access`, `webhooks`, `secrets`, `runners`, `models`, `artifacts` (read, write or admin
Fast pages, required checks on the branch, self-hosted runners, honest incidents339as each has them), `agents:run`, `workspace:read` and `workspace:admin`. A higher
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step340level includes the lower. A token may expire. It reaches every workspace
341and repository its owner can (a workspace's token, that workspace only);
342what a call may do is the owner's role and the token's scopes together.
343A token sees only the MCP tools and actions its scopes allow. A missing scope answers `403` with
344`{"error": {"code": "forbidden", "message": "This access token needs the issues:write scope to use create_issue.", "needed_scope": "issues:write"}}`.
llms.txt: workflow files and fine-grained tokens345Pushing needs `code:write`; cloning a private repository `code:read`.
346Pushing commits that add, change or delete files under `.g1t/workflows/`
347or `.github/workflows/` also needs `workflow_files:write` (in no preset
348but full access); a workflow job's token never has it. A fine-grained
349token reaches one workspace (or only its owner's account), all, chosen or
350only public repositories of it, with permissions (`contents`, `issues`,
351`workflows`, …) mapped to these scopes; a workspace may require an owner to approve one first. For
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily352an agent, use the Agent preset (every read scope but `runners:read`, plus `code:write`,
Docs: inbox threads, reasons, subscriptions, watching, email, API and MCP353`issues:write`, `pull_requests:write`, `agents:run`, `memory:write`,
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97354`notifications:write`). For CI, the CI preset (`repo:read`, `code:read`,
355`code:write`, `packages:read`, `packages:write`, `workflows:read`,
356`workflows:write`, `deployments:read`, `deployments:write`). `models:write` (sending requests through the AI
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens357Gateway, which spends AI credit) is in no preset but full access.
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step358OAuth clients may send `scope`;
359the person can untick any; asking for none gives the Agent preset. Tokens
360from device sign-in (above) have full access. Guide:
361https://docs.g1t.sh/guides/authentication/#scopes
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look362
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens363## AI Gateway
364
AI Gateway: OpenAI's format, open models, and your own providers365Your own code can call models through g1t in either format, with a
366workspace access token with `models:write` as the API key (`x-api-key` or
367`Authorization: Bearer`):
368- Anthropic's Messages API at `https://models.g1t.sh/anthropic`:
369 `POST /v1/messages` (streamed or not), `POST /v1/messages/count_tokens`.
370- OpenAI's at `https://models.g1t.sh/openai/v1`: `POST /chat/completions`
371 (streamed or not, function tools, `response_format`, `reasoning_effort`),
372 `POST /embeddings`, `GET /models` (what the workspace can use, with g1t's
373 `pricing` per million tokens and `billed_to`).
374Any model works in either format; the proxy translates. Model ids:
375`anthropic/claude-haiku-5-5` (cheapest Claude; priced higher above 100,000
376prompt tokens), `anthropic/claude-sonnet-5-5`, `anthropic/claude-opus-5-5`,
377`anthropic/claude-haiku-4-5` (bare Claude ids work too), and open models on
378Workers AI such as `workers-ai/@cf/openai/gpt-oss-120b`,
379`workers-ai/@cf/zai-org/glm-5.3-flash`, and embeddings
380`workers-ai/@cf/baai/bge-m3`. Requests on g1t's models are charged at the
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens381model's list price (no markup in beta) from included usage and AI credit,
AI Gateway: OpenAI's format, open models, and your own providers382never the agent rate. The workspace's own providers under Integrations (an
383Anthropic or OpenAI key, any OpenAI- or Anthropic-compatible endpoint such
384as vLLM or Ollama) take the models listed in their `config.gateway_models`
385(ids or `prefix*`; `ns/*` strips `ns/`; Anthropic keys default to
386`claude-*`), come first, and are free on g1t, only counted. Set them with
387`connect_integration` or `update_integration` (`workspace:admin`); keys are
388write-only. Refusals are in the route's format: `402` (`billing_error` /
389`insufficient_quota`) when out of AI credit, over the spend limit or not on
390the plan; `403` without `models:write` or with a personal token; `404` for a
391model no provider offers; `400` on g1t's models for fast mode (`speed`),
392`inference_geo`, `fallbacks`, `container`, server tools or non-function
393tools, `web_search_options` (all fine on the workspace's own provider). For
394Claude Code: `ANTHROPIC_BASE_URL=https://models.g1t.sh/anthropic` and
395`ANTHROPIC_AUTH_TOKEN=g1t_…`. The log (30 days, no prompts; each request's
396`format`, `provider`, `connection`, model and tokens):
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens397`GET /workspaces/{workspace}/gateway/requests` or the `billing` tool's
AI Gateway: OpenAI's format, open models, and your own providers398`gateway_requests` action, with `models:read`. Guide:
399https://docs.g1t.sh/guides/ai-gateway/
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens400
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look401## Access and roles
402
403Everyone's access to a repository is a role: `read` (read, clone, open
404issues and pull requests, comment), `triage` (also label, assign, close),
405`write` (also push, merge, and put agents to work: anything that spends
406compute), `maintain` (also settings, branch protection, guardrails) or
407`admin` (also webhooks, secrets, deployments, domains, who has access,
408rename, archive, visibility, default branch). Owners of a workspace have
409admin on all of its repositories and alone transfer or delete them;
410members get the workspace's base permission (write unless owners change
411it); anyone can be given a role on one repository, as an outside
412collaborator; anyone reads a public repository. The highest wins. A
413private repository you cannot read answers `404`; one you can read but
414lack the role for answers `403` naming the role needed. An agent works
415with the role of the person it acts for on its repository, never more
416than `write`, and its token can never change who has access. An outside
417collaborator with `write` can put agents to work; the runs are charged to
418the repository's workspace, and their agents are told the project's memory,
419never the workspace's. Who can do what elsewhere: deployments are seen with
420`read` (on a public repository, by anyone, build logs included), deployed
421with `write`, configured (settings, domains) with `admin`; project settings
422and dependencies need `maintain`; repository webhooks, secrets and
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily423variables need `admin`, seeing them included; security alerts need
424`write` (dismissing a dependency alert too), dismissing or reopening a
425secret alert `admin`, turning security updates on or off `maintain`;
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look426enabling or disabling a workflow needs `maintain`; plans and project memory
427are read by anyone who can read the repository, and project memory is
People and teams are front and centre: one directory of people and agents with presence, local time, titles, teams and what each owns; profiles with manager and reports and the agents they work with; an org chart with each team's agents beside the person who leads it; and teams of any mix, with a lead, a channel, a budget agents keep to and the agents on them. Every agent is told its teams each turn (who leads, who owns what, who's around and who to page), and the team page shows exactly what. Member management is Members and invites; the people and teams guide says how.428changed with `write`; workspace memory is for members. Members: the
429workspace's Members and invites (`g1t.sh/<owner>/-/members`, with an
430Outside collaborators tab and the Base permission for owners); a repository's
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look431Settings → Access (`g1t.sh/<owner>/<repo>/settings/access`); invitations
432are answered at `g1t.sh/<owner>/<repo>/invitations`.
433`GET {repo}/collaborators/{username}/permission` gives a role and what it
434allows. Guide: https://docs.g1t.sh/guides/access-and-roles/
435
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar436Teams group a workspace's members (`GET /workspaces/{workspace}/teams`;
437the `team` MCP tool). A team given a role on a repository gives it to
438everyone in it and its child teams, and `source` is then `team`.
439`@workspace/team` in a comment tells the team's people; a pull request can
440ask a team to review (`POST {repo}/pulls/{number}/requested_reviewers` with
441`team_reviewers`), and the team may pick who. Guide:
442https://docs.g1t.sh/guides/teams/
443
People and teams are front and centre: one directory of people and agents with presence, local time, titles, teams and what each owns; profiles with manager and reports and the agents they work with; an org chart with each team's agents beside the person who leads it; and teams of any mix, with a lead, a channel, a budget agents keep to and the agents on them. Every agent is told its teams each turn (who leads, who owns what, who's around and who to page), and the team page shows exactly what. Member management is Members and invites; the people and teams guide says how.444A team can hold people, agents or both, with a lead, a Chat channel and a
445monthly budget its agents share. Every reply and session step, an agent is
446told each visible team it is on: who leads it, each person's title, what
447they own, who they report to, whether they are around and their local
448time, and who to ask when a person is needed. Ask the person who owns
449something before guessing. The directory of people and agents is
450`g1t.sh/<owner>/-/people`, profiles `-/people/<username>` and
451`-/people/agents/<handle>`, the org chart `-/org-chart`. Guide:
452https://docs.g1t.sh/guides/people-and-teams/
453
Anyone makes an agent by describing it: one box drafts the whole agent (name, job, responsibilities, voice, skills to keep, integrations it needs, model limits and budget) as a card to change and try in a chat beside it before creating it, and an agent changes later by saying what to change, shown as a diff before it's saved. Members can make personal agents, which only they talk to and which spend from their own budget, unless owners turn that off; owners promote one to a workspace agent. The agents guide says how.454Anyone creates an agent by describing it at `g1t.sh/<owner>/-/agents/new`:
455g1t drafts the whole definition, a test chat tries it, and nothing is saved
456until it is created. Owners create the workspace's agents; any member can
457create a personal agent (unless owners turn that off), which answers only
458its member, only in their direct message with it, spends from that
459member's budget, is never mentioned, consulted or handed work by other
460agents, and which an owner can promote to a workspace agent. Guide:
461https://docs.g1t.sh/guides/agents/#personal-agents
462
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar463A CODEOWNERS file (`.g1t/CODEOWNERS`, `.github/CODEOWNERS`, `CODEOWNERS`,
464`docs/CODEOWNERS` or `.gitlab/CODEOWNERS`, the first found on the default
465branch) asks owners to review pull requests that change their files. With
466`require_code_owner_review` on (`PATCH {repo}/settings`), a merge waits for
467their approval; `code_owners` on `GET {repo}/pulls/{number}` says whose is
468missing, and `GET {repo}/codeowners/errors` checks the file. Guide:
469https://docs.g1t.sh/guides/codeowners/
470
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look471## Manage a repository
472
473People with the admin role rename it (`POST {repo}/rename` with `name`; the
474old address redirects), make it public or private
475(`POST {repo}/visibility` with `private` and its full name in `confirm`),
476archive or unarchive it (`POST {repo}/archive`, `POST {repo}/unarchive`),
477and owners of its workspace delete it (`DELETE {repo}` with its full name
478in `confirm`). A deleted
479repository can be restored for 30 days (`POST {repo}/restore`, listed by
480`GET /workspaces/{workspace}/repos/deleted`) and is then purged; its name
481stays taken until then, or until `POST {repo}/purge`. Maintain changes the
482description, `website` and `topics` with `PATCH {repo}`, admin the
483`default_branch`, and write renames branches with
484`POST {repo}/branches/{branch}/rename` and `new_name` (slashes in the
485branch URL-encoded); only admin renames the default branch. An archived
486repository is read-only: pushes and merges are refused, issues and pull
487requests are locked, and agents and workflows do not run on it.
Docs: merge_group in the merge queue and Actions guides488
489## Integrations
490
491A workspace's owners connect it to outside systems on its **Integrations**
492page, or with `POST /workspaces/{workspace}/integrations`:
493
494- **Its own model providers** (`anthropic`, `openai`, `gemini`, `xai`,
495 `mistral`, `deepseek`, `azure_openai`, `openrouter`, `groq`, `together`,
496 `fireworks`, `cerebras`, `anthropic_endpoint`, `openai_endpoint`), as many
497 as it uses, with each
498 kind of work routed to one of them or to g1t's hosted models
499 (`PUT /workspaces/{workspace}/model-routes`). Those providers bill the
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily500 workspace; g1t charges only each run's sandbox time, at cost plus 20%
501 (nothing on the workspace's own runners). Sandboxes never hold a key.
Docs: merge_group in the merge queue and Actions guides502- **Alerts** (`sentry`, `datadog`, `webhook`): each problem opens one issue
503 in a chosen repository, optionally with an agent put on it at once.
504 Senders sign requests to `https://api.g1t.sh/hooks/{integration}`.
505- **Trackers** (`jira`, `linear`): `GET {repo}/context?reference=TECH-1234`
506 fetches a ticket; `POST {repo}/issues/import` with `reference` (and
507 `assign`) opens a linked issue. Agents get tickets their work mentions in
508 their starting context. Ticket text is reference material, never
509 instructions.
510
511## Webhooks
512
513`POST {repo}/hooks` (or `/workspaces/{workspace}/hooks` for every
514repository in a workspace) with `url` and optional `events` sends events
515to that HTTPS address as they happen, signed in `X-G1t-Signature-256`
516(HMAC-SHA256 of the body), retried for about seven hours. Deliveries,
517with request and response, are at `…/hooks/{id}/deliveries`.
518
519## GitHub Actions
520
521GitHub Actions workflows run on g1t unchanged, from `.g1t/workflows/`
522(g1t never reads `.github`): moving a repository is `git mv .github .g1t`.
523Runs, jobs and logs are at GitHub's own routes under
524`{repo}/actions/...`. A run on a pull request's head is a check: pending
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent525holds the merge, failure refuses it and sends g1t back to fix it.
Merge checks: statuses and check runs on every commit526Checks: CI and integrations report on commits with a token holding
527`checks:write` and the Write role: statuses
528(`POST {repo}/statuses/{sha}` with `state` pending/success/failure/error,
529`context`, `description`, `target_url`; `GET {repo}/commits/{ref}/status`
530combines them) and check runs (`POST {repo}/check-runs` with `name`,
531`head_sha`, `status`, `conclusion`, `output` {`title`, `summary`,
532`text`, `annotations`}, `actions`; `PATCH {repo}/check-runs/{id}` to
533complete one). A required check is met by a status or a check run of its
534name. g1t's agents read checks and never report them. Guide:
535https://docs.g1t.sh/guides/checks/
Secrets and variables: one list, rows per environment, for workflows and deployments536Secrets and variables are one list per repository (site:
537`g1t.sh/<owner>/<repo>/settings/secrets`) and per workspace: each row is a
538key, Secret or Config, the environments it applies to (all, or e.g.
539production/preview, or a job's `environment:`), and whether workflows,
540deployments or both read it. API: `{repo}/actions/secrets` and
541`{repo}/actions/variables` (GitHub's routes) with extra `environments`,
Merge branch 'worktree-agent-a3abfcce648e87dca'542`available_to`, `repositories`, `note`, `id`. Every job gets
543`secrets.G1T_TOKEN` (`GITHUB_TOKEN` is its alias): a token for that job
544only, reaching its repository only, with the scopes its `permissions:`
545give (default `contents: read`, `packages: read`), revoked when the job
546ends; what it changes starts no workflows except `workflow_dispatch` and
547`repository_dispatch` (`POST {repo}/dispatches`). It cannot change
548secrets. A job naming an environment with protection rules (required
549reviewers, wait timer, branch limits; `PUT {repo}/environments/{name}`)
550waits until they pass, and reviewers approve it at
551`POST {repo}/actions/runs/{id}/pending_deployments`. A pull request's
552runs from outside may wait as `action_required` until someone with Write
553approves them (`POST {repo}/actions/runs/{id}/approve`); agents cannot
554approve runs or deployments. A pull request's runs and preview are trusted
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look555only when its author has `write` or higher on the repository (a member or
g1t is the stored author of what it opens; the person who asked is requested_by and keeps the author's rights556an outside collaborator), or is g1t working on its own; for one g1t made,
557the role of whoever asked for it (`requested_by`) counts. Anyone else's run
558with config only. Guide:
Secrets and variables: one list, rows per environment, for workflows and deployments559https://docs.g1t.sh/guides/secrets-and-variables/
Docs: merge_group in the merge queue and Actions guides560
Fast pages, required checks on the branch, self-hosted runners, honest incidents561Self-hosted runners: a job with `runs-on: self-hosted` (or
562`[self-hosted, linux, gpu]`, or `{group: name}`) waits until a runner of the
563workspace's with every label takes it. Owners add one under
564`g1t.sh/<workspace>/-/runners`: a one-hour registration token, then
565`g1t-runner register --url https://g1t.sh --token g1trt_…` and
566`g1t-runner run`. Runners only connect out. API:
567`/workspaces/{workspace}/actions/runners`, `.../runner-groups`,
568`.../runner-settings` (and the same under `{repo}/actions/` for a
569repository's own); MCP: the `workflow` tool's `list_runners`,
570`create_runner_token`, `remove_runner`, runner group and settings actions
571(`runners:read`/`runners:admin`). Pull requests from forks never run on them
572unless allowed. Guide: https://docs.g1t.sh/guides/self-hosted-runners/
573
Projects: what a workspace builds and runs, first on every page574## Projects
575
576A project is what a workspace builds and runs; every repository is a
577project of its own name (`g1t.sh/<owner>/<project>` opens its overview; its
578code is under `/code`; every repository address still works). Deployments,
579secrets and variables belong to the project; branches, pull requests,
580review and merge rules to its repository (Settings → Repository). Guide:
581https://docs.g1t.sh/guides/projects/
582
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API583## Security
584
585A push that adds a known key or token format (AWS, GitHub, GitLab, Stripe
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily586live, Slack tokens and webhooks, Google, Anthropic, OpenAI, npm, g1t,
587SendGrid, PEM private keys, service-role JWTs) is refused with every secret
588listed by `file:line` in git's output and a link to allow it; this includes
589an agent's push to its pull request. A very large push is scanned after it
590lands, not before: it goes through, its new commits (any branch) are
591scanned in the background, and a secret found is an open alert, emailed to
592the workspace's owners when it looks real. History is scanned once in the
593background. Never commit a secret: read it from the environment. Values are
594judged by the value alone, never the file's path: a documented example key,
595a value containing example/sample/dummy/fake/placeholder/changeme/notreal/
596redacted/xxxxx, one that counts up (six or more, like 123456), one
597character five or more times, a repeated short piece, or too little
598randomness is a "likely test value": listed apart, never blocks a push,
599never counted critical. Any other fixture carries `g1t:allow-secret` in a
600comment on its line. Alerts are `open`, `dismissed` or `fixed`. Dismissing a
601secret alert needs `admin`, with a reason (`false_positive`,
602`used_in_tests`, `wont_fix`: dismissed, and pushes carrying it go through;
603`revoked`: fixed) and an optional comment (500 characters); a dependency
604alert needs `write` (`fix_started`, `no_bandwidth`, `tolerable_risk`,
605`inaccurate`, `not_used`). Reopen undoes it. API:
606`GET {repo}/security/alerts` (`state`, `kind`),
607`POST {repo}/security/alerts/{id}/dismiss` (`reason`, `comment`),
608`POST {repo}/security/alerts/{id}/reopen`; MCP `repository` actions
609`security_alerts`, `dismiss_alert`, `reopen_alert` (`repo:read` to list,
610`repo:admin` to dismiss or reopen). Lockfiles (npm, pnpm, yarn, Cargo, Go,
611Python) on the default branch are checked against OSV on every push to it
612and daily. Security updates (on by default; `maintain` turns them off): for
613each vulnerable dependency with a fix, g1t itself opens a pull request
614authored by `g1t` from `g1t/security/<package>-<version>`, raising the
615version in each lockfile with the ecosystem's own tool; it merges through
616the branch's required checks and merge queue. A newer update for the same
617package, or the package no longer being vulnerable, closes it as
618superseded. Only when the bump fails, or required checks fail because code
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent619must change, does g1t open an issue and assign it to g1t (the session
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily620shows "started by g1t"). With no fix published, the alert links the
621advisory and is checked again daily. `.g1t/dependencies.yml` (version
622updates) is read and validated, but no version update pull requests are
623opened yet. `g1t` is not an account and cannot be signed in to.
Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API624Guide: https://docs.g1t.sh/guides/security/
625
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar626The security suite (scopes `security:read`, `security:write`; MCP tool
627`security`). A push refused for a secret links to its alert, where anyone
628with `write` bypasses it with a reason (`false_positive`, `used_in_tests`,
629`will_fix_later`), or asks owners when the workspace delegates bypasses;
630an agent never bypasses: take the secret out and push again. Code
631scanning: upload SARIF 2.1.0 to `POST {repo}/code-scanning/sarifs`
632(`commit_sha`, `ref`, `sarif` gzipped then base64); default-branch results
633become alerts, pull request results (`refs/pull/<n>/head`) become line
634comments and the `Code scanning` status. `Dependency review` is a status on
635every pull request that changes a lockfile. Fix what either reports in your
636own pull request; both can be required checks. Also: custom patterns,
637validity checks, `GET {repo}/dependency-graph/sbom` (SPDX 2.3, in `sbom`),
638`GET {repo}/dependency-graph/compare/{base...head}`, and a workspace
Pricing says it plainly: models at the provider's price, the agent rate for what g1t runs around every model call (the gateway, secrets, routing, context and pass-through to your own provider, so your own keys too), everything else at cost plus 20%, your own runners free, no seats; Security and quality comes with the plan with no separate fee, and live activations end. Each agent has an effort setting, Auto to Max, with what a typical task has cost at each level, and Spend's Spend less, keep quality suggests a lower level only when the agent's own past work shows quality held, to apply or dismiss. The pricing, spend and agents guides say how.639overview. On private repositories these come with the g1t plan, with no
640price of their own (`402` without it); public repositories have them free.
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar641Guides: https://docs.g1t.sh/guides/security/secret-protection/,
642https://docs.g1t.sh/guides/security/code-scanning/,
643https://docs.g1t.sh/guides/security/supply-chain/
644
Deployments: a preview for every pull request, production on g1t.page645## Deployments
646
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look647Part of the g1t plan ($20 a month per workspace, started by an owner
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas648under the workspace's Billing). No quotas: unlimited projects and
649previews (never charged); builds by the second, requests ($0.36/M), CPU
650($0.024/M ms) and custom domains ($0.12 a month each) metered from the
651first at cost + 20%, from the plan's $10 first. The trial
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look652never covers deployments. Then someone with admin on the repository
Projects: what a workspace builds and runs, first on every page653turns deployments on for a project (Settings → Deployments, or Deploy on
654its overview). Production deploys from the default branch to
655`https://<project>-<owner>.g1t.page` on each push; every branch with an
656open pull request gets a preview at
657`https://<project>-git-<branch>-<owner>.g1t.page` (a fork's pull request is
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily658`pr-<n>`), shown on it as the check `g1t / deploy` (`g1t / deploy (<project>)`
659for a workspace's other projects). Builds and running apps
Projects: what a workspace builds and runs, first on every page660read the project's secrets and variables available to Deployments, each
661key's Production or Preview row. Workers projects (`wrangler.jsonc`) and
662static sites build without configuration. Previews come down when the pull
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97663request closes and after idle days.
Projects: what a workspace builds and runs, first on every page664Guide: https://docs.g1t.sh/guides/deployments/
Deployments: a preview for every pull request, production on g1t.page665
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97666A repository's deployments, wherever they run, are one list: `source` is
667`api` (reported from any CI), `actions` (a g1t Actions job with
668`environment:`) or `g1t_page` (g1t.page builds, ids `dpl_…`, environments
669`production` and `preview`). Read with `GET {repo}/deployments` (filters
670`environment`, `ref`, `sha`, `task`, `state`, `source`, `creator`, `page`,
671`per_page`), `GET {repo}/deployments/{id}`, `GET {repo}/deployments/{id}/statuses`,
672`GET {repo}/environments` and `GET {repo}/environments/{environment}`
673(`deployments:read`, Read role). Report from a CI with
674`POST {repo}/deployments` (`ref`, optional `environment` (default
675`production`), `sha`, `task`, `description`, `payload`, `state`,
676`environment_url`, `log_url`), then
677`POST {repo}/deployments/{id}/statuses` with `state` (`queued`,
678`in_progress`, `success`, `failure`, `error`, `inactive`) and
679`environment_url` (`deployments:write`, Write role). A success makes the
680environment's older successful deployments `inactive` unless
681`auto_inactive: false`. Each status sets the commit check
682`deploy / <environment>`, which a ruleset's `required_deployments` rule can
683require. A g1t Actions job with `environment:` (or `{name, url}`) reports
684by itself, one deployment per run and environment; `deployment: false`
685opts out. MCP: the `workflow` tool's `list_deployments`, `get_deployment`,
686`create_deployment`, `deployment_statuses`, `create_deployment_status`,
687`list_environments`, `get_environment`. Webhooks: `deployment.created`,
688`deployment_status.created`. Guide: https://docs.g1t.sh/guides/deployments-api/
689
Search across all of g1t, Explore, and a command palette690## Search
691
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step692`GET https://api.g1t.sh/search?q=<query>&type=<type>` (MCP: `search`, action `code`, the default)
Search across all of g1t, Explore, and a command palette693searches all of g1t: repositories (name, description, topics, README), code
694on default branches, issues, pull requests, people and workspaces. No token
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look695needed for public results; with one, private results the token's person
696can read are included (their workspaces' repositories, and those they were
697given a role on), checked against current membership and roles. `type` is
Search across all of g1t, Explore, and a command palette698`repositories`, `code`, `issues`, `pulls` or `people` (worked out from the
699qualifiers when left out); `page` and `per_page` (at most 50) page through.
700The query takes words, `"exact phrases"`, `-word` to leave out, and
701`repo:owner/name`, `org:<workspace>`, `language:<lang>`, `path:<prefix or
702*.glob>`, `is:issue`, `is:pr`, `is:open`, `is:closed`, `is:merged`,
703`author:<username>`, `label:<label>`. Code search matches any run of three
704characters or more; vendored directories, lockfiles, binaries and files
705over 512 KB are not indexed. Results give `counts` per type and each hit's
706`snippet` or code `lines` as parts with `highlight`. On the site:
707`https://g1t.sh/search?q=`, ⌘K, and `https://g1t.sh/explore` for public
708projects by activity, language (`?language=`) and topic (`?topic=`).
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step709The `search` tool's `context` action stays the search of one workspace's
710context hub. Guide:
Search across all of g1t, Explore, and a command palette711https://docs.g1t.sh/guides/search/
712
Docs: merge_group in the merge queue and Actions guides713## Facts
714
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily715- API base: `https://api.g1t.sh`. `GET /` lists the main URLs as templates;
716 every operation is in the OpenAPI document.
Docs: merge_group in the merge queue and Actions guides717 Auth: `Authorization: Bearer g1t_…`. Public data needs no token. Errors are
718 `{"error": {"code": "…", "message": "…"}}` with codes `unauthenticated`
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily719 (401), `payment_required` (402, when the plan or a limit refuses compute),
720 `forbidden` (403, with `needed_scope` when the token lacks a
Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails721 scope), `not_found` (404), `conflict` (409), `invalid` (422),
722 `rate_limited` (429, with `Retry-After`: 1,000 requests a minute per
723 token, 60 per IP address without one; wait, then retry). Each
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step724 operation's scope is `x-scope` in the OpenAPI document. The full description is at https://api.g1t.sh/openapi.json.
Docs: merge_group in the merge queue and Actions guides725- Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths,
726 `{owner}` is the workspace. Pull request forks:
727 `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available.
What g1t can't do yet, and an open letter to Cloudflare728- Limits: 1 GB per repository, 32 MB per file, 100 MB per push. Every
729 current limit, why it exists and the workaround:
730 https://docs.g1t.sh/about/limitations/
Docs: merge_group in the merge queue and Actions guides731- Forgotten password: https://g1t.sh/forgot (the person does this, in a
732 browser).
733- Times are RFC 3339 in UTC.
734- OAuth 2.1 for applications: metadata at
735 `https://api.g1t.sh/.well-known/oauth-authorization-server`; authorization
736 code with PKCE (S256), public clients, dynamic registration.
Fast pages, required checks on the branch, self-hosted runners, honest incidents737- A pull request whose required checks have not passed (failed, still
738 running, or not reported yet) is refused a merge with `409`, saying
739 which; where the repository allows bypassing them
740 (`allow_ignoring_checks`), someone who can merge can send
741 `{"ignore_checks": true}`. Checks that are not required never hold a
742 merge. With the merge queue on, the workflows behind required checks
743 need `merge_group` in their `on:`.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily744- Landing fast-forwards the default branch: g1t makes no merge commit on
745 main. Bringing a pull request up to date makes a merge commit on its own
746 branch.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look747- Pricing (https://g1t.sh/pricing): the forge is free. One plan, g1t, at
748 $20 a month per workspace with unlimited members, includes $10 of usage
749 at cost + 20% (unused does not roll over). Compute needs the plan or a
750 card check (never charged); the $5 trial needs a credit or debit card,
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas751 not a prepaid one. No quotas on the plan: everything is metered from the
752 first unit at cost + 20%, and only the spend limit stops work. Every
753 workspace has 1 GB of private storage and 50,000 git operations a month
754 free; past them, the plan pays ($0.60/GB-month, $0.18/1,000) and a free
755 workspace is held (pushes to private repositories stop; git slowed to 60
756 an hour). Limits: $100 in a
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look757 paid workspace's first month, rising as payments clear; owners set a
758 spend limit, prepay, or ask with Raise my limit. Caps: $2 a run and $10
759 an issue by default. A spend spike pauses new compute until an owner
760 chooses Keep going or Stop (`/<workspace>/-/billing`). Audit log: 90 days
761 on every plan.
Docs: merge_group in the merge queue and Actions guides762
763## More
764
765- [Quickstart](https://docs.g1t.sh/quickstart/)
766- [How g1t works](https://docs.g1t.sh/concepts/overview/)
Search across all of g1t, Explore, and a command palette767- [Search and Explore](https://docs.g1t.sh/guides/search/)
g1t is one name: its agent's work, commits and comments show as @g1t, and nobody can claim g1t or g1t-agent768- [g1t's agent](https://docs.g1t.sh/guides/working-with-g1t/)
Docs: merge_group in the merge queue and Actions guides769- [Outcomes and plans](https://docs.g1t.sh/guides/outcomes/)
770- [Talking to agents](https://docs.g1t.sh/guides/talking-to-agents/)
771- [Bring your own agent](https://docs.g1t.sh/guides/bring-your-own-agent/)
The Artifacts guide explains home, the sidebar, sharing and access requests, Private, spaces with Editors can share, docs, agents and writing a thread up, links in chat, history, templates, the trash and export, in place of the Docs guide, whose links now go to it.772- [Artifacts](https://docs.g1t.sh/guides/artifacts/)
Agents → Skills is the workspace's skill library in the open SKILL.md format: write a skill in g1t, import a SKILL.md or zip, link a repository whose .g1t/skills folders publish on every push, or save a finished session as a skill once a person reviews it; attach a skill to an agent, a team or the whole workspace, each attachment pinned to a version. Agents see each skill's name and when to use it, and read the rest with use_skill when a request needs it; a skill never adds a permission, and scripts wait for an agent's own computer. The agent skills guide says how.773- [Agent skills](https://docs.g1t.sh/guides/agent-skills/): every workspace agent makes PDFs, Word documents and spreadsheets (`make_file`), writes reports with sources, charts data and reviews code, with the tools it already has; a workspace's own skills live in its skill library in the open SKILL.md format (written, imported, saved from a session or kept in `.g1t/skills/` in a repository), attached to agents, teams or every agent at a pinned version; agents see each skill's name and when to use it and read it with `use_skill`
Docs: merge_group in the merge queue and Actions guides774- [The merge queue](https://docs.g1t.sh/guides/merge-queue/)
775- [Sessions and why-blame](https://docs.g1t.sh/guides/why-blame/)
776- [Forks and branches](https://docs.g1t.sh/concepts/forks/)
777- [Accounts and sign-in](https://docs.g1t.sh/guides/authentication/)
778- [Workspaces and tokens](https://docs.g1t.sh/guides/workspaces/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look779- [Access and roles](https://docs.g1t.sh/guides/access-and-roles/)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar780- [Teams](https://docs.g1t.sh/guides/teams/)
People and teams are front and centre: one directory of people and agents with presence, local time, titles, teams and what each owns; profiles with manager and reports and the agents they work with; an org chart with each team's agents beside the person who leads it; and teams of any mix, with a lead, a channel, a budget agents keep to and the agents on them. Every agent is told its teams each turn (who leads, who owns what, who's around and who to page), and the team page shows exactly what. Member management is Members and invites; the people and teams guide says how.781- [People and teams](https://docs.g1t.sh/guides/people-and-teams/)
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar782- [CODEOWNERS](https://docs.g1t.sh/guides/codeowners/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look783- [Managing a repository](https://docs.g1t.sh/guides/managing-repositories/)
Docs: merge_group in the merge queue and Actions guides784- [Integrations](https://docs.g1t.sh/guides/integrations/)
785- [Model providers](https://docs.g1t.sh/guides/models/)
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens786- [AI Gateway](https://docs.g1t.sh/guides/ai-gateway/)
Docs: merge_group in the merge queue and Actions guides787- [Webhooks](https://docs.g1t.sh/guides/webhooks/)
788- [GitHub Actions](https://docs.g1t.sh/guides/actions/)
Fast pages, required checks on the branch, self-hosted runners, honest incidents789- [Self-hosted runners](https://docs.g1t.sh/guides/self-hosted-runners/)
Docs: merge_group in the merge queue and Actions guides790- [Usage and billing](https://docs.g1t.sh/guides/usage-and-billing/)
791- [Git](https://docs.g1t.sh/guides/git/)
792- [MCP tools](https://docs.g1t.sh/reference/mcp/)
Merge branch 'worktree-agent-ab2e39e11a6493412'793- [API reference](https://docs.g1t.sh/reference/api/)
Merge branch 'worktree-agent-a8752162fea25f63f' into spend-guardrails794- [Rate limits](https://docs.g1t.sh/reference/rate-limits/)
What g1t can't do yet, and an open letter to Cloudflare795- [What g1t can't do yet](https://docs.g1t.sh/about/limitations/)
796- [An open letter to Cloudflare](https://docs.g1t.sh/about/open-letter-to-cloudflare/)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look797- [Source](https://g1t.sh/flagon-io/g1t), MIT licensed
798
799## Help, status and policies
800
status.g1t.sh with incident management, invites that land you in the workspace, settings as pages, usage without quotas801- [Status](https://status.g1t.sh/): whether each part of g1t is working now, 90 days of uptime, and incidents; the same as JSON at https://status.g1t.sh/status.json
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily802- [Support](https://g1t.sh/support): where to get help (hey@flagon.io)
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look803- [Security](https://g1t.sh/security): how g1t protects code and accounts, and responsible disclosure (hey@flagon.io, https://g1t.sh/.well-known/security.txt)
804- [Policies](https://g1t.sh/policies): [Terms of Service](https://g1t.sh/policies/terms), [Privacy Policy](https://g1t.sh/policies/privacy), [Acceptable Use](https://g1t.sh/policies/acceptable-use), [Refunds and Cancellation](https://g1t.sh/policies/refunds), [Subprocessors](https://g1t.sh/policies/subprocessors)
805- g1t is made by Flagon, Inc. (https://www.flagon.io)

This file's history is long; its oldest lines are credited to the oldest commit read.