g1t/apps/docs/src/content/docs/guides/authentication.md

96 lines3,593 bytesCodeBlame
1---
2title: Accounts and authentication
3description: Accounts, email confirmation, access tokens and password reset.
4---
5
6## Creating an account
7
8Register at [g1t.sh/register](https://g1t.sh/register). Usernames are
9lowercase letters, digits and single hyphens, up to 39 characters.
10
11Accounts can only be created in a browser. There is no API for it, by
12design: it keeps passwords out of scripts and agents, and lets g1t protect
13the one place accounts are made.
14
15## Confirming your email
16
17g1t sends a confirmation link from `noreply@g1t.sh`. It works for 24 hours.
18
19Until you follow it you can sign in and look around, but you cannot create
20repositories, push, or open issues and pull requests. Those requests fail with `403` and a
21message telling you to confirm your address. To get a new link, sign in and
22use the banner at the top of the site.
23
24## Workspaces
25
26A workspace owns repositories and is the first part of their address:
27`g1t.sh/<workspace>/<repo>`. There is one kind. A workspace for just you and
28one for a company are the same thing with a different number of members, so
29there is no separate notion of an organization.
30
31Your account does not own repositories itself. After confirming your email
32you create a workspace, which can have the same name as your username, and
33repositories go in it. You can belong to up to ten.
34
35| Role | Can |
36| --- | --- |
37| Member | Create repositories, push, manage issues, merge pull requests. |
38| Owner | Everything a member can, and add or remove members. |
39
40Manage members on the workspace's page, `g1t.sh/<workspace>`.
41
42## Access tokens
43
44A token stands in for your password everywhere outside the website:
45
46| Where | How to send it |
47| --- | --- |
48| git | As the password, with your username. |
49| API | `Authorization: Bearer g1t_…` |
50| MCP | The same header, set when you add the server. |
51
52Create one in [Settings](https://g1t.sh/settings). A token is shown once,
53when it is created; g1t stores only a hash of it. If you lose one, delete it
54and create another. Delete a token the moment you think someone else has
55seen it.
56
57A token has the full rights of your account. Scoped tokens are planned.
58
59## Signing in from a tool
60
61An agent or command-line tool gets a token without ever handling your
62password, the same way `gh auth login` works:
63
641. The tool asks g1t for a code and shows you a link and a short code such
65 as `WDJB-MJHT`.
662. You open the link, sign in (or create an account), check that the code
67 matches, and approve.
683. The tool collects its token.
69
70```sh
71# 1. The tool starts a sign-in.
72curl -X POST https://api.g1t.sh/v1/device/code -H "Content-Type: application/json" -d '{"client_name": "my-tool"}'
73
74# 2. You open verification_uri_complete from the response and approve.
75
76# 3. The tool polls, no faster than "interval" seconds, until it is approved.
77curl -X POST https://api.g1t.sh/v1/device/token -H "Content-Type: application/json" -d '{"device_code": "…"}'
78```
79
80The poll answers with a `status` of `pending`, `approved`, `denied` or
81`expired`. An approved answer carries the token, once. Codes expire after 15
82minutes. The token appears in your settings under the tool's name, where you
83can delete it.
84
85Only approve a code you asked for. Approving gives the tool the full rights
86of your account.
87
88## Resetting your password
89
90Use [g1t.sh/forgot](https://g1t.sh/forgot). The emailed link works for one
91hour. Setting a new password signs you out everywhere.
92
93## What g1t stores
94
95Passwords are stored as salted PBKDF2-SHA256 hashes. Sessions and tokens are
96stored as SHA-256 hashes. Neither can be read back.