Skip to content
233 linesCodeBlameRaw

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

API and MCP server, Rust identity service, registration, site redesign1# g1t
2
Chat and workspace agents: channels, DMs and named agents you talk to3One open-source workspace where a team and its agents talk, work, write
4things down and ship. No separate chat app, wiki or forge to stitch
5together. It runs on Cloudflare Workers and Artifacts.
Agents as a team: lifecycle, merge queue, billing and a new shell6
Chat and workspace agents: channels, DMs and named agents you talk to7- **Chat.** Channels, direct messages and threads, live. People and agents
8 are members alike: DM an agent, or mention it in a thread, and it answers
9 there. Chat is included on every plan, with no seats and no history
10 cutoff.
11- **Agents.** A workspace's own agents, each with a role, a job, a
12 personality, limits on which models Auto may route it to (including the
13 workspace's own providers) and a budget. Start from templates: planner,
14 implementer, reviewer, triage, documenter, release manager, on-call.
15- **Docs** (coming soon). Specs, runbooks and decisions, written together,
16 read by agents and kept current by them.
17- **Code.** Git over HTTPS, issues, pull requests and reviews. Assign an
18 issue to g1t or connect any coding agent over MCP; hand g1t an outcome and
19 a planner splits it into issues that agents take up as they unblock.
20 Checks run by g1t in clean sandboxes, workflows from `.g1t/workflows`, a
21 merge queue that tests changes together, why-blame from any line to the
22 session that wrote it, and a preview of every pull request on `g1t.page`.
23- **Rails.** Budgets per workspace, agent and task; agents act with the
24 asker's access and answer only with what their audience may see;
25 approvals for merges and production deploys; an audit log on every
26 workspace.
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look27- **Open and fair.** MIT licensed and self-hostable (an early Docker Compose
Chat and workspace agents: channels, DMs and named agents you talk to28 version of the core forge, in `deploy/self-host`). People chat free and
29 the forge is free; agents pay the model's price plus a flat agent rate,
30 and other compute is what it costs plus 20%, never per seat.
31
32The plan for the workspace is [docs/WORKSPACE.md](docs/WORKSPACE.md).
Agents as a team: lifecycle, merge queue, billing and a new shell33
Invite-only launch: sign in with GitHub, repository access and lifecycle, many emails, a new look34g1t is made by Flagon, Inc. It is also an entry in Cloudflare's **Build the
35Next-Gen Git Platform** competition, which asks what a git platform looks
36like when many of the people using it are agents
37([the challenge](https://blog.cloudflare.com/next-git-platform-on-cloudflare/),
38[rules and dates](https://www.cloudflare.com/git-competition/)).
39[docs/PLAN.md](docs/PLAN.md) says how g1t answers the brief and what is
40built so far.
Agents as a team: lifecycle, merge queue, billing and a new shell41
42## Where things are
43
API and MCP server, Rust identity service, registration, site redesign44- Site: <https://g1t.sh>
Issues and pull requests replace intents and attempts45- Docs: <https://docs.g1t.sh>
API and MCP server, Rust identity service, registration, site redesign46- API: <https://api.g1t.sh> · MCP: <https://mcp.g1t.sh>
47- Plan and design: [docs/PLAN.md](docs/PLAN.md)
Agents as a team: lifecycle, merge queue, billing and a new shell48- Demo walk-through: [docs/DEMO.md](docs/DEMO.md)
API and MCP server, Rust identity service, registration, site redesign49
50## Status
51
52Working today:
53
OAuth 2.1 sign-in for MCP clients and other applications54- Accounts with email verification and password reset. Applications sign
55 in through the browser with OAuth 2.1, so connecting an MCP client needs
56 no pasted token; tools without a browser use a device code.
Agents as a team: lifecycle, merge queue, billing and a new shell57- Workspaces that own repositories, with members and roles. Every account
58 creates one before anything else, and usernames and workspaces share one
59 namespace.
60- Access tokens that belong to a workspace instead of a person, for CI and
61 integrations, so nothing needs a shared service account.
Issues and pull requests replace intents and attempts62- Public and private repositories, and git over HTTPS, including creating a
63 repository by pushing to it.
Fast pages, required checks on the branch, self-hosted runners, honest incidents64- Issues with labels and comments; a description can say what done means,
65 under a Definition of done.
Pull requests from branches66- Pull requests with a diff and a recorded agent session: in a
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise67 fork of their own, which is how agents work, or from a branch pushed to
Pull requests from branches68 the repository. Several can be made for one issue.
Fast pages, required checks on the branch, self-hosted runners, honest incidents69- Checks: the repository's workflows run on every pull request, a
70 person's or an agent's, and report a check each. The default branch
71 names the required checks a merge needs; an agent whose change fails a
72 check is sent back with the failing jobs' logs. A repository with no
73 workflows gets a starter CI workflow in one click.
Acceptance checks in sandboxes, line comments and review verdicts74- Review: comments on lines of a change, and approve or request-changes
75 verdicts, from people and from agents.
Agents as a team: lifecycle, merge queue, billing and a new shell76- Overlap: each pull request shows which others in progress change the
77 same files, while the work is still going on.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily78- Catch-up: when `main` has moved under a pull request, g1t merges it in,
Cleanup: clippy is quiet outside billing, the README says g1t, and http-cache-semantics is 4.3.079 and g1t resolves any conflict.
80- Reviews written by g1t, on request: line comments, a summary and
Agents as a team: lifecycle, merge queue, billing and a new shell81 a verdict.
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily82- Importing a public repository from any git host by its address, and
83 public or private repositories through g1t's GitHub App, imported once,
84 mirrored, or pushed back to GitHub.
Issues and pull requests replace intents and attempts85- Merging: lands a pull request on `main`, closes its issue naming the pull
86 request that resolved it, and closes the others for that issue as
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily87 superseded. When `main` has moved, the pull request is brought up to date
88 first, or refused where the repository requires that, so no commit is
89 lost.
Issues and pull requests replace intents and attempts90- g1t agents: g1t's own agents working on an issue in sandboxes on
README says what is working today; the free allowance says what it covers91 Cloudflare Containers, seeing each pull request through checks, an
92 agent's review, revisions and catch-up.
93- Outcomes: a brief planned into issues with dependencies, which agents
94 take up as their dependencies land.
95- The merge queue: pull requests tested together with what is ahead of
96 them before they land, with failures sent back to the agent that wrote
97 them. Required approvals and checks per repository.
98- Checks in detail on every pull request, and conflicts worked out on
99 every push, before a merge is tried.
100- Agents as records: every run with its live steps, cost and session, Stop
101 and Message, and memory at two levels (project and workspace) that
102 agents write and read.
103- Projects with deployments on g1t.page: a preview for every pull request,
104 production on merge, dependencies between projects, custom domains.
105- GitHub Actions workflows from `.g1t/workflows`, secrets and variables,
106 webhooks and integrations (Sentry, Datadog, Jira, Linear).
107- Profiles, workspaces with display names, icons and renameable slugs.
108- Usage billing with no seats: what it costs g1t plus a markup, a public
109 price book, usage limits and itemised invoices.
Issues and pull requests replace intents and attempts110- A REST API, an OpenAPI document and an MCP server over the same operations.
API and MCP server, Rust identity service, registration, site redesign111- An event bus: every state change is published, logged and delivered to
112 subscribers.
113
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily114Not built yet: what the Soon pages in each project's menu describe. Git
115over SSH waits on inbound TCP on port 22, which on Cloudflare
Say why git over SSH is not on yet116means Workers inbound TCP, a beta g1t has applied for and is waiting on.
117Use HTTPS until then. See the build order in the plan.
API and MCP server, Rust identity service, registration, site redesign118
119## Try it
120
121```sh
OAuth 2.1 sign-in for MCP clients and other applications122# 1. Create an account and a workspace at https://g1t.sh/register.
API and MCP server, Rust identity service, registration, site redesign123
OAuth 2.1 sign-in for MCP clients and other applications124# 2. Connect Claude Code, then run /mcp in it to sign in through your browser.
125claude mcp add --transport http g1t https://mcp.g1t.sh
API and MCP server, Rust identity service, registration, site redesign126
Issues and pull requests replace intents and attempts127# 3. Ask it to open a pull request for an open issue.
API and MCP server, Rust identity service, registration, site redesign128```
129
Issues and pull requests replace intents and attempts130[Getting started](https://docs.g1t.sh/quickstart/) walks through this in
131full. An assistant can do it for you from <https://g1t.sh/llms.txt>.
API and MCP server, Rust identity service, registration, site redesign132
133## Layout
134
README: the layout table gives each part's language in its own column135| Path | What it is | Language |
136| --- | --- | --- |
137| `apps/web` | The site: server-rendered React on a Worker. Holds no data. | TypeScript |
138| `apps/docs` | The documentation site, with the API explorer. | TypeScript |
139| `apps/api` | REST API and MCP server. | Rust |
140| `services/identity` | Accounts, workspaces, sessions, keys and tokens. | Rust |
141| `services/repos` | Repository registry, contents, forks, diffs, landing, git over HTTPS. | Rust |
142| `services/work` | Issues, pull requests, reviews, check runs and sessions. | Rust |
143| `services/events` | The event bus and its log. | Rust |
144| `services/search` | Site-wide search and Explore. | Rust |
145| `services/billing` | Usage, the price book, limits, invoices and payments. | Rust |
146| `services/actions` | GitHub Actions workflows, runs, caches and self-hosted runners. | Rust |
147| `services/security` | Push protection findings, history scanning and dependency upkeep. | Rust |
148| `services/integrations` | Model providers, alerts, trackers and the GitHub App. | Rust |
149| `services/webhooks` | Webhook deliveries. | Rust |
150| `services/runner` | Starts sandboxes: for g1t agents, workflow jobs and the merge queue. | TypeScript |
151| `services/projects` | Projects and the dependencies between them. | TypeScript |
152| `services/deployments` | Builds, previews and production on `g1t.page`. | TypeScript |
153| `services/pages` | Serves every app deployed on `g1t.page`, and custom domains. | TypeScript |
154| `services/models` | The model proxy at `models.g1t.sh`. | TypeScript |
155| `services/context` | The context hub: catalog, search and scorecards. | TypeScript |
156| `services/og` | Social cards at `og.g1t.sh`: a PNG per page, showing only what anyone may see. | TypeScript |
157| `apps/status` | The status page at `status.g1t.sh`. | TypeScript |
158| `apps/sudo` | g1t's own staff console. | TypeScript |
159| `crates/runner` | The program inside a sandbox: runs an agent, a workflow job or a merge queue build, and reports back. | Rust |
160| `crates/contracts` | Types and service interfaces for the Rust services. | Rust |
161| `crates/kit` | Plumbing shared by Rust services on Workers. | Rust |
162| `crates/actions` | Reads workflows and evaluates their expressions. | Rust |
163| `crates/scan` | Secret and lockfile scanning, shared by services. | Rust |
164| `crates/secrets` | Secrets at rest and signatures. | Rust |
165| `crates/sshd` | Git over SSH, bridged to Artifacts. Not deployed yet. | Rust |
166| `packages/contracts` | The same interfaces for TypeScript callers. | TypeScript |
167| `packages/theme` | Design tokens and the logo, shared by the site and the docs. | CSS |
168| `deploy` | `stack.jsonc`, every deployable part and its resources; `self-host`, the Docker Compose version. | JSON, Docker Compose |
API and MCP server, Rust identity service, registration, site redesign169
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily170Each service is its own Worker, and each one that keeps data has its own
171database. They call each other through service bindings and react to each
172other through events. The core services (accounts, repositories, work,
173events, billing, Actions, security and the API) are written in Rust; the
README: the layout table gives each part's language in its own column174web apps and the rest of the Workers in TypeScript. The Language column
175says which, part by part.
API and MCP server, Rust identity service, registration, site redesign176
177## Run your own
178
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise179### On your own machine
180
181The core forge runs in Docker, with no Cloudflare account:
182
183```sh
184docker compose -f deploy/self-host/docker-compose.yml up --build
185```
186
187Then open http://localhost:8787 and sign up. The confirmation mail is in
Merge branch 'worktree-agent-aaf03bdceac799c89'188Mailpit at http://localhost:8025. Repositories, push and clone, issues,
189pull requests and code browsing work, and the API and MCP server answer at
Merge branch 'worktree-agent-af58ac8933b0dd125'190http://localhost:8789; packages and container images are kept in the
191bundled S3-compatible store, RustFS. Agents, deployments and context search
192are off in this version.
README: run the core forge locally with Docker Compose; forks described as copies, not copy-on-write, until Cloudflare says otherwise193[docs/SELF_HOSTING.md](docs/SELF_HOSTING.md) says what works and what is next.
194
195### On Cloudflare
196
API and MCP server, Rust identity service, registration, site redesign197You need a Cloudflare account on the Workers Paid plan (Artifacts requires
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily198it), Node 22.22 or newer (`engines` in `package.json`; g1t is built on
199Node 24), Rust with the `wasm32-unknown-unknown` target, and
Issues and pull requests replace intents and attempts200Docker to build the sandbox image.
API and MCP server, Rust identity service, registration, site redesign201
202```sh
203npm install
204npx wrangler login
205```
206
207Then, once:
208
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily2091. Create the resources each part needs: D1 databases, queues, KV
210 namespaces, R2 buckets and the Artifacts namespace (`npx wrangler d1
211 create <name>`, `npx wrangler queues create <name>`, and so on), and set
212 each part's secrets. `deploy/stack.jsonc` lists them all.
API and MCP server, Rust identity service, registration, site redesign2132. Put your own `account_id`, database ids and hostnames in each
214 `wrangler.jsonc`.
Deploy scripts live in the repository2153. For [Deployments](https://docs.g1t.sh/guides/deployments/), which needs
216 the Workers for Platforms add-on and a zone for apps:
217 `scripts/setup-deployments.sh`.
API and MCP server, Rust identity service, registration, site redesign218
Deploy scripts live in the repository219Deploy everything, migrations first, in dependency order:
API and MCP server, Rust identity service, registration, site redesign220
221```sh
Deploy scripts live in the repository222scripts/deploy.sh
API and MCP server, Rust identity service, registration, site redesign223```
224
Deploy scripts live in the repository225Or only what changed, still in order: `scripts/deploy.sh billing web`.
226Both use your `wrangler login`, not a token in `.env`.
227
API and MCP server, Rust identity service, registration, site redesign228Create the first account by registering on your site, or with
229`node services/identity/scripts/create-user.mjs <username>`.
230
231## License
232
233[MIT](LICENSE)

This file's history is long; its oldest lines are credited to the oldest commit read.