| 577 | 577 | | |
| 578 | 578 | | ## Access tokens |
| 579 | 579 | | |
| 580 | | − | A token stands in for your password everywhere outside the website: |
| 580 | + | A token stands in for your password everywhere outside the website, and on |
| 581 | + | the website too when you turn that on for it: |
| 581 | 582 | | |
| 582 | 583 | | | Where | How to send it | |
| 583 | 584 | | | --- | --- | |
| 584 | 585 | | | git | As the password, with your username. | |
| 585 | 586 | | | API | `Authorization: Bearer g1t_…` | |
| 586 | 587 | | | MCP | The same header, set when you add the server. | |
| 588 | + | | The website | The same header on every request, from automation that drives a browser. Only a token with **Use the website as you** turned on. See [use a token on the website](#use-a-token-on-the-website). | |
| 587 | 589 | | |
| 588 | 590 | | A token is shown once, when it is created; g1t stores only a hash of it. |
| 589 | 591 | | If you lose one, delete it and create another. Delete a token the moment |
| ⋯ |
| 627 | 629 | | 5. Under **Permissions**, set each resource the token needs to a level. |
| 628 | 630 | | **Read only**, **Agent** and **CI** fill in a [preset](#presets); |
| 629 | 631 | | **Clear** sets everything back to no access. |
| 630 | | − | 6. Select **Generate token**, and copy it. It is not shown again. |
| 632 | + | 6. Leave **Use the website as you**, under **Website**, off unless the |
| 633 | + | token is for automation that drives a browser. See |
| 634 | + | [use a token on the website](#use-a-token-on-the-website). |
| 635 | + | 7. Select **Generate token**, and copy it. It is not shown again. |
| 631 | 636 | | |
| 632 | 637 | | When you make a token for one workspace that |
| 633 | 638 | | [requires approval](#a-workspaces-rules-for-tokens), and you are not one of |
| ⋯ |
| 641 | 646 | | The list under Settings → Access tokens shows each token's name, status |
| 642 | 647 | | (pending, denied or revoked, with the owner's note), where it reaches, its |
| 643 | 648 | | permissions, and when it was made, last used and expires. Select a token to |
| 644 | | − | open its page, where you can change its name, description, repositories |
| 645 | | − | and permissions, and select **Save changes**. The token itself stays the |
| 649 | + | open its page, where you can change its name, description, repositories, |
| 650 | + | permissions and **Use the website as you**, and select **Save changes**. |
| 651 | + | A token that can use the website is marked **Uses the website**. The token |
| 652 | + | itself stays the |
| 646 | 653 | | same; the change applies from its next request. Widening a token made for |
| 647 | 654 | | a workspace that requires approval asks its owners again. Where it reaches |
| 648 | 655 | | and when it expires cannot change; make a new token instead. |
| 649 | 656 | | |
| 650 | 657 | | **Delete token**, at the bottom of its page, stops it working at once. |
| 651 | 658 | | |
| 659 | + | ### Use a token on the website |
| 660 | + | |
| 661 | + | Automation that drives a browser, such as end-to-end tests or an agent |
| 662 | + | checking how a page looks, can use g1t.sh as you with an access token, so it |
| 663 | + | never types your password or a two-factor code. Each request it makes |
| 664 | + | carries the token in the `Authorization` header; no cookie is set and no |
| 665 | + | session is started. |
| 666 | + | |
| 667 | + | 1. Open [Settings → Access tokens](https://g1t.sh/settings/tokens) and |
| 668 | + | select **New token**, or open a token you have. |
| 669 | + | 2. Give it an expiration, and the permissions it needs for git, the API and |
| 670 | + | MCP, if any. |
| 671 | + | 3. Under **Website**, tick **Use the website as you**. It is off unless you |
| 672 | + | tick it, and a workspace's own token cannot have it. |
| 673 | + | 4. Select **Generate token** (or **Save changes**), and keep the token in a |
| 674 | + | file only the automation can read. |
| 675 | + | 5. Send `Authorization: Bearer g1t_…` on every request to g1t.sh. |
| 676 | + | |
| 677 | + | With [Playwright](https://playwright.dev), set the header on the browser |
| 678 | + | context, reading the token from a file so it is never printed: |
| 679 | + | |
| 680 | + | ```js |
| 681 | + | import { readFileSync } from "node:fs"; |
| 682 | + | import { chromium } from "playwright"; |
| 683 | + | |
| 684 | + | const token = readFileSync(process.env.G1T_TOKEN_FILE, "utf8").trim(); |
| 685 | + | const browser = await chromium.launch(); |
| 686 | + | const context = await browser.newContext({ |
| 687 | + | extraHTTPHeaders: { authorization: `Bearer ${token}` }, |
| 688 | + | }); |
| 689 | + | const page = await context.newPage(); |
| 690 | + | await page.goto("https://g1t.sh/acme/rocket/pulls"); |
| 691 | + | await page.screenshot({ path: "pulls.png", fullPage: true }); |
| 692 | + | await browser.close(); |
| 693 | + | ``` |
| 694 | + | |
| 695 | + | `extraHTTPHeaders` sends the header with every request the page makes, |
| 696 | + | including to other addresses it loads files from. To send it to g1t.sh |
| 697 | + | only, add it per request instead: |
| 698 | + | |
| 699 | + | ```js |
| 700 | + | const context = await browser.newContext(); |
| 701 | + | await context.route("https://g1t.sh/**", (route) => |
| 702 | + | route.continue({ headers: { ...route.request().headers(), authorization: `Bearer ${token}` } }), |
| 703 | + | ); |
| 704 | + | ``` |
| 705 | + | |
| 706 | + | Any HTTP client works the same way: |
| 707 | + | |
| 708 | + | ```sh |
| 709 | + | curl -H "Authorization: Bearer $(cat ~/.config/g1t/website-token)" https://g1t.sh/acme/rocket/pulls |
| 710 | + | ``` |
| 711 | + | |
| 712 | + | On the website, the token acts as you in the workspaces it |
| 713 | + | [reaches](#where-a-token-reaches). Its permissions are made for git, the API |
| 714 | + | and MCP, and the website does not hold it to them: treat it as able to do |
| 715 | + | anything there that you can. Keep it as safe as your password, and give it |
| 716 | + | an expiration. |
| 717 | + | |
| 718 | + | - **Only the header counts.** A token in a query string or a cookie is |
| 719 | + | ignored. A request with the header is the token's, even if it also has a |
| 720 | + | session cookie. |
| 721 | + | - **Checked on every request.** Deleting the token, its expiry, or a |
| 722 | + | workspace [revoking it](#a-workspaces-rules-for-tokens) stops it at once. |
| 723 | + | - **A token that is not accepted is no one.** One that is not valid, has |
| 724 | + | expired, or does not have **Use the website as you** loads pages as |
| 725 | + | someone signed out, with a `WWW-Authenticate` header saying the token was |
| 726 | + | refused; the data requests and form posts pages make answer `401`. |
| 727 | + | - **Form posts need nothing more.** Browsers never send the header by |
| 728 | + | themselves, so a post with it needs no other proof it came from g1t.sh. |
| 729 | + | A post from another site is still refused. |
| 730 | + | - **Limits follow the token**: 1,000 requests a minute, as on the API. See |
| 731 | + | [rate limits](/reference/rate-limits/). |
| 732 | + | - **The audit log names it.** A change made this way is recorded as yours, |
| 733 | + | with the token's id under **Credential**. See [the audit log](/guides/audit-log/). |
| 734 | + | |
| 735 | + | Some things always need you to sign in on g1t.sh yourself. With a token, |
| 736 | + | these pages answer **This needs you to sign in** (`403`): |
| 737 | + | |
| 738 | + | | What | Where | |
| 739 | + | | --- | --- | |
| 740 | + | | Access tokens, yours and a workspace's, and a workspace's rules for and approvals of members' tokens | Settings → Access tokens; a workspace's Settings → Access tokens and Personal access tokens | |
| 741 | + | | Two-factor authentication | Settings → Two-factor authentication | |
| 742 | + | | Your username, and deleting your account | Settings → Account | |
| 743 | + | | Email addresses, which reset your password | Settings → Emails | |
| 744 | + | | SSH keys | Settings → SSH keys | |
| 745 | + | | Applications you signed in to, and signing in with GitHub | Settings → Connected applications, Settings → GitHub | |
| 746 | + | | Letting a device or an application sign in | `g1t.sh/device`, `g1t.sh/oauth/authorize` | |
| 747 | + | | Deleting a workspace, and giving it to another owner | A workspace's Settings and People | |
| 748 | + | | Payment methods: the billing portal, adding a card, subscribing and buying AI credit | A workspace's Billing | |
| 749 | + | |
| 652 | 750 | | ### Permissions |
| 653 | 751 | | |
| 654 | 752 | | A permission is a resource and a level. A higher level includes the lower |