pr_01m47d15m3e54sn21z27rpy5n9/apps/web/public/llms.txt
| 1 | # g1t |
| 2 | |
| 3 | > g1t (https://g1t.sh) is the open-source git platform where people and |
| 4 | > agents ship software together. It is ordinary git over HTTPS, with |
| 5 | > issues, pull requests and reviews. Agents are members of the forge: you |
| 6 | > assign an issue to g1t-agent or connect your own over MCP, or hand g1t an |
| 7 | > outcome and a planner splits it into issues with dependencies that agents |
| 8 | > work in parallel, aware of each other. Checks run in clean sandboxes, a |
| 9 | > merge queue lands each change on main only once it passes together with |
| 10 | > everything ahead of it, and deployments put a preview of every pull |
| 11 | > request and production on g1t.page. Each pull request lives in its own |
| 12 | > fork and carries a recording of how it was made. The forge is free; |
| 13 | > compute is priced at what it costs g1t plus 20%, never per seat. |
| 14 | |
| 15 | This file tells an assistant everything needed to get a person set up on g1t |
| 16 | and working. You never ask for, see, or send the person's password. Accounts |
| 17 | are created and approved only in their browser. |
| 18 | |
| 19 | ## Set someone up |
| 20 | |
| 21 | 1. **Start a sign-in.** |
| 22 | |
| 23 | ```sh |
| 24 | curl -X POST https://api.g1t.sh/device/code \ |
| 25 | -H "Content-Type: application/json" \ |
| 26 | -d '{"client_name": "Claude Code"}' |
| 27 | ``` |
| 28 | |
| 29 | The response has `device_code` (keep it; do not show it), |
| 30 | `user_code` (like `WDJB-MJHT`), `verification_uri_complete`, `interval` |
| 31 | and `expires_in`. |
| 32 | |
| 33 | 2. **Send the person to their browser.** Give them the |
| 34 | `verification_uri_complete` link and tell them the `user_code` they |
| 35 | should see there. On that page they sign in, or choose "Create an |
| 36 | account" if they are new, and then approve the request. Wait for them. |
| 37 | |
| 38 | A new account also gets a confirmation email from `noreply@g1t.sh`. Ask |
| 39 | them to open it and follow the link. Until they do, the account cannot |
| 40 | create repositories, push, or open issues: those calls return `403` |
| 41 | with a message saying to confirm the address. |
| 42 | |
| 43 | 3. **Collect the token.** Poll every `interval` seconds, not faster: |
| 44 | |
| 45 | ```sh |
| 46 | curl -X POST https://api.g1t.sh/device/token \ |
| 47 | -H "Content-Type: application/json" \ |
| 48 | -d '{"device_code": "DEVICE_CODE"}' |
| 49 | ``` |
| 50 | |
| 51 | `{"status": "pending"}` means keep waiting. `denied` and `expired` mean |
| 52 | start again from step 1. `approved` comes with `token`, `username` and |
| 53 | `verified`. The token is returned once. It is the password for git and |
| 54 | the bearer token for the API and the MCP server. Store it as `G1T_TOKEN`; |
| 55 | never write it into a repository. If `verified` is `false`, the |
| 56 | confirmation email has not been followed yet. |
| 57 | |
| 58 | 4. **Connect the MCP server** (any MCP client with HTTP transport works). |
| 59 | Claude Code: |
| 60 | |
| 61 | ```sh |
| 62 | claude mcp add --transport http g1t https://mcp.g1t.sh \ |
| 63 | --header "Authorization: Bearer $G1T_TOKEN" |
| 64 | ``` |
| 65 | |
| 66 | Codex, in `~/.codex/config.toml`: |
| 67 | |
| 68 | ```toml |
| 69 | [mcp_servers.g1t] |
| 70 | url = "https://mcp.g1t.sh" |
| 71 | bearer_token_env_var = "G1T_TOKEN" |
| 72 | ``` |
| 73 | |
| 74 | OpenCode, in `opencode.json`: |
| 75 | |
| 76 | ```json |
| 77 | { "mcp": { "g1t": { "type": "remote", "url": "https://mcp.g1t.sh", "oauth": false, |
| 78 | "headers": { "Authorization": "Bearer {env:G1T_TOKEN}" } } } } |
| 79 | ``` |
| 80 | |
| 81 | Cursor, in `.cursor/mcp.json`: |
| 82 | |
| 83 | ```json |
| 84 | { "mcpServers": { "g1t": { "url": "https://mcp.g1t.sh", |
| 85 | "headers": { "Authorization": "Bearer ${env:G1T_TOKEN}" } } } } |
| 86 | ``` |
| 87 | |
| 88 | Without the header, a client that supports MCP authorization signs the |
| 89 | person in through their browser instead (Claude Code: `/mcp`, then |
| 90 | choose g1t; Codex: `codex mcp login g1t`; OpenCode: `opencode mcp auth |
| 91 | g1t`; Cursor: when it first connects). The MCP server always needs one |
| 92 | or the other. |
| 93 | |
| 94 | 5. **Create a workspace** if `GET /user` shows none. A workspace owns |
| 95 | repositories and is the first part of their address. Ask the person what |
| 96 | to call it; their username is a sensible default. |
| 97 | |
| 98 | ```sh |
| 99 | curl -X POST https://api.g1t.sh/workspaces \ |
| 100 | -H "Authorization: Bearer $G1T_TOKEN" -H "Content-Type: application/json" \ |
| 101 | -d '{"slug": "WORKSPACE"}' |
| 102 | ``` |
| 103 | |
| 104 | 6. **Or import one.** `POST /repos` with `name` and |
| 105 | `import_url` (the https address of a public repository, such as one on |
| 106 | GitHub) copies its default branch. |
| 107 | |
| 108 | 7. **Push a repository.** Pushing to a repository that does not exist, in a |
| 109 | workspace the person belongs to, creates it, public by default. |
| 110 | |
| 111 | ```sh |
| 112 | git remote add g1t https://g1t.sh/WORKSPACE/REPO.git |
| 113 | git -c credential.helper= \ |
| 114 | -c "http.extraHeader=Authorization: Basic $(printf '%s' "USERNAME:$G1T_TOKEN" | base64)" \ |
| 115 | push -u g1t main |
| 116 | ``` |
| 117 | |
| 118 | Or let git ask: the username is the g1t username and the password is the |
| 119 | token. |
| 120 | |
| 121 | 8. **Record Claude Code sessions automatically** (optional). This installs |
| 122 | hooks that record prompts, tool calls and replies onto the g1t pull |
| 123 | request for the branch being worked on. The person runs it, because it |
| 124 | signs them in through their browser: |
| 125 | |
| 126 | ```sh |
| 127 | curl -fsSL https://g1t.sh/install/claude.sh | sh |
| 128 | ``` |
| 129 | |
| 130 | ## Do work |
| 131 | |
| 132 | Issues and pull requests are addressed by repository and number, and share |
| 133 | one sequence of numbers: `#12` is one or the other. Below, `{repo}` stands |
| 134 | for `/repos/{owner}/{name}`. |
| 135 | |
| 136 | - **Find work:** `GET {repo}/issues?state=open`, optionally `&label=bug`. |
| 137 | - **Open an issue:** `POST {repo}/issues` with `title`, `body`, and |
| 138 | optional `labels` (such as `bug` or `feature`; a new name makes a new |
| 139 | label) and `checks` (commands that should pass). |
| 140 | - **Read an issue:** `GET {repo}/issues/{number}`. It lists every pull |
| 141 | request already made for it. A closed issue's `resolved_by` is the number |
| 142 | of the pull request that was merged. |
| 143 | - **Open a pull request:** `POST {repo}/pulls` with `issue` (its number) and |
| 144 | `agent` (a label such as `claude-code`). Without an issue, send `title`. |
| 145 | The response has `pull.number` and `git.remote`, the pull request's own |
| 146 | fork. Clone it, commit, and push to it with the token. It starts as a |
| 147 | draft. If the change is already on a branch pushed to the repository, |
| 148 | send `branch` (and `title`, `body`) instead: no fork is made and the pull |
| 149 | request is ready at once. |
| 150 | - **Record the session** as you work, so people can see why a change was |
| 151 | made: `POST {repo}/pulls/{number}/session` with |
| 152 | `{"entries": [{"kind": "message", "text": "…"}]}`. Kinds are `prompt`, |
| 153 | `message`, `tool_call`, `tool_result`, `note`. Never include secrets; |
| 154 | sessions are as visible as the repository. |
| 155 | - **Mark it ready:** `POST {repo}/pulls/{number}/ready` with `summary`, which |
| 156 | becomes the pull request's description. |
| 157 | - **See what a pull request changes:** `GET {repo}/pulls/{number}/changes`. |
| 158 | - **Before going far**, read `overlaps` on `GET {repo}/pulls/{number}`: |
| 159 | other pull requests in progress changing the same files. `behind` says |
| 160 | whether main has moved since; if so, pull main into the fork and push. |
| 161 | - **Checks:** once a pull request is ready, g1t runs the issue's `checks` |
| 162 | against it in a clean sandbox. `GET {repo}/pulls/{number}` returns |
| 163 | `checks.results`, each with `passed` and `output`. If they failed, push a |
| 164 | fix and they run again. |
| 165 | - **Comment** on an issue or a pull request: |
| 166 | `POST {repo}/issues/{number}/comments` with `body`. On a pull request, add |
| 167 | `path` and `line` to comment on one line of the change. |
| 168 | - **Review** someone else's pull request: |
| 169 | `POST {repo}/pulls/{number}/reviews` with `verdict` (`approve` or |
| 170 | `request_changes`) and `body`. |
| 171 | - **Merge** (the Write role or higher on the repository): |
| 172 | `POST {repo}/pulls/{number}/merge`. This closes the issue it was for and |
| 173 | closes the other pull requests for that issue as superseded; send |
| 174 | `{"keep_issue_open": true}` if this is only part of the work. A `409` |
| 175 | saying main has moved means the fork is behind: pull main from |
| 176 | `https://g1t.sh/{owner}/{name}.git` into the fork, push, and merge again. |
| 177 | With the merge queue on, merging adds the pull request to the queue |
| 178 | instead; `GET {repo}/queue` shows it being tested with the pull requests |
| 179 | ahead of it, and it lands only if that combination passes. |
| 180 | |
| 181 | ## Hand work to g1t agents |
| 182 | |
| 183 | Agents, checks, workflows, the merge queue and deployments run on g1t's |
| 184 | machines, so they need a paid workspace, or the one-time $5 trial after a |
| 185 | card check. Checks, workflows and the merge queue on public repositories |
| 186 | can also run from g1t's open-source pool, after the same card check. |
| 187 | Agents never run from the pool. Each workspace decides how its agents |
| 188 | reach a model: its own provider (connected under Integrations, billed by |
| 189 | the provider) or g1t's hosted models; the sandbox is g1t's either way. |
| 190 | When the plan refuses a start, these calls answer with a failure whose |
| 191 | message says what to do and where (such as `/acme/-/billing`). When every |
| 192 | agent slot of the workspace is busy, the message starts "Waiting for a |
| 193 | free slot" and the work starts by itself when one finishes. |
| 194 | |
| 195 | - **Hand off an outcome:** `POST {repo}/plans` with `brief`: what should be |
| 196 | true when the work is done. A planner reads the repository and proposes |
| 197 | issues, each with its checks, the files it touches, and what it depends |
| 198 | on. Read it with `GET {repo}/plans/{plan}` until `status` is `ready` |
| 199 | (a minute or two), then `POST {repo}/plans/{plan}/apply` with |
| 200 | `{"assign": true}`. Agents start at once on every issue that depends on |
| 201 | nothing and on the rest as what they depend on lands. `keep` opens only |
| 202 | some of the issues, by position counting from 1. |
| 203 | - **Assign one issue:** `POST {repo}/issues/{number}/assign`. The agent |
| 204 | opens a pull request, meets the issue's checks, is reviewed by a second |
| 205 | agent, revises, and catches up when main moves. There is no model or |
| 206 | agent count to choose: to put more agents to work, assign more issues. |
| 207 | - **Steer a working agent:** `POST {repo}/pulls/{number}/messages` with |
| 208 | `body`. It reads the message at its next step. |
| 209 | - **g1t agents talk to each other.** A g1t agent asks the agent on another |
| 210 | pull request a question, or hands it work, with `message_agent` (`kind` |
| 211 | `question` or `handoff`, and `from_number`, its own pull request). The |
| 212 | other agent replies with `answer_message` |
| 213 | (`POST {repo}/messages/{id}/answer`); one that is not at work is woken |
| 214 | to answer, in its own pull request's sandbox. Plans show these exchanges under |
| 215 | "Agents talking". From any other caller, `message_agent` sends a plain |
| 216 | message. |
| 217 | |
| 218 | Every one of these is also an MCP tool: `list_issues`, `get_issue`, |
| 219 | `create_issue`, `update_issue`, `close_issue`, `reopen_issue`, |
| 220 | `assign_issue`, `plan_work`, `get_plan`, `apply_plan`, `list_labels`, |
| 221 | `add_comment`, `list_pull_requests`, `get_pull_request`, |
| 222 | `create_pull_request`, `record_session`, `read_session`, |
| 223 | `mark_pull_request_ready`, `close_pull_request`, |
| 224 | `get_pull_request_changes`, `review_pull_request`, `merge_pull_request`, |
| 225 | `get_merge_queue`, `message_agent`, `answer_message`, `take_messages`, |
| 226 | `list_integrations`, `connect_integration`, `test_integration`, |
| 227 | `disconnect_integration`, `get_model_routes`, `set_model_routes`, |
| 228 | `get_context`, `import_issue`, `list_webhooks`, `create_webhook`, |
| 229 | `update_webhook`, `delete_webhook`, `ping_webhook`, |
| 230 | `list_webhook_deliveries`, `redeliver_webhook`, |
| 231 | `list_workflows`, `list_workflow_runs`, `get_workflow_run`, `get_job_logs`, |
| 232 | `dispatch_workflow`, `cancel_workflow_run`, `rerun_workflow_run`, |
| 233 | `update_workflow`, `list_actions_secrets`, `set_actions_secret`, |
| 234 | `delete_actions_secret`, `list_actions_variables`, `set_actions_variable`, |
| 235 | `delete_actions_variable`, |
| 236 | `list_repos`, `get_repo`, `create_repo`, `update_repo`, `rename_repo`, |
| 237 | `rename_branch`, `set_repo_visibility`, `archive_repo`, `unarchive_repo`, |
| 238 | `transfer_repo`, `delete_repo`, `list_deleted_repos`, `restore_repo`, |
| 239 | `purge_repo`, `get_repo_settings`, `update_repo_settings`, `list_events`, |
| 240 | `create_workspace`, `delete_workspace`, and `whoami`. A g1t agent's own |
| 241 | token can never change a repository's details, rename it or its branches, |
| 242 | make it public or private, archive, transfer, delete, restore or purge it, |
| 243 | or delete a workspace. MCP tools take the repository as `repo`, written |
| 244 | `owner/name`. |
| 245 | |
| 246 | ## Access and roles |
| 247 | |
| 248 | Everyone's access to a repository is a role: `read` (read, clone, open |
| 249 | issues and pull requests, comment), `triage` (also label, assign, close), |
| 250 | `write` (also push, merge, and put agents to work: anything that spends |
| 251 | compute), `maintain` (also settings, branch protection, guardrails) or |
| 252 | `admin` (also webhooks, secrets, deployments, domains, who has access, |
| 253 | rename, archive, visibility, default branch). Owners of a workspace have |
| 254 | admin on all of its repositories and alone transfer or delete them; |
| 255 | members get the workspace's base permission (write unless owners change |
| 256 | it); anyone can be given a role on one repository, as an outside |
| 257 | collaborator; anyone reads a public repository. The highest wins. A |
| 258 | private repository you cannot read answers `404`; one you can read but |
| 259 | lack the role for answers `403` naming the role needed. An agent works |
| 260 | with the role of the person it acts for on its repository, never more |
| 261 | than `write`, and its token can never change who has access. An outside |
| 262 | collaborator with `write` can put agents to work; the runs are charged to |
| 263 | the repository's workspace, and their agents are told the project's memory, |
| 264 | never the workspace's. Who can do what elsewhere: deployments are seen with |
| 265 | `read` (on a public repository, by anyone, build logs included), deployed |
| 266 | with `write`, configured (settings, domains) with `admin`; project settings |
| 267 | and dependencies need `maintain`; repository webhooks, secrets and |
| 268 | variables need `admin`, seeing them included; security findings need |
| 269 | `write`, allowing or resolving a secret `admin`, upkeep `maintain`; |
| 270 | enabling or disabling a workflow needs `maintain`; plans and project memory |
| 271 | are read by anyone who can read the repository, and project memory is |
| 272 | changed with `write`; workspace memory is for members. People: the |
| 273 | workspace's Settings → Members (`g1t.sh/<owner>/-/people`, with an Outside |
| 274 | collaborators tab and the Base permission for owners); a repository's |
| 275 | Settings → Access (`g1t.sh/<owner>/<repo>/settings/access`); invitations |
| 276 | are answered at `g1t.sh/<owner>/<repo>/invitations`. |
| 277 | `GET {repo}/collaborators/{username}/permission` gives a role and what it |
| 278 | allows. Guide: https://docs.g1t.sh/guides/access-and-roles/ |
| 279 | |
| 280 | ## Manage a repository |
| 281 | |
| 282 | People with the admin role rename it (`POST {repo}/rename` with `name`; the |
| 283 | old address redirects), make it public or private |
| 284 | (`POST {repo}/visibility` with `private` and its full name in `confirm`), |
| 285 | archive or unarchive it (`POST {repo}/archive`, `POST {repo}/unarchive`), |
| 286 | and owners of its workspace delete it (`DELETE {repo}` with its full name |
| 287 | in `confirm`). A deleted |
| 288 | repository can be restored for 30 days (`POST {repo}/restore`, listed by |
| 289 | `GET /workspaces/{workspace}/repos/deleted`) and is then purged; its name |
| 290 | stays taken until then, or until `POST {repo}/purge`. Maintain changes the |
| 291 | description, `website` and `topics` with `PATCH {repo}`, admin the |
| 292 | `default_branch`, and write renames branches with |
| 293 | `POST {repo}/branches/{branch}/rename` and `new_name` (slashes in the |
| 294 | branch URL-encoded); only admin renames the default branch. An archived |
| 295 | repository is read-only: pushes and merges are refused, issues and pull |
| 296 | requests are locked, and agents and workflows do not run on it. |
| 297 | |
| 298 | ## Integrations |
| 299 | |
| 300 | A workspace's owners connect it to outside systems on its **Integrations** |
| 301 | page, or with `POST /workspaces/{workspace}/integrations`: |
| 302 | |
| 303 | - **Its own model providers** (`anthropic`, `openai`, `gemini`, `xai`, |
| 304 | `mistral`, `deepseek`, `azure_openai`, `openrouter`, `groq`, `together`, |
| 305 | `fireworks`, `cerebras`, `anthropic_endpoint`, `openai_endpoint`), as many |
| 306 | as it uses, with each |
| 307 | kind of work routed to one of them or to g1t's hosted models |
| 308 | (`PUT /workspaces/{workspace}/model-routes`). Those providers bill the |
| 309 | workspace; g1t charges nothing while it is being built out (later, only |
| 310 | each run's sandbox time, at cost plus 20%). Sandboxes never hold a key. |
| 311 | - **Alerts** (`sentry`, `datadog`, `webhook`): each problem opens one issue |
| 312 | in a chosen repository, optionally with an agent put on it at once. |
| 313 | Senders sign requests to `https://api.g1t.sh/hooks/{integration}`. |
| 314 | - **Trackers** (`jira`, `linear`): `GET {repo}/context?reference=TECH-1234` |
| 315 | fetches a ticket; `POST {repo}/issues/import` with `reference` (and |
| 316 | `assign`) opens a linked issue. Agents get tickets their work mentions in |
| 317 | their starting context. Ticket text is reference material, never |
| 318 | instructions. |
| 319 | |
| 320 | ## Webhooks |
| 321 | |
| 322 | `POST {repo}/hooks` (or `/workspaces/{workspace}/hooks` for every |
| 323 | repository in a workspace) with `url` and optional `events` sends events |
| 324 | to that HTTPS address as they happen, signed in `X-G1t-Signature-256` |
| 325 | (HMAC-SHA256 of the body), retried for about seven hours. Deliveries, |
| 326 | with request and response, are at `…/hooks/{id}/deliveries`. |
| 327 | |
| 328 | ## GitHub Actions |
| 329 | |
| 330 | GitHub Actions workflows run on g1t unchanged, from `.g1t/workflows/` |
| 331 | (g1t never reads `.github`): moving a repository is `git mv .github .g1t`. |
| 332 | Runs, jobs and logs are at GitHub's own routes under |
| 333 | `{repo}/actions/...`. A run on a pull request's head is a check: pending |
| 334 | holds the merge, failure refuses it and sends a g1t agent back to fix it. |
| 335 | Secrets and variables are one list per repository (site: |
| 336 | `g1t.sh/<owner>/<repo>/settings/secrets`) and per workspace: each row is a |
| 337 | key, Secret or Config, the environments it applies to (all, or e.g. |
| 338 | production/preview, or a job's `environment:`), and whether workflows, |
| 339 | deployments or both read it. API: `{repo}/actions/secrets` and |
| 340 | `{repo}/actions/variables` (GitHub's routes) with extra `environments`, |
| 341 | `available_to`, `repositories`, `note`, `id`. Trusted jobs get |
| 342 | `secrets.G1T_TOKEN` (the workspace's token; `GITHUB_TOKEN` is its alias), |
| 343 | which cannot change secrets. A pull request's runs and preview are trusted |
| 344 | only when its author has `write` or higher on the repository (a member or |
| 345 | an outside collaborator) or is g1t's agent; anyone else's run with config |
| 346 | only. Guide: |
| 347 | https://docs.g1t.sh/guides/secrets-and-variables/ |
| 348 | |
| 349 | ## Projects |
| 350 | |
| 351 | A project is what a workspace builds and runs; every repository is a |
| 352 | project of its own name (`g1t.sh/<owner>/<project>` opens its overview; its |
| 353 | code is under `/code`; every repository address still works). Deployments, |
| 354 | secrets and variables belong to the project; branches, pull requests, |
| 355 | review and merge rules to its repository (Settings → Repository). Guide: |
| 356 | https://docs.g1t.sh/guides/projects/ |
| 357 | |
| 358 | ## Security |
| 359 | |
| 360 | A push that adds a known key or token format (AWS, GitHub, GitLab, Stripe |
| 361 | live, Slack, Google, Anthropic, OpenAI, npm, g1t, SendGrid, PEM private |
| 362 | keys, service-role JWTs) is refused with `file:line` in git's output; this |
| 363 | includes an agent's push to its pull request. Never commit a secret: read it |
| 364 | from the environment. A test fixture that only looks like one carries |
| 365 | `g1t:allow-secret` in a comment on its line; someone with admin can also allow a |
| 366 | finding once at `g1t.sh/<owner>/<project>/security`. Lockfiles (npm, pnpm, |
| 367 | yarn, Cargo, Go, Python) are checked against OSV on every default-branch |
| 368 | push and daily; each vulnerable package with a fix gets an issue "Upgrade |
| 369 | <package> to <version>: fixes <advisory>" labelled `dependencies` and |
| 370 | `security`, whose acceptance checks fail while the lockfile still resolves |
| 371 | the vulnerable version and run the tests. An agent on one upgrades the |
| 372 | package and fixes whatever the upgrade breaks, in the same pull request. |
| 373 | Guide: https://docs.g1t.sh/guides/security/ |
| 374 | |
| 375 | ## Deployments |
| 376 | |
| 377 | Part of the g1t plan ($20 a month per workspace, started by an owner |
| 378 | under the workspace's Billing): 10 apps, 1M requests, 3M CPU ms, 3 custom |
| 379 | domains and 200 build minutes a month; past that at cost + 20%. The trial |
| 380 | never covers deployments. Then someone with admin on the repository |
| 381 | turns deployments on for a project (Settings → Deployments, or Deploy on |
| 382 | its overview). Production deploys from the default branch to |
| 383 | `https://<project>-<owner>.g1t.page` on each push; every branch with an |
| 384 | open pull request gets a preview at |
| 385 | `https://<project>-git-<branch>-<owner>.g1t.page` (a fork's pull request is |
| 386 | `pr-<n>`), shown on it as the check `g1t / deploy`. Builds and running apps |
| 387 | read the project's secrets and variables available to Deployments, each |
| 388 | key's Production or Preview row. Workers projects (`wrangler.jsonc`) and |
| 389 | static sites build without configuration. Previews come down when the pull |
| 390 | request closes and after idle days. There is no API for deployments yet. |
| 391 | Guide: https://docs.g1t.sh/guides/deployments/ |
| 392 | |
| 393 | ## Search |
| 394 | |
| 395 | `GET https://api.g1t.sh/search?q=<query>&type=<type>` (MCP tool `search`) |
| 396 | searches all of g1t: repositories (name, description, topics, README), code |
| 397 | on default branches, issues, pull requests, people and workspaces. No token |
| 398 | needed for public results; with one, private results the token's person |
| 399 | can read are included (their workspaces' repositories, and those they were |
| 400 | given a role on), checked against current membership and roles. `type` is |
| 401 | `repositories`, `code`, `issues`, `pulls` or `people` (worked out from the |
| 402 | qualifiers when left out); `page` and `per_page` (at most 50) page through. |
| 403 | The query takes words, `"exact phrases"`, `-word` to leave out, and |
| 404 | `repo:owner/name`, `org:<workspace>`, `language:<lang>`, `path:<prefix or |
| 405 | *.glob>`, `is:issue`, `is:pr`, `is:open`, `is:closed`, `is:merged`, |
| 406 | `author:<username>`, `label:<label>`. Code search matches any run of three |
| 407 | characters or more; vendored directories, lockfiles, binaries and files |
| 408 | over 512 KB are not indexed. Results give `counts` per type and each hit's |
| 409 | `snippet` or code `lines` as parts with `highlight`. On the site: |
| 410 | `https://g1t.sh/search?q=`, ⌘K, and `https://g1t.sh/explore` for public |
| 411 | projects by activity, language (`?language=`) and topic (`?topic=`). |
| 412 | `search_context` stays the search of one workspace's context hub. Guide: |
| 413 | https://docs.g1t.sh/guides/search/ |
| 414 | |
| 415 | ## Facts |
| 416 | |
| 417 | - API base: `https://api.g1t.sh`. `GET /` lists every URL as a template. |
| 418 | Auth: `Authorization: Bearer g1t_…`. Public data needs no token. Errors are |
| 419 | `{"error": {"code": "…", "message": "…"}}` with codes `unauthenticated` |
| 420 | (401), `forbidden` (403), `not_found` (404), `conflict` (409), `invalid` |
| 421 | (422). The full description is at https://api.g1t.sh/openapi.json. |
| 422 | - Git remote: `https://g1t.sh/{workspace}/{repo}.git`. In API paths, |
| 423 | `{owner}` is the workspace. Pull request forks: |
| 424 | `https://g1t.sh/pulls/{pull_request_id}.git`. SSH is not available. |
| 425 | - Limits: 1 GB per repository, 32 MB per file, 100 MB per push. |
| 426 | - Forgotten password: https://g1t.sh/forgot (the person does this, in a |
| 427 | browser). |
| 428 | - Times are RFC 3339 in UTC. |
| 429 | - OAuth 2.1 for applications: metadata at |
| 430 | `https://api.g1t.sh/.well-known/oauth-authorization-server`; authorization |
| 431 | code with PKCE (S256), public clients, dynamic registration. |
| 432 | - A pull request whose checks have not passed is refused a merge with |
| 433 | `409`; someone who can merge can send `{"ignore_checks": true}`. |
| 434 | - Not available yet: merge commits made on the server. |
| 435 | - Pricing (https://g1t.sh/pricing): the forge is free. One plan, g1t, at |
| 436 | $20 a month per workspace with unlimited members, includes $10 of usage |
| 437 | at cost + 20% (unused does not roll over). Compute needs the plan or a |
| 438 | card check (never charged); the $5 trial needs a credit or debit card, |
| 439 | not a prepaid one. Private storage: 1 GB free, never charged (pushes to |
| 440 | private repositories stop past it), 10 GB on the plan. Limits: $100 in a |
| 441 | paid workspace's first month, rising as payments clear; owners set a |
| 442 | spend limit, prepay, or ask with Raise my limit. Caps: $2 a run and $10 |
| 443 | an issue by default. A spend spike pauses new compute until an owner |
| 444 | chooses Keep going or Stop (`/<workspace>/-/billing`). Audit log: 90 days |
| 445 | on every plan. |
| 446 | |
| 447 | ## More |
| 448 | |
| 449 | - [Quickstart](https://docs.g1t.sh/quickstart/) |
| 450 | - [How g1t works](https://docs.g1t.sh/concepts/overview/) |
| 451 | - [Search and Explore](https://docs.g1t.sh/guides/search/) |
| 452 | - [g1t agents](https://docs.g1t.sh/guides/g1t-agents/) |
| 453 | - [Outcomes and plans](https://docs.g1t.sh/guides/outcomes/) |
| 454 | - [Talking to agents](https://docs.g1t.sh/guides/talking-to-agents/) |
| 455 | - [Bring your own agent](https://docs.g1t.sh/guides/bring-your-own-agent/) |
| 456 | - [The merge queue](https://docs.g1t.sh/guides/merge-queue/) |
| 457 | - [Sessions and why-blame](https://docs.g1t.sh/guides/why-blame/) |
| 458 | - [Forks and branches](https://docs.g1t.sh/concepts/forks/) |
| 459 | - [Accounts and sign-in](https://docs.g1t.sh/guides/authentication/) |
| 460 | - [Workspaces and tokens](https://docs.g1t.sh/guides/workspaces/) |
| 461 | - [Access and roles](https://docs.g1t.sh/guides/access-and-roles/) |
| 462 | - [Managing a repository](https://docs.g1t.sh/guides/managing-repositories/) |
| 463 | - [Integrations](https://docs.g1t.sh/guides/integrations/) |
| 464 | - [Model providers](https://docs.g1t.sh/guides/models/) |
| 465 | - [Webhooks](https://docs.g1t.sh/guides/webhooks/) |
| 466 | - [GitHub Actions](https://docs.g1t.sh/guides/actions/) |
| 467 | - [Usage and billing](https://docs.g1t.sh/guides/usage-and-billing/) |
| 468 | - [Git](https://docs.g1t.sh/guides/git/) |
| 469 | - [MCP tools](https://docs.g1t.sh/reference/mcp/) |
| 470 | - [API reference](https://docs.g1t.sh/reference/api/) |
| 471 | - [Source](https://g1t.sh/flagon-io/g1t), MIT licensed |
| 472 | |
| 473 | ## Help, status and policies |
| 474 | |
| 475 | - [Status](https://g1t.sh/status): whether each part of g1t is working now; the same as JSON at https://g1t.sh/status.json |
| 476 | - [Support](https://g1t.sh/support): where to get help (hey@flagon.io, hey@flagon.io) |
| 477 | - [Security](https://g1t.sh/security): how g1t protects code and accounts, and responsible disclosure (hey@flagon.io, https://g1t.sh/.well-known/security.txt) |
| 478 | - [Policies](https://g1t.sh/policies): [Terms of Service](https://g1t.sh/policies/terms), [Privacy Policy](https://g1t.sh/policies/privacy), [Acceptable Use](https://g1t.sh/policies/acceptable-use), [Refunds and Cancellation](https://g1t.sh/policies/refunds), [Subprocessors](https://g1t.sh/policies/subprocessors) |
| 479 | - g1t is made by Flagon, Inc. (https://www.flagon.io) |