StarGit API
Inspect code, propose pull requests, publish handovers and connect your tools with permissions you choose.
One connection. Clear permissions.
Create a private connection prompt, paste it into your agent, and work with your repositories, PRs, handovers and agent evidence. Start with read access; add scoped changes when you need them.
The download includes a Python command client and optional local MCP server. Every write uses a recorded user request, current playbook revision and stable retry key. Human PR approval and merge remain in the web review workflow.
Browse 39 supported account operations
| Endpoint | Permission | Behavior |
|---|---|---|
GET /api/v1/bootstrap | account:read | Discover identity, granted permissions, catalog and workflows. |
GET /api/v1/me | account:read | Read your account identity; never returns secrets. |
GET /api/v1/repositories | repositories:read | List repositories you own or belong to, with pagination and total. |
GET /api/v1/repositories/<uuid> | repositories:read | Read repository metadata and your current role. |
PATCH /api/v1/repositories/<uuid> | repositories:write | Update an owned repository description with an expected revision. |
POST /api/v1/repositories/references | repositories:create | Attach an existing Git remote as a private repository reference. |
POST /api/v1/repositories | repositories:create | Create a managed repository at an available hosting destination. |
GET /api/v1/repositories/<uuid>/branches | repositories:read | List reported branches; includes freshness information. |
GET /api/v1/repositories/<uuid>/tree | repositories:read | Read a selected branch tree; remote reads may return a pending operation. |
GET /api/v1/repositories/<uuid>/file | repositories:read | Read a file at an exact commit; returns text and content hash. |
GET /api/v1/repositories/<uuid>/commits | repositories:read | Read branch history with pagination and snapshot provenance. |
GET /api/v1/servers | servers:read | List your connected servers, without host credentials or filesystem paths. |
GET /api/v1/hosting/providers | repositories:read | Discover enabled managed hosting destinations and readiness. |
GET /api/v1/repositories/<uuid>/hosting | repositories:read | Inspect managed creation status and clone URLs. |
POST /api/v1/repositories/<uuid>/hosting | repositories:create | Retry an owned failed managed repository creation. |
GET /api/v1/operations/<int:task_id> | repositories:read | Inspect an authorized read operation; no arbitrary server task results. |
GET /api/v1/repositories/<uuid>/pulls | pulls:read | List PRs with pagination and total. |
POST /api/v1/repositories/<uuid>/pulls | pulls:write | Propose a focused PR with branches and optional dependencies. |
GET /api/v1/repositories/<uuid>/pulls/<int:number> | pulls:read | Read exact revision, comparison, checks and discussions. |
POST /api/v1/repositories/<uuid>/pulls/<int:number> | pulls:write | Update intent, refresh, mark ready/draft, comment or report a check. Requires current PR revision. |
GET /api/v1/repositories/<uuid>/pulls/<int:number>/revisions/<int:revision> | pulls:read | Inspect immutable PR revision evidence. |
GET /api/v1/repositories/<uuid>/handovers | handovers:read | List versioned publications for this repository. |
POST /api/v1/repositories/<uuid>/handovers | handovers:write | Publish a handover and supporting Markdown with original project paths. |
GET /api/v1/repositories/<uuid>/handovers/<rid> | handovers:read | Read publication manifest, source revision and file hashes. |
GET /api/v1/repositories/<uuid>/handovers/<rid>/document | handovers:read | Read a hash-verified published Markdown document. |
GET /api/v1/agents | agents:read | List your configured in-product agents; does not execute paid model calls. |
GET /api/v1/agents/<agent_uuid> | agents:read | Read an owned agent configuration summary without provider secrets. |
GET /api/v1/agents/<agent_uuid>/threads | agents:read | List accessible in-product conversations for your agent. |
GET /api/v1/agents/<agent_uuid>/threads/<thread_uuid> | agents:read | Read public user/assistant messages with pagination; excludes system/tool internals. |
GET /api/v1/agents/<agent_uuid>/runs | agents:read | List existing in-product execution evidence; separate from external workflow runs. |
GET /api/v1/agents/<agent_uuid>/runs/<execution_uuid> | agents:read | Inspect public output, recorded model identity, step status and tool names; excludes hidden reasoning. |
GET /api/v1/agents/<agent_uuid>/schedules | agents:read | Read owned agent schedules without executing them or exposing stored configuration. |
GET /api/v1/runs | account:read | List public workflow evidence recorded through this connection. |
POST /api/v1/runs | account:read | Record public user intent and read or write mode before performing work. |
GET /api/v1/runs/<run_id> | account:read | Read public prompt, client-reported metadata and request evidence. |
POST /api/v1/runs/<run_id>/finish | account:read | Record a public outcome with no hidden reasoning, usage or invented costs. |
GET /api/v1/receipts/<key> | account:read | Recover the durable result of a write after a network interruption. |
GET /api/v1/playbooks | account:read | Discover current immutable guide versions and SHA-256 hashes. |
GET /api/v1/playbooks/<guide>/<version> | account:read | Retrieve a hash-verifiable versioned data-only playbook. |
Account connections, Git clone credentials and legacy StarBridge API keys have separate purposes. Browser-only ChatGPT requires an execution environment or a hosted connector; this release provides local stdio MCP.
StarGit account API keys
Sign in to create and manage your API keys.
Sign in for API keysCreate a repository from your agent or terminal
Use the managed repository API to discover a destination, create a repository, and retrieve its HTTPS and SSH clone URLs. No browser session is required for these calls.
Choose the right credential
| Task | Credential | Where to get it |
|---|---|---|
| Create managed repositories from an agent | Hosting token with “Allow agents to create repositories” | Git access |
| Clone or push over HTTPS | Hosting token as Git password; push permission is separate | Git access |
| Connect a StarBridge server | StarBridge API key exchanged for server access tokens | StarBridge API keys |
| Workspace queue and PR review actions | Signed-in browser session and applicable CSRF checks | Your workspace |
Hosting tokens expire after 90 days and are limited to one destination. Existing Git tokens need explicit creation permission. Set STARGIT_TOKEN through your secret manager; never commit it or include it in a clone URL.
1. Discover your destination
curl --fail-with-body --silent --show-error \
-H "Authorization: Bearer $STARGIT_TOKEN" \
https://stargit.com/api/hosting/setup
Use the returned providers[].id as PROVIDER_ID when available is true. Your account owns the repository automatically.
2. Create once, retry safely
export REQUEST_ID="my-agent-task-001"
jq -n --argjson provider "$PROVIDER_ID" '{
provider_id: $provider,
name: "my-project",
description: "What this project does",
visibility: "private",
readme: true
}' > repository-request.json
curl --fail-with-body --silent --show-error \
-H "Authorization: Bearer $STARGIT_TOKEN" \
-H "Content-Type: application/json" \
-H "Idempotency-Key: $REQUEST_ID" \
--data-binary @repository-request.json \
https://stargit.com/api/hosting/repositories > repository-result.json
HTTP 202 means provisioning has started. Set readme: false for an empty repository. Repeat the same request ID and JSON after a network failure; the API returns the same repository. Changing the settings under that ID returns 409.
3. Wait for ready, then clone
REPOSITORY_UUID=$(jq -r .uuid repository-result.json)
curl --fail-with-body --silent --show-error \
-H "Authorization: Bearer $STARGIT_TOKEN" \
"https://stargit.com/api/hosting/repositories/$REPOSITORY_UUID"
Poll every three seconds with a bounded timeout. States are provisioning, ready, and error. When ready, use https_url or clone_url. For a failed setup, POST {"action":"retry"} to the same status URL.
Creation does not launch an agent or authorize a merge. Use branches and pull requests for human review. The hosting token does not authenticate browser-only PR or queue endpoints.
| Method & endpoint | Result |
|---|---|
GET /api/hosting/setup | Automatic owner and token-scoped destination |
POST /api/hosting/repositories | Create or resume an identical request |
GET /api/hosting/repositories/{uuid} | Creation state, errors, and clone URLs |
POST /api/hosting/repositories/{uuid} | Retry failed provisioning |
400: invalid input · 401: invalid/expired token · 403: permission or destination mismatch · 404: repository unavailable to this account · 409: conflict, limit, or destination not ready. Read the JSON error before retrying.
Publish project context. Continue on another computer.
Attach versioned handovers and Markdown documents to a repository, inspect them in StarGit, then restore their original project paths. Source code stays in Git.
Use an active StarGit account API key as Authorization: Bearer. Create an account API key, then run python3 stargit_handover.py auth on the new computer. The command also accepts STARGIT_API_KEY or an owner-only credentials file. Each teammate uses their own account. Git hosting tokens and SSH keys do not authenticate these endpoints.
python3 stargit_handover.py --credentials-file /private/credentials.env publish \
--repo REPOSITORY_UUID --root . --name continuation --title "Project continuation" \
--file docs/handoffs/continuation.md --follow-links --dry-run
python3 stargit_handover.py --credentials-file /private/credentials.env pull \
--repo REPOSITORY_UUID --revision PUBLICATION_UUID --root . --dry-run
Inspect the selection, then repeat without --dry-run. Pull checks the source commit, hashes and local conflicts before writing. Existing differing files are preserved. Agent instruction files require an explicit --include-instructions after review.
| Method & endpoint | Result |
|---|---|
GET /api/handovers/auth | Verify account API-key authentication |
POST /api/handovers/repositories | Register or reuse a private source repository reference |
GET /api/repos/{uuid}/handovers | List published revisions |
POST /api/repos/{uuid}/handovers | Publish immutable Markdown files and a manifest; requires Idempotency-Key |
GET /api/repos/{uuid}/handovers/{revision} | Original paths, source commit and document hashes |
GET /api/repos/{uuid}/handovers/{revision}/files/{path} | Authenticated original Markdown bytes |
Handovers remain private even when the source repository is public. Owners and repository contributors can publish; members with read access can inspect and pull. Every update names its parent revision, so parallel agents cannot silently replace each other's publications.
Connect your own server with StarBridge
The core connection endpoints below are implemented in StarGit. Authentication differs between the StarBridge API and signed-in workspace actions.
| Method & endpoint | Authentication | Purpose |
|---|---|---|
POST /api/auth/token | API key as a Bearer token | Issue access and refresh tokens for a StarBridge connection. |
POST /api/auth/refresh | Refresh token in JSON | Replace the access token while keeping its server binding and scopes. |
POST /api/servers/register | Access token · servers:register | Register a server and report its initial status. |
POST /api/servers/heartbeat | Access token · servers:heartbeat | Report server health. |
POST /api/servers/poll | Access token · servers:poll | Poll for queued tasks and return execution results. |
POST /api/servers/live-update | Access token · servers:live-update | Update repository and server metadata. |
StarBridge authentication
For a self-hosted StarBridge connection, generate an API key in your account, then use it to request tokens. Replace the example values with your own key and server identifier.
curl --request POST https://stargit.com/api/auth/token \
--header "Authorization: Bearer $STARGIT_API_KEY" \
--header "Content-Type: application/json" \
--data '{"server_uuid":"YOUR_SERVER_UUID","scopes":"servers:register servers:heartbeat servers:poll servers:live-update"}'The response contains access_token, refresh_token, api_key_uuid, and server_uuid. Refresh with POST /api/auth/refresh and JSON {"refresh_token":"…"}. Save the returned access token; it replaces the previous one. Use the access token as Authorization: Bearer … for the server endpoints.
Refresh an expired access token
jq -n --arg token "$STARGIT_REFRESH_TOKEN" '{refresh_token: $token}' | \
curl --fail-with-body --silent --show-error \
-H "Content-Type: application/json" --data-binary @- \
https://stargit.com/api/auth/refreshThe refresh token has its own expiry. A revoked token or disabled/expired API key cannot refresh. Save the returned access token before your next StarBridge request.
Store credentials outside source control. StarBridge handles the connection lifecycle; follow its setup guide for the full server payloads.
Set up StarBridgeWorkspace operations use your session.
POST /api/enqueue creates a queued operation for a repository or server. GET /api/queue/<queue_id> reads its result.
These routes use the signed-in web session. A StarBridge Bearer token is not a replacement for that session.
A queued request returns a queue identifier. Check the status and result before treating an operation as complete.