Developer API

StarGit API

Inspect code, propose pull requests, publish handovers and connect your tools with permissions you choose.

Token-authenticated access Queue and polling workflows StarBridge integration
For developers and AI agents

One connection. Clear permissions.

Create a private connection prompt, paste it into your agent, and work with your repositories, PRs, handovers and agent evidence. Start with read access; add scoped changes when you need them.

The download includes a Python command client and optional local MCP server. Every write uses a recorded user request, current playbook revision and stable retry key. Human PR approval and merge remain in the web review workflow.

Browse 39 supported account operations
EndpointPermissionBehavior
GET /api/v1/bootstrapaccount:readDiscover identity, granted permissions, catalog and workflows.
GET /api/v1/meaccount:readRead your account identity; never returns secrets.
GET /api/v1/repositoriesrepositories:readList repositories you own or belong to, with pagination and total.
GET /api/v1/repositories/<uuid>repositories:readRead repository metadata and your current role.
PATCH /api/v1/repositories/<uuid>repositories:writeUpdate an owned repository description with an expected revision.
POST /api/v1/repositories/referencesrepositories:createAttach an existing Git remote as a private repository reference.
POST /api/v1/repositoriesrepositories:createCreate a managed repository at an available hosting destination.
GET /api/v1/repositories/<uuid>/branchesrepositories:readList reported branches; includes freshness information.
GET /api/v1/repositories/<uuid>/treerepositories:readRead a selected branch tree; remote reads may return a pending operation.
GET /api/v1/repositories/<uuid>/filerepositories:readRead a file at an exact commit; returns text and content hash.
GET /api/v1/repositories/<uuid>/commitsrepositories:readRead branch history with pagination and snapshot provenance.
GET /api/v1/serversservers:readList your connected servers, without host credentials or filesystem paths.
GET /api/v1/hosting/providersrepositories:readDiscover enabled managed hosting destinations and readiness.
GET /api/v1/repositories/<uuid>/hostingrepositories:readInspect managed creation status and clone URLs.
POST /api/v1/repositories/<uuid>/hostingrepositories:createRetry an owned failed managed repository creation.
GET /api/v1/operations/<int:task_id>repositories:readInspect an authorized read operation; no arbitrary server task results.
GET /api/v1/repositories/<uuid>/pullspulls:readList PRs with pagination and total.
POST /api/v1/repositories/<uuid>/pullspulls:writePropose a focused PR with branches and optional dependencies.
GET /api/v1/repositories/<uuid>/pulls/<int:number>pulls:readRead exact revision, comparison, checks and discussions.
POST /api/v1/repositories/<uuid>/pulls/<int:number>pulls:writeUpdate intent, refresh, mark ready/draft, comment or report a check. Requires current PR revision.
GET /api/v1/repositories/<uuid>/pulls/<int:number>/revisions/<int:revision>pulls:readInspect immutable PR revision evidence.
GET /api/v1/repositories/<uuid>/handovershandovers:readList versioned publications for this repository.
POST /api/v1/repositories/<uuid>/handovershandovers:writePublish a handover and supporting Markdown with original project paths.
GET /api/v1/repositories/<uuid>/handovers/<rid>handovers:readRead publication manifest, source revision and file hashes.
GET /api/v1/repositories/<uuid>/handovers/<rid>/documenthandovers:readRead a hash-verified published Markdown document.
GET /api/v1/agentsagents:readList your configured in-product agents; does not execute paid model calls.
GET /api/v1/agents/<agent_uuid>agents:readRead an owned agent configuration summary without provider secrets.
GET /api/v1/agents/<agent_uuid>/threadsagents:readList accessible in-product conversations for your agent.
GET /api/v1/agents/<agent_uuid>/threads/<thread_uuid>agents:readRead public user/assistant messages with pagination; excludes system/tool internals.
GET /api/v1/agents/<agent_uuid>/runsagents:readList existing in-product execution evidence; separate from external workflow runs.
GET /api/v1/agents/<agent_uuid>/runs/<execution_uuid>agents:readInspect public output, recorded model identity, step status and tool names; excludes hidden reasoning.
GET /api/v1/agents/<agent_uuid>/schedulesagents:readRead owned agent schedules without executing them or exposing stored configuration.
GET /api/v1/runsaccount:readList public workflow evidence recorded through this connection.
POST /api/v1/runsaccount:readRecord public user intent and read or write mode before performing work.
GET /api/v1/runs/<run_id>account:readRead public prompt, client-reported metadata and request evidence.
POST /api/v1/runs/<run_id>/finishaccount:readRecord a public outcome with no hidden reasoning, usage or invented costs.
GET /api/v1/receipts/<key>account:readRecover the durable result of a write after a network interruption.
GET /api/v1/playbooksaccount:readDiscover current immutable guide versions and SHA-256 hashes.
GET /api/v1/playbooks/<guide>/<version>account:readRetrieve a hash-verifiable versioned data-only playbook.

Account connections, Git clone credentials and legacy StarBridge API keys have separate purposes. Browser-only ChatGPT requires an execution environment or a hosted connector; this release provides local stdio MCP.

StarGit account API keys

Sign in to create and manage your API keys.

Sign in for API keys

Create a repository from your agent or terminal

Use the managed repository API to discover a destination, create a repository, and retrieve its HTTPS and SSH clone URLs. No browser session is required for these calls.

Choose the right credential

TaskCredentialWhere to get it
Create managed repositories from an agentHosting token with “Allow agents to create repositories”Git access
Clone or push over HTTPSHosting token as Git password; push permission is separateGit access
Connect a StarBridge serverStarBridge API key exchanged for server access tokensStarBridge API keys
Workspace queue and PR review actionsSigned-in browser session and applicable CSRF checksYour workspace

Hosting tokens expire after 90 days and are limited to one destination. Existing Git tokens need explicit creation permission. Set STARGIT_TOKEN through your secret manager; never commit it or include it in a clone URL.

1. Discover your destination

curl --fail-with-body --silent --show-error \
  -H "Authorization: Bearer $STARGIT_TOKEN" \
  https://stargit.com/api/hosting/setup

Use the returned providers[].id as PROVIDER_ID when available is true. Your account owns the repository automatically.

2. Create once, retry safely

export REQUEST_ID="my-agent-task-001"
jq -n --argjson provider "$PROVIDER_ID" '{
  provider_id: $provider,
  name: "my-project",
  description: "What this project does",
  visibility: "private",
  readme: true
}' > repository-request.json

curl --fail-with-body --silent --show-error \
  -H "Authorization: Bearer $STARGIT_TOKEN" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: $REQUEST_ID" \
  --data-binary @repository-request.json \
  https://stargit.com/api/hosting/repositories > repository-result.json

HTTP 202 means provisioning has started. Set readme: false for an empty repository. Repeat the same request ID and JSON after a network failure; the API returns the same repository. Changing the settings under that ID returns 409.

3. Wait for ready, then clone

REPOSITORY_UUID=$(jq -r .uuid repository-result.json)
curl --fail-with-body --silent --show-error \
  -H "Authorization: Bearer $STARGIT_TOKEN" \
  "https://stargit.com/api/hosting/repositories/$REPOSITORY_UUID"

Poll every three seconds with a bounded timeout. States are provisioning, ready, and error. When ready, use https_url or clone_url. For a failed setup, POST {"action":"retry"} to the same status URL.

Creation does not launch an agent or authorize a merge. Use branches and pull requests for human review. The hosting token does not authenticate browser-only PR or queue endpoints.

Managed repository endpoints
Method & endpointResult
GET /api/hosting/setupAutomatic owner and token-scoped destination
POST /api/hosting/repositoriesCreate or resume an identical request
GET /api/hosting/repositories/{uuid}Creation state, errors, and clone URLs
POST /api/hosting/repositories/{uuid}Retry failed provisioning

400: invalid input · 401: invalid/expired token · 403: permission or destination mismatch · 404: repository unavailable to this account · 409: conflict, limit, or destination not ready. Read the JSON error before retrying.

Publish project context. Continue on another computer.

Attach versioned handovers and Markdown documents to a repository, inspect them in StarGit, then restore their original project paths. Source code stays in Git.

Use an active StarGit account API key as Authorization: Bearer. Create an account API key, then run python3 stargit_handover.py auth on the new computer. The command also accepts STARGIT_API_KEY or an owner-only credentials file. Each teammate uses their own account. Git hosting tokens and SSH keys do not authenticate these endpoints.

python3 stargit_handover.py --credentials-file /private/credentials.env publish \
  --repo REPOSITORY_UUID --root . --name continuation --title "Project continuation" \
  --file docs/handoffs/continuation.md --follow-links --dry-run

python3 stargit_handover.py --credentials-file /private/credentials.env pull \
  --repo REPOSITORY_UUID --revision PUBLICATION_UUID --root . --dry-run

Inspect the selection, then repeat without --dry-run. Pull checks the source commit, hashes and local conflicts before writing. Existing differing files are preserved. Agent instruction files require an explicit --include-instructions after review.

Handover endpoints
Method & endpointResult
GET /api/handovers/authVerify account API-key authentication
POST /api/handovers/repositoriesRegister or reuse a private source repository reference
GET /api/repos/{uuid}/handoversList published revisions
POST /api/repos/{uuid}/handoversPublish immutable Markdown files and a manifest; requires Idempotency-Key
GET /api/repos/{uuid}/handovers/{revision}Original paths, source commit and document hashes
GET /api/repos/{uuid}/handovers/{revision}/files/{path}Authenticated original Markdown bytes

Handovers remain private even when the source repository is public. Owners and repository contributors can publish; members with read access can inspect and pull. Every update names its parent revision, so parallel agents cannot silently replace each other's publications.

Connect your own server with StarBridge

The core connection endpoints below are implemented in StarGit. Authentication differs between the StarBridge API and signed-in workspace actions.

StarBridge connection endpoints
Method & endpointAuthenticationPurpose
POST /api/auth/tokenAPI key as a Bearer tokenIssue access and refresh tokens for a StarBridge connection.
POST /api/auth/refreshRefresh token in JSONReplace the access token while keeping its server binding and scopes.
POST /api/servers/registerAccess token · servers:registerRegister a server and report its initial status.
POST /api/servers/heartbeatAccess token · servers:heartbeatReport server health.
POST /api/servers/pollAccess token · servers:pollPoll for queued tasks and return execution results.
POST /api/servers/live-updateAccess token · servers:live-updateUpdate repository and server metadata.

StarBridge authentication

For a self-hosted StarBridge connection, generate an API key in your account, then use it to request tokens. Replace the example values with your own key and server identifier.

curl --request POST https://stargit.com/api/auth/token \
  --header "Authorization: Bearer $STARGIT_API_KEY" \
  --header "Content-Type: application/json" \
  --data '{"server_uuid":"YOUR_SERVER_UUID","scopes":"servers:register servers:heartbeat servers:poll servers:live-update"}'

The response contains access_token, refresh_token, api_key_uuid, and server_uuid. Refresh with POST /api/auth/refresh and JSON {"refresh_token":"…"}. Save the returned access token; it replaces the previous one. Use the access token as Authorization: Bearer … for the server endpoints.

Refresh an expired access token

jq -n --arg token "$STARGIT_REFRESH_TOKEN" '{refresh_token: $token}' | \
  curl --fail-with-body --silent --show-error \
  -H "Content-Type: application/json" --data-binary @- \
  https://stargit.com/api/auth/refresh

The refresh token has its own expiry. A revoked token or disabled/expired API key cannot refresh. Save the returned access token before your next StarBridge request.

Store credentials outside source control. StarBridge handles the connection lifecycle; follow its setup guide for the full server payloads.

Set up StarBridge

Workspace operations use your session.

POST /api/enqueue creates a queued operation for a repository or server. GET /api/queue/<queue_id> reads its result.

These routes use the signed-in web session. A StarBridge Bearer token is not a replacement for that session.

A queued request returns a queue identifier. Check the status and result before treating an operation as complete.

Cookie preferences

Cookies keep you signed in and maintain your session. Your choice here is remembered for one year.

Essential session cookies may still be needed when you sign in. See the privacy policy for details about data handling.