Skip to content
Proud to collaborate with Microsoft for Startups

repligit.credential.mint ​

Mint a short-lived Repligit Git credential (RS256 JWT)

Mint a short-lived RS256 JWT that a Git client presents to a Repligit appliance (HTTP Bearer / Basic password, or the REPLIGIT_CREDENTIAL SSH env).

Inputs:

  • repository_uuid: UUID of the Repligit repository the credential scopes to (required)
  • pusher_uuid: UUID of the principal the credential represents (required)
  • scope: read | write | admin (default read)
  • pusher_kind: user | agent | sync_worker | broker (default user)
  • ttl_seconds: credential lifetime, 60..3600 (default 900)
  • audience: JWT audience (default "repligit")

Outputs (terminal state_data):

  • token: the signed JWT — revealed once on the start response, never retrievable again
  • grant_uuid: the token's jti, stable identifier for audit
  • expires_at: ISO-8601 expiry timestamp
  • repository_uuid / pusher_uuid / pusher_kind / scope / audience: echoes

Requires the Orkestia-side signing private key (see module docstring). The organization_uuid claim is taken from the run's own organization scope.

Overview ​

PropertyValue
Workflow typeAtomic
LibraryApp-repligit
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
repository_uuiduuidYes—UUID of the Repligit repository the credential scopes to
pusher_uuiduuidYes—UUID of the principal (user, agent, sync worker) the credential represents
scopestringNo—Access scope: read
pusher_kindstringNo—Principal kind: user
ttl_secondsintegerNo—Credential lifetime in seconds, 60..3600 (default 900)
audiencestringNo—JWT audience the appliance validates (default repligit)

Output Schema ​

FieldTypeRequiredDefaultDescription
tokenstringNo—Signed JWT — revealed once on the start response, never retrievable again
grant_uuiduuidNo—The token's jti; stable identifier for audit
expires_atstringNo—ISO-8601 expiry timestamp
repository_uuiduuidNo—Echo of the scoped repository
pusher_uuiduuidNo—Echo of the principal UUID
pusher_kindstringNo—Echo of the principal kind
scopestringNo—Echo of the granted scope
audiencestringNo—Echo of the JWT audience
ttl_secondsintegerNo—Echo of the requested lifetime
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "repligit.credential.mint",
  "initial_data": {
    "repository_uuid": "value",
    "pusher_uuid": "value"
  }
}