repligit.credential.mint ​
Mint a short-lived Repligit Git credential (RS256 JWT)
Mint a short-lived RS256 JWT that a Git client presents to a Repligit appliance (HTTP Bearer / Basic password, or the REPLIGIT_CREDENTIAL SSH env).
Inputs:
- repository_uuid: UUID of the Repligit repository the credential scopes to (required)
- pusher_uuid: UUID of the principal the credential represents (required)
- scope: read | write | admin (default read)
- pusher_kind: user | agent | sync_worker | broker (default user)
- ttl_seconds: credential lifetime, 60..3600 (default 900)
- audience: JWT audience (default "repligit")
Outputs (terminal state_data):
- token: the signed JWT — revealed once on the start response, never retrievable again
- grant_uuid: the token's jti, stable identifier for audit
- expires_at: ISO-8601 expiry timestamp
- repository_uuid / pusher_uuid / pusher_kind / scope / audience: echoes
Requires the Orkestia-side signing private key (see module docstring). The organization_uuid claim is taken from the run's own organization scope.
Overview ​
| Property | Value |
|---|---|
| Workflow type | Atomic |
| Library | App-repligit |
| Version | 1.0 |
Input Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
repository_uuid | uuid | Yes | — | UUID of the Repligit repository the credential scopes to |
pusher_uuid | uuid | Yes | — | UUID of the principal (user, agent, sync worker) the credential represents |
scope | string | No | — | Access scope: read |
pusher_kind | string | No | — | Principal kind: user |
ttl_seconds | integer | No | — | Credential lifetime in seconds, 60..3600 (default 900) |
audience | string | No | — | JWT audience the appliance validates (default repligit) |
Output Schema ​
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
token | string | No | — | Signed JWT — revealed once on the start response, never retrievable again |
grant_uuid | uuid | No | — | The token's jti; stable identifier for audit |
expires_at | string | No | — | ISO-8601 expiry timestamp |
repository_uuid | uuid | No | — | Echo of the scoped repository |
pusher_uuid | uuid | No | — | Echo of the principal UUID |
pusher_kind | string | No | — | Echo of the principal kind |
scope | string | No | — | Echo of the granted scope |
audience | string | No | — | Echo of the JWT audience |
ttl_seconds | integer | No | — | Echo of the requested lifetime |
failure_reason | string | No | — | — |
failure_type | string | No | — | — |
failed_action | string | No | — | — |
failed_at_state | string | No | — | — |
failed_step | string | No | — | — |
failed_layer | string | No | — | — |
error | string | No | — | — |
error_type | string | No | — | — |
States ​
| State | Initial | Terminal | Success | Auto-advance | Description |
|---|---|---|---|---|---|
pending | Yes | No | — | execute | — |
completed | No | Yes | Yes | — | — |
failed | No | Yes | No | — | — |
State Diagram ​
Transitions ​
| From | Action | To | Description |
|---|---|---|---|
pending | execute | completed | — |
* (any state) | fail | failed | — |
API Usage ​
bash
POST /api/workflows/start
Content-Type: application/json
{
"workflow_type": "repligit.credential.mint",
"initial_data": {
"repository_uuid": "value",
"pusher_uuid": "value"
}
}