Skip to main content
Code Storage supports standard Git operations over HTTPS. You can use any Git client with JWT-authenticated remote URLs. You can also create commits and update refs directly through the SDK or the HTTP API, without a local clone. See the SDK reference.

Authentication format

Git commands use HTTP Basic Auth with a JWT-backed remote. The format is consistent across every repository:
  • Username: Always t (for “token”)
  • Password: Your JWT token
  • Repository: Must match the repo claim in your JWT
Example:
The SDK and dashboard mint these URLs for you, but you can also construct them manually once you have a JWT. If authentication fails, confirm that:
  • The JWT repo claim matches the repository you are cloning or pushing.
  • The token includes the scopes required for the command (git:read, git:write, or repo:write).
  • The token has not expired (exp claim)

Supported commands

Every command uses the same remote syntax and JWT authentication scheme.

Read operations (git:read)

Write operations (git:write)

The SDK’s repo.getRemoteURL() helper generates the JWT-backed URL for you. You can also mint JWTs manually through the authentication flow described in Authentication. Once you have the URL, Git behaves exactly the way it does against any other HTTPS remote.

Integration patterns

Use scoped JWTs to differentiate between automation, developers, and product-level access. Short TTLs keep CI credentials disposable, while longer-lived tokens can be issued to developer machines or preview environments.

CI/CD pipeline

Development environment

When in doubt, mint tokens via the SDK—its helpers manage scope validation and URL formatting for you.