Authentication
gittan auth
| Subcommand | Description |
|---|
| login | Device-flow login. Opens your browser for approval, saves tokens to ~/.config/gittan/credentials. |
| logout | Remove stored credentials. |
| status | Show login status and token expiry. |
gittan credential
Git credential helper. Exchanges your stored OIDC token for a short-lived git token,
so git push and git pull authenticate automatically.
git config --global credential.https://git.gittan.eu.helper 'gittan credential'
Tokens are cached at ~/.config/gittan/git-token-cache and refreshed automatically. No passwords are ever stored on disk.
gittan status
Connectivity check. Shows API reachability, auth status (including token source),
and org memberships. Default output format is pretty.
Teams
gittan teams
| Subcommand | Args | Description |
|---|
| list | — | List all teams in the org. |
| get | <id|name> | Get team details. |
| create | <name> | Create a team. |
| members | <team-id> | List team members. |
| metrics | <team-id> | Show DORA metrics for the team. |
| rename | <id|name> | Rename a team. |
| delete | <id|name> | Delete an empty team. |
| Flag | Used by | Description |
|---|
| --display-name | create, rename | Human-readable team name. |
| --slack-channel | create | Slack channel for notifications. |
| --name | rename | New team slug. |
Repositories
gittan repos
| Subcommand | Args | Description |
|---|
| list | — | List repos for a team. Requires --team. |
| get | <repo-id> | Get repo details. |
| create | <name> | Create a repo. Requires --team. |
| update | <repo-id> | Update repo settings. |
| delete | <repo-id> | Delete a repo. |
| clone-url | <repo-id> | Show SSH and HTTPS clone URLs. |
| import | <url> | Import from GitHub, GitLab, Bitbucket, Gitea, or Gogs. |
| Flag | Used by | Description |
|---|
| --team <id> | list, create, import | Target team. Required. |
| --description | create | Repo description. |
| --tags <a,b> | create, update | Comma-separated tags. |
| --gated-branches <a,b> | update | Branches that require passing pipelines. |
| --token <pat> | import | PAT for the source platform. Required. |
| --service <name> | import | Source platform: github, gitlab, bitbucket, gitea, gogs. Auto-detected from URL. |
| --update | import | Overwrite if the repo already exists. |
Pipelines
gittan pipelines
Repo is auto-detected from the git remote when run inside a gittan repo.
Override with --repo.
| Subcommand | Args | Description |
|---|
| list | — | List recent runs. Use --team to list across a team. |
| logs | [run-id] | Show run with step output. Defaults to the latest run. |
| Flag | Description |
|---|
| --repo <repo-id> | Override auto-detected repo. |
| --team <team-id> | List runs for all repos in a team. |
| --full | Show full step output. Default: last 40 lines of output, first 20 lines of errors. |
gittan findings
Security scan results from pipeline runs.
| Subcommand | Description |
|---|
| list | List findings. Use --repo + --org for a single repo, or --team for a team view. |
| Flag | Description |
|---|
| --repo <repo-id> | Show findings for a specific repo. Requires --org. |
| --team <team-id> | Show findings for all repos in a team. |
| --aggregate | With --team: show only the latest finding per repo and scanner. |
Deploy
gittan deploy
Track a push from pipeline through to running in the cluster.
| Subcommand | Args | Description |
|---|
| watch | [run-id] | Follow a run from pipeline → published → config-updated → cluster-applied. |
| status | [run-id] | One-shot deploy status check. |
| feedback create | — | Create a deploy feedback endpoint. Returns a token and URL (shown once). |
| feedback list | — | List feedback endpoints. |
| feedback revoke | <token-prefix> | Revoke a feedback endpoint. |
| Flag | Description |
|---|
| --repo <repo-id> | Required for watch and status. |
| --timeout <seconds> | Watch timeout. Default: 600. |
| --description | Description for a feedback endpoint. |
Security
gittan secrets
Manage secrets at three scopes. Narrower scopes override broader ones in pipelines:
repo > team > org.
| Subcommand | Args | Description |
|---|
| set | org|team|repo | Set a secret. Values are encrypted at rest and never returned through the API. |
| list | org|team|repo | List secret names. Values are not shown. |
| delete | org|team|repo | Remove a secret. |
| Flag | Description |
|---|
| --name <name> | Secret name. Required for set and delete. |
| --value <value> | Secret value. Required for set. |
| --org-id <id> | Org scope identifier. |
| --team-id <id> | Team scope identifier. |
| --repo-id <id> | Repo scope identifier. |
gittan secrets set org --name NPM_TOKEN --value <token> --org-id <id>
gittan secrets set team --name DB_URL --value <url> --team-id <id>
gittan secrets set repo --name DEPLOY_KEY --value <key> --org-id <id> --repo-id <id>
gittan service-accounts
Machine-to-machine access via OAuth2 client_credentials.
Org-owner only.
| Subcommand | Description |
|---|
| create | Create a service account. Returns client_id and client_secret — shown once. |
| list | List service accounts in the org. |
| delete | Delete a service account. |
| Flag | Description |
|---|
| --name <name> | Service account name. Required for create. |
| --org <org-id> | Organization. Required. |
| --client-id <id> | Client ID to delete. Required for delete. |
Global flags
| Flag | Default | Description |
|---|
| --org <id> | Auto-resolved | Target organization. Auto-resolved if you belong to one org. |
| --format <fmt> | json | Output format: json, pretty, table. |
| --token <token> | Stored credentials | Use a specific access token. |
| --api <url> | https://gittan.eu | API base URL. |
| --auth-url <url> | https://auth.gittan.eu | Auth server URL. |
Environment variables
| Variable | Description |
|---|
| GITTAN_API_URL | API base URL. |
| GITTAN_AUTH_URL | Auth server URL. |
| GITTAN_TOKEN | Access token. Overrides stored credentials. |
| GITTAN_ORG | Default organization ID. |
Token precedence: --token flag
> GITTAN_TOKEN env
> stored credentials (from gittan auth login).