← Reference

CLI reference

Every command, flag, and environment variable.

Authentication

gittan auth

SubcommandDescription
loginDevice-flow login. Opens your browser for approval, saves tokens to ~/.config/gittan/credentials.
logoutRemove stored credentials.
statusShow login status and token expiry.

gittan credential

Git credential helper. Exchanges your stored OIDC token for a short-lived git token, so git push and git pull authenticate automatically.

git config --global credential.https://git.gittan.eu.helper 'gittan credential'

Tokens are cached at ~/.config/gittan/git-token-cache and refreshed automatically. No passwords are ever stored on disk.

gittan status

Connectivity check. Shows API reachability, auth status (including token source), and org memberships. Default output format is pretty.

Teams

gittan teams

SubcommandArgsDescription
list—List all teams in the org.
get<id|name>Get team details.
create<name>Create a team.
members<team-id>List team members.
metrics<team-id>Show DORA metrics for the team.
rename<id|name>Rename a team.
delete<id|name>Delete an empty team.
FlagUsed byDescription
--display-namecreate, renameHuman-readable team name.
--slack-channelcreateSlack channel for notifications.
--namerenameNew team slug.

Repositories

gittan repos

SubcommandArgsDescription
list—List repos for a team. Requires --team.
get<repo-id>Get repo details.
create<name>Create a repo. Requires --team.
update<repo-id>Update repo settings.
delete<repo-id>Delete a repo.
clone-url<repo-id>Show SSH and HTTPS clone URLs.
import<url>Import from GitHub, GitLab, Bitbucket, Gitea, or Gogs.
FlagUsed byDescription
--team <id>list, create, importTarget team. Required.
--descriptioncreateRepo description.
--tags <a,b>create, updateComma-separated tags.
--gated-branches <a,b>updateBranches that require passing pipelines.
--token <pat>importPAT for the source platform. Required.
--service <name>importSource platform: github, gitlab, bitbucket, gitea, gogs. Auto-detected from URL.
--updateimportOverwrite if the repo already exists.

Pipelines

gittan pipelines

Repo is auto-detected from the git remote when run inside a gittan repo. Override with --repo.

SubcommandArgsDescription
list—List recent runs. Use --team to list across a team.
logs[run-id]Show run with step output. Defaults to the latest run.
FlagDescription
--repo <repo-id>Override auto-detected repo.
--team <team-id>List runs for all repos in a team.
--fullShow full step output. Default: last 40 lines of output, first 20 lines of errors.

gittan findings

Security scan results from pipeline runs.

SubcommandDescription
listList findings. Use --repo + --org for a single repo, or --team for a team view.
FlagDescription
--repo <repo-id>Show findings for a specific repo. Requires --org.
--team <team-id>Show findings for all repos in a team.
--aggregateWith --team: show only the latest finding per repo and scanner.

Deploy

gittan deploy

Track a push from pipeline through to running in the cluster.

SubcommandArgsDescription
watch[run-id]Follow a run from pipeline → published → config-updated → cluster-applied.
status[run-id]One-shot deploy status check.
feedback create—Create a deploy feedback endpoint. Returns a token and URL (shown once).
feedback list—List feedback endpoints.
feedback revoke<token-prefix>Revoke a feedback endpoint.
FlagDescription
--repo <repo-id>Required for watch and status.
--timeout <seconds>Watch timeout. Default: 600.
--descriptionDescription for a feedback endpoint.

Security

gittan secrets

Manage secrets at three scopes. Narrower scopes override broader ones in pipelines: repo > team > org.

SubcommandArgsDescription
setorg|team|repoSet a secret. Values are encrypted at rest and never returned through the API.
listorg|team|repoList secret names. Values are not shown.
deleteorg|team|repoRemove a secret.
FlagDescription
--name <name>Secret name. Required for set and delete.
--value <value>Secret value. Required for set.
--org-id <id>Org scope identifier.
--team-id <id>Team scope identifier.
--repo-id <id>Repo scope identifier.
gittan secrets set org --name NPM_TOKEN --value <token> --org-id <id>
gittan secrets set team --name DB_URL --value <url> --team-id <id>
gittan secrets set repo --name DEPLOY_KEY --value <key> --org-id <id> --repo-id <id>

gittan service-accounts

Machine-to-machine access via OAuth2 client_credentials. Org-owner only.

SubcommandDescription
createCreate a service account. Returns client_id and client_secret — shown once.
listList service accounts in the org.
deleteDelete a service account.
FlagDescription
--name <name>Service account name. Required for create.
--org <org-id>Organization. Required.
--client-id <id>Client ID to delete. Required for delete.

Global flags

FlagDefaultDescription
--org <id>Auto-resolvedTarget organization. Auto-resolved if you belong to one org.
--format <fmt>jsonOutput format: json, pretty, table.
--token <token>Stored credentialsUse a specific access token.
--api <url>https://gittan.euAPI base URL.
--auth-url <url>https://auth.gittan.euAuth server URL.

Environment variables

VariableDescription
GITTAN_API_URLAPI base URL.
GITTAN_AUTH_URLAuth server URL.
GITTAN_TOKENAccess token. Overrides stored credentials.
GITTAN_ORGDefault organization ID.

Token precedence: --token flag > GITTAN_TOKEN env > stored credentials (from gittan auth login).