Skip to main content
Connect a repository in your workspace runtime using a personal access token (PAT). Choose the easy file-upload method or the more secure Terminal method. After setup, ask the agent to validate authenticated access to the intended repository. These methods use the existing Files and Terminal tools. The current UI does not have a dedicated GitHub/GitLab token connection form.

Before you start

Have the repository’s HTTPS URL, your provider username, and the intended project/repository folder ready. Use a URL without a token, such as:
Ask the agent to prepare the repository if it is not already present. Confirm that the workspace runtime is available and that your role permits the required setup.

Create a token

GitHub: Open your account Settings → Developer settings → Personal access tokens → Fine-grained tokens → Generate new token. Select an expiration date, the correct resource owner, and only the repositories you need. Grant Contents: Read-only for reading, or Read and write when the agent will also change code. Complete organization approval if required. See GitHub token creation and compatibility guidance. GitLab: On the GitLab host that owns your repository, open Edit profile → Access → Personal access tokens. Create an expiring PAT; newer versions may label the scope-based option Legacy token. Select read_repository for reading or write_repository for reading and pushing. These Git scopes do not grant general API access. See GitLab token creation and scope definitions. A token cannot grant access that your provider account does not already have. Copy it once for the method below; do not paste it into an Agent Chat message.

Choose a setup method

1. Make a temporary token file

On your computer, create a plain-text file such as github-token.txt or gitlab-token.txt containing only the token on one line. Keep the username, repository URL, and setup request separate from that file.

2. Upload it to WS Files

Open Files, choose a temporary folder outside the repository, and use Upload.For example, use WS Files/Working-files/Git-connection/ only after checking that this folder is outside your Google Drive sync scope. The folder name does not automatically exclude it from sync or protect it.Avoid shared links, previews, Use in chat, and chat attachments for this file. Send its path to the agent rather than its contents.

3. Ask the agent to configure and validate

Replace the placeholders in this message; do not include the token itself:
The agent should load the file within the configuration process and pass the credential directly to Git, rather than display it through file-reading output. Setup depends on the agent’s tools and permissions; the request does not make WS Files a secret vault.

4. Remove the temporary file

Once the agent confirms that the credential is configured and the connection has been validated, delete the uploaded file through Files. Remove the temporary copy on your computer when it is no longer needed.Deleting the file does not remove the configured credential. It also does not guarantee removal from any earlier sync or backup copies.
This is a convenience method with a plaintext token file. WS Files does not give an uploaded token file special secret protection. Choose Terminal when the token must not be stored in ordinary workspace files.

Connection confirmed

The agent should report the provider, repository, authenticated read-access result, and any credential lifetime limitation. A listing of public repository references alone is insufficient proof of authentication. If validation fails, ask the agent to explain the cause without showing credential contents. Setup is complete when authenticated access to the intended repository succeeds. For later commit, pull, push, or PR/MR work, ask the agent to perform it. This connection does not change repository permissions, branch protection, or workspace permissions. It is separate from importing a skill from a public GitHub URL.