Authorization header:
<your-token> in your own environment. Do not put credentials in URLs, source files, screenshots, logs or agent conversations. The raw OpenAPI contract is public and needs no token.
Use an API token in automation
Create an API token in your token settings. Store it in your CI or runtime secret store and supply it in the bearer header. The quickstart examples expect the token in an environment variable namedGITHITS_API_TOKEN; the API does not require that variable name.
Use your CLI login
The existing GitHits login flow stores OAuth credentials in your system keychain by default. Scripts can capture a usable token withnpx githits@latest auth token; the CLI refreshes an expired OAuth token when needed. The quickstart shows command substitution without printing the token.
GITHITS_API_TOKEN takes precedence over the CLI’s stored OAuth credentials. Check the source safely with:
Use the API playground
Enter the token value, without theBearer prefix, in the playground’s bearer field. The playground adds the Authorization header for you. GitHits login is not integrated into this documentation site; enter credentials yourself, outside agent-controlled sessions.
The playground uses your browser to send requests directly to https://api.githits.dev. Reading the docs needs no authentication, but sending a request uses your token’s access and can perform the work described by the endpoint.
If the browser reports a network error without a readable API response, do not paste your token into a bug report. Confirm the request destination and see browser request errors.
Resolve authentication errors
ForAUTHENTICATION_REQUIRED, check the bearer header and replace expired or invalid credentials. TERMS_ACCEPTANCE_REQUIRED means you must review and accept the applicable terms; follow the terms acceptance instructions. Other access failures are described in errors.