Mint a short-lived GitHub installation token for a repo
Called by the host daemon to obtain a short-lived GitHub App installation token for a specific repository. The token is minted from the org's GitHub App installation and expires in ~1 hour. The `orgId` in the body must match the authenticated org. Auth: `Bearer rsk_*` via `getCliOrSessionAuth` OR worker runtime JWT. Returns `{ token: null, reason }` (HTTP 200) on soft failures so the caller can decide whether to fall back to a stored PAT.
Rensei API key presented as Authorization: Bearer rsk_live_. Required API-key scopes are recorded per operation in x-rensei-required-scopes.
In: header
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/api/daemon/git-token" \ -H "Content-Type: application/json" \ -d '{ "orgId": "string" }'{
"token": "string",
"expiresAt": "2019-08-24T14:15:22Z"
}{
"error": "Session not found"
}{
"error": "Session not found"
}{
"error": "Session not found"
}{
"error": "Session not found"
}Resolve credential env map for a session
Runtime-worker-JWT-only secret-release endpoint used at session spawn. Requires `worker:session`. Before any credential read, the platform resolves the canonical scope from the active worker row and claimed session: JWT worker (`sub`), org, and project claims must exactly match the active worker; the session must be owned by that worker in the same organization, and session project metadata must match when present. Body `orgId` must match that canonical scope and optional `projectId` is an exact assertion, never an override. Missing or mismatched ownership is collapsed to 404. Returns the blocklist-filtered agent environment and refresh horizon. The optional synthetic `poolId` is cost-attribution metadata and is not emitted into the agent environment. Audit is appended asynchronously without secret values.
Post merge-queue landing verdict
Called by a daemon worker with `LANDING_CAPABILITY` after attempting to land a commit onto the merge queue (automerge / fast-forward). Records the outcome and triggers post-landing cleanup (lock release, next-work promotion, Linear notification). Auth: runtime JWT. Cross-tenant guard: `orgId` in body must match the JWT's org claim (mismatch returns 404, not 403).