Option 1: API token (recommended for CI)
An API token lets you authenticate without any browser interaction. The token is read from an environment variable, so you can inject it as a CI secret without modifying your code or config files.1
Get your API token
Open your token settings to create an API token. Copy your API token — it starts with
ghi-.2
Set the environment variable
Export the token in your shell or add it to your CI configuration as a secret:
3
Verify authentication
Confirm that GitHits picks up the token:The output should show you as authenticated and indicate that credentials are sourced from the environment variable.
GitHub Actions example
Add your API token as a repository secret namedGITHITS_API_TOKEN, then reference it in your workflow:
variables:), CircleCI (project environment variables), and any other CI system that supports injecting secrets as environment variables.
Group requests by run
With CLI 0.25.1 or later, setGITHITS_SESSION_ID before starting commands to group requests from one CI or agent run. Use an opaque value of 1–64 ASCII letters, digits, underscores, or hyphens, such as ci_run-42_agent-a. Keep the value consistent for related commands and choose a new value for a separate run. GitHits sends explicit values unchanged; leave it unset for automatic detection.
Option 2: OAuth over an SSH tunnel
If the CLI runs on a remote host but your browser runs locally, choose a fixed callback port on the remote host:Remote host
Browser machine
user@remote-host with your SSH destination.