Skip to content
StellarFirmStellarFirm
Mission manual
Esc

Type a word to search every page. Try , or .

Module 01 · Getting started

Connect your code

The checklist for giving the Coder a repository on GitHub, GitLab, or Bitbucket: which token, which permissions, where to connect it, and a first test.

View as Markdown
On this page

Before the Coder can work on your code, it needs three things from you: a token from your code host, that token connected in StellarFirm, and a repository to work in. This page is the checklist for all three, on GitHub, GitLab, or Bitbucket. Each host's own page has the exact clicks.

Checklist#

  • You have the StellarFirm desktop app and are signed in.
  • You know which repository the Coder should work in. A small or test repository is a good first choice.
  • You created a token on your code host with the permissions below, and nothing more.
  • You connected the token under Integrations and the card shows Connected.
  • You told the Coder its repository, in your message or under Settings, Coders.
  • You chose what happens after the work in your house rules.
  • You ran a read-only test prompt and got a sensible answer.

Choose your token#

Code hostNarrowest tokenToken that does the mostWhat you pasteFull guide
GitHubFine-grained token, chosen repositories onlyClassic token with repoThe tokenGitHub
GitLabProject access token (Premium or Ultimate on gitlab.com)Personal access tokenThe tokenGitLab
BitbucketRepository access tokenAtlassian token with scopesThe token, plus the account email for an Atlassian tokenBitbucket

Start narrow. You can always make a new token with more access later, and a narrow token limits what any mistake can touch.

The permissions, side by side#

Give the token what the steps you want need. Reads run on their own; every write waits for your Approve or follows your merge policy.

StepGitHub fine-grained tokenGitLab tokenBitbucket repository access tokenBitbucket Atlassian token
Read the code, pull or merge requests, changed filesContents, Pull requests, Metadata: ReadapiRepositories, Pull requests: Readread:repository, read:pullrequest
Read check, pipeline, or build resultsCommit statuses: ReadapiRepositories: Readread:repository
Read and open issuesIssues: Read and writeapiNot possibleread:issue, write:issue
Push its branchContents: Read and writewrite_repository, Developer roleRepositories: Writewrite:repository
Open a pull or merge requestPull requests: Read and writeapi, Developer rolePull requests: Writewrite:pullrequest
Merge, when your rules allowContents: Read and writeapi, Maintainer for a protected branchPull requests: Writewrite:pullrequest
Create a repositoryAdministration: Read and write, All repositoriesNot availableNot availableNot available

Bitbucket's Atlassian scopes all end in :bitbucket, for example read:repository:bitbucket. A GitHub classic token with repo covers its whole column, and also reads check runs, which fine-grained tokens cannot.

Connect it#

  1. Open the StellarFirm desktop app and sign in.
  2. Open Integrations and pick your code host from the Code hosting shelf.
  3. Paste the token. For a Bitbucket Atlassian token, also enter the account email.
  4. Leave the live switch on and press Connect.
  5. Check that the card shows Connected.

The desktop app saves the token on your computer. It is never shown back to you, never goes into chat, and is handed to one git command at a time when the Coder pushes. See security.

Give the Coder its repository#

The Coder works in one repository at a time. Tell it which one:

  • In each message. Write it as owner/repository (GitLab: group/project; Bitbucket: workspace/repository), or paste its link.
  • Once, per Coder. Under Settings, Coders, each Coder has Repository and login: the code host, the repository, and whose login it uses. A message that names that repository goes to that Coder.

Shared or own login. By default every Coder uses the token you connected under Integrations, so its work shows your name on the code host. Choose Its own login to give a Coder a separate token, for example a machine account that only has access to one repository. Running several Coders? Give each its own repository and, if you like, its own login. See several Coders.

Decide what happens after the work#

The token says what the Coder could do. Your house rules say what it does.

SettingWhereStart with
Merge policyHouse rulesReview only: the Coder opens a pull request and stops
ShippingHouse rulesNever
Auto-approveApprovals and SettingsEverything off
Written rulesYour company briefThree lines on branches, tests, and what never to touch

The Coder opens drafts. A draft cannot be merged on any of the three hosts, so mark it ready for review on the host before you ask the Coder to merge it.

Test the connection#

Run a read-only prompt first. Nothing is written, so nothing waits for Approve.

PromptRead-only check

Coder, in [repository], list the open pull requests and tell me what each one is waiting for.

If the answer lists your real pull requests, the token works. Then try a small change:

PromptFirst small change

Coder, in [repository], fix [one small thing]. Run the tests and open a pull request for review once I Approve.

When something is off#

What you seeUsual causeFix
The job stops as Blocked before codingThe token cannot read the repository, or has expiredCheck the repository name and the token's access and expiry
The Coder says no code host is connectedNothing is connected, or the card is turned offConnect the token under Integrations in the desktop app
Reads work, but the push or pull request is refusedThe token is read only, or the role is too lowAdd the write permission from the table above
No check resultsGitHub fine-grained tokens cannot read check runsUse a classic token, or a CI that posts commit statuses
The merge is refusedThe pull request is a draft, checks are not green, or branch protection blocks itMark it ready, wait for green, or adjust the protection

Keep it safe#

  • Least access. Only the repositories and permissions the Coder needs.
  • Set an expiry. A token that expires limits the damage of a leak. The Coder tells you when it needs a new one.
  • Never paste a token in chat. Tokens go only into Integrations or Settings, Coders.
  • Revoke on the host. Deleting the token on GitHub, GitLab, or Bitbucket stops access straight away. Then choose Turn off on the card.

Next#