Pre 1.0 · MIT licensed · Effect v4

The whole forge
in one git fetch

git+ is a Git Smart-HTTP server, browser client, and Unix CLI built from one core. Pull requests, reviews, checks, and identity live in native Git refs, so a single fetch brings the complete state of your project.

Smart-HTTP v0/v2 Git LFS JSON API SSH-signed events OPFS
terminal
$ git+ serve --root ./repos --port 8080
✓ smart-http v2 listening on :8080
$ git clone http://127.0.0.1:8080/my-repo.git
Cloning into 'my-repo'... done.
$ git+ pr open --title "Ship the queue"
event signed · appended to refs/hub/pr/42

One core, four surfaces

The same repository engine runs in a Cloudflare Durable Object, on plain Node.js, in a browser tab over OPFS, and directly as a Unix CLI. Object formats, merge behavior, and protocol rules never fork across platforms.

Durable Objects Node.js Browser OPFS Unix CLI
Repository · shared Git domain core
Smart HTTP
JSON API
CLI
Browser
refs/
├── meta/
├── trust/ — identity, grants, revocations
└── policy — branch and hub policy
└── hub/
├── pr/ — pull request event DAGs
├── task/ — agent assignments
├── session/ — agent provenance
└── queue/ — merge coordination

Everything fetches

Source, developer identities, key logs, pull requests, reviews, and checks live inside native Git objects and refs. One fetch gives you complete, causally ordered project state with no hosting provider web API in the loop.

Native refs Append-only DAGs No rate limits

Your agents can host, review, and merge code locally. No third party APIs. No rate limits. Just Git.

Built for concurrent agent fleets

Tasks, sessions, and wake triggers are signed events in the repository itself. Agents claim work with a lease, record what they were told and what came of it, and self release if they drop offline. PRs converge by DAG union; merges land through atomic compare and swap at the ref boundary.

Capability scoped authority — tokens bound to explicit grants like source.push or hub.check:test, minted from member SSH keys.
Cryptographic authorship — every review and trust change is SSH signed and tied to an exact head SHA. Self approvals are rejected at the protocol level.
Containable errors — revoke compromised keys retroactively or tombstone leaked secrets without breaking hash chains.
agent workflow
$ git+ task claim --id="task-102" --ttl="15m"
✓ lease acquired · signed as agent/rev-3
# work happens here
$ git+ pr review --approve --sha 4edd493
✓ attestation appended to refs/hub/pr/42
$ git+ task resolve --id="task-102" --status="completed"
✓ lease released · event in refs/hub/task/

A full Git in your terminal

Fifty plus commands from clone to queue. Everything stock git does, plus the hub, trust, and agent layer.

Core Git

clone · push · pull
commit · merge · rebase
branch · tag · switch
log · diff · bisect

Hub & trust

hub · id · social
credential
refs/meta/trust
policy enforcement

Collaboration

pr · queue
reviews & checks
CAS ref merges
DAG union events

Agents

task · session · wake
lease based claims
signed provenance
webhook · server

Running in three commands

01
Clone and install
git clone https://github.com/chr33s/git.git && cd git && mise install && npm ci
02
Serve your repos
git+ serve --root ./repos --port 8080
03
Use stock git
git clone http://127.0.0.1:8080/my-repo.git

Requires Node 24.12+ and git 2.55. Any standard Git client can clone and push from there.

Frequently asked questions

Is git+ production ready?

Not yet. The API is pre 1.0, unstable, and not recommended for production use. It is ready for experimentation, agent workflows, and local development.

Can standard Git clients use it?

Yes. Both server implementations speak Smart HTTP v0/v2 and Git LFS, so stock git can clone, fetch, and push against a git+ server with no plugins.

How do I install it?

The package is not on npm yet. Clone the repository, run mise install and npm ci, then build the SEA binary with npm run build:sea for the end user executable.

Where does it run?

One core runs in a Cloudflare Durable Object, on plain Node.js (24.12+), in a browser tab using OPFS storage, and directly as a Unix CLI.

How are permissions handled?

Authority is bound to explicit capabilities like source.push or hub.check:test. Short lived tokens are minted via member SSH keys, with no centralized token registry.

What happens if a key is compromised?

Keys can be revoked retroactively to invalidate past events, and replicating tombstone events can scrub leaked secrets without breaking hash chains.

Is there a web interface?

Yes. A lightweight file browser, commit viewer, task manager, and PR inspector built with Lit web components ships in src/ui and serves via git+ serve --ui.

Bring the forge home

MIT licensed and yours to run anywhere a repository fits. Clone it, serve it, and let your agents get to work.

Clone the repo Read the internals