[{"data":1,"prerenderedAt":761},["ShallowReactive",2],{"navigation_docs":3,"-reference-source-control-providers":168,"-reference-source-control-providers-surround":756},[4,146],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Guide","i-lucide-book-open","\u002Fguide","1.guide",[10,14,37,55,59,63,67,71,75,79,83,87,109,134,138,142],{"title":11,"path":12,"stem":13},"What is Agent Zero?","\u002Fguide\u002Fintroduction","1.guide\u002F1.introduction",{"title":15,"icon":16,"path":17,"stem":18,"children":19,"page":36},"API","i-lucide-plug","\u002Fguide\u002Fapi","1.guide\u002F10.api",[20,24,28,32],{"title":21,"path":22,"stem":23},"API overview","\u002Fguide\u002Fapi\u002Foverview","1.guide\u002F10.api\u002F1.overview",{"title":25,"path":26,"stem":27},"Define endpoints","\u002Fguide\u002Fapi\u002Fdefine-endpoints","1.guide\u002F10.api\u002F2.define-endpoints",{"title":29,"path":30,"stem":31},"Use the API from a client","\u002Fguide\u002Fapi\u002Fuse-from-client","1.guide\u002F10.api\u002F3.use-from-client",{"title":33,"path":34,"stem":35},"Protect endpoints","\u002Fguide\u002Fapi\u002Fprotect-endpoints","1.guide\u002F10.api\u002F4.protect-endpoints",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Authentication","i-lucide-lock","\u002Fguide\u002Fauthentication","1.guide\u002F11.authentication",[43,47,51],{"title":44,"path":45,"stem":46},"Authentication overview","\u002Fguide\u002Fauthentication\u002Foverview","1.guide\u002F11.authentication\u002F1.overview",{"title":48,"path":49,"stem":50},"GitHub OAuth","\u002Fguide\u002Fauthentication\u002Foauth","1.guide\u002F11.authentication\u002F2.oauth",{"title":52,"path":53,"stem":54},"Permissions","\u002Fguide\u002Fauthentication\u002Fpermissions","1.guide\u002F11.authentication\u002F3.permissions",{"title":56,"path":57,"stem":58},"Organizations","\u002Fguide\u002Forganizations","1.guide\u002F12.organizations",{"title":60,"path":61,"stem":62},"Frontend","\u002Fguide\u002Ffrontend","1.guide\u002F13.frontend",{"title":64,"path":65,"stem":66},"Mails","\u002Fguide\u002Fmails","1.guide\u002F14.mails",{"title":68,"path":69,"stem":70},"Internationalization","\u002Fguide\u002Finternationalization","1.guide\u002F15.internationalization",{"title":72,"path":73,"stem":74},"Deployment","\u002Fguide\u002Fdeployment","1.guide\u002F16.deployment",{"title":76,"path":77,"stem":78},"Tech stack","\u002Fguide\u002Ftech-stack","1.guide\u002F2.tech-stack",{"title":80,"path":81,"stem":82},"Installation","\u002Fguide\u002Finstallation","1.guide\u002F3.installation",{"title":84,"path":85,"stem":86},"Environment variables","\u002Fguide\u002Fenvironment-variables","1.guide\u002F4.environment-variables",{"title":88,"icon":89,"path":90,"stem":91,"children":92,"page":36},"Codebase","i-lucide-folder-tree","\u002Fguide\u002Fcodebase","1.guide\u002F5.codebase",[93,97,101,105],{"title":94,"path":95,"stem":96},"Codebase structure","\u002Fguide\u002Fcodebase\u002Fstructure","1.guide\u002F5.codebase\u002F1.structure",{"title":98,"path":99,"stem":100},"Dependencies","\u002Fguide\u002Fcodebase\u002Fdependencies","1.guide\u002F5.codebase\u002F2.dependencies",{"title":102,"path":103,"stem":104},"Formatting and linting","\u002Fguide\u002Fcodebase\u002Fformatting-linting","1.guide\u002F5.codebase\u002F3.formatting-linting",{"title":106,"path":107,"stem":108},"Agent Skills","\u002Fguide\u002Fcodebase\u002Fagent-skills","1.guide\u002F5.codebase\u002F4.agent-skills",{"title":110,"icon":111,"path":112,"stem":113,"children":114,"page":36},"Architecture","i-lucide-layers","\u002Fguide\u002Farchitecture","1.guide\u002F6.architecture",[115,118,122,126,130],{"title":110,"path":116,"stem":117},"\u002Fguide\u002Farchitecture\u002Foverview","1.guide\u002F6.architecture\u002F1.overview",{"title":119,"path":120,"stem":121},"State machine","\u002Fguide\u002Farchitecture\u002Fstate-machine","1.guide\u002F6.architecture\u002F2.state-machine",{"title":123,"path":124,"stem":125},"Execution boundary","\u002Fguide\u002Farchitecture\u002Fexecution-boundary","1.guide\u002F6.architecture\u002F3.execution-boundary",{"title":127,"path":128,"stem":129},"Issue-to-PR workflow","\u002Fguide\u002Farchitecture\u002Fissue-to-pr","1.guide\u002F6.architecture\u002F4.issue-to-pr",{"title":131,"path":132,"stem":133},"Adding a capability","\u002Fguide\u002Farchitecture\u002Fadding-a-capability","1.guide\u002F6.architecture\u002F5.adding-a-capability",{"title":135,"path":136,"stem":137},"Repository policy","\u002Fguide\u002Fconfiguration","1.guide\u002F7.configuration",{"title":139,"path":140,"stem":141},"Safety model","\u002Fguide\u002Fsafety","1.guide\u002F8.safety",{"title":143,"path":144,"stem":145},"Database","\u002Fguide\u002Fdatabase","1.guide\u002F9.database",{"title":147,"icon":148,"path":149,"stem":150,"children":151,"page":36},"Reference","i-lucide-book-marked","\u002Freference","2.reference",[152,156,160,164],{"title":153,"path":154,"stem":155},"CLI","\u002Freference\u002Fcli","2.reference\u002F1.cli",{"title":157,"path":158,"stem":159},"Model providers","\u002Freference\u002Fmodel-providers","2.reference\u002F2.model-providers",{"title":161,"path":162,"stem":163},"Source-control providers","\u002Freference\u002Fsource-control-providers","2.reference\u002F3.source-control-providers",{"title":165,"path":166,"stem":167},"Sandbox providers","\u002Freference\u002Fsandbox-providers","2.reference\u002F4.sandbox-providers",{"id":169,"title":161,"body":170,"description":749,"extension":750,"links":751,"meta":752,"navigation":753,"path":162,"seo":754,"stem":163,"__hash__":755},"docs\u002F2.reference\u002F3.source-control-providers.md",{"type":171,"value":172,"toc":740},"minimark",[173,193,196,201,257,261,440,443,505,509,512,615,626,633,637,644,726,729,733],[174,175,176,177,181,182,185,186,185,189,192],"p",{},"Agent Zero integrates with source-control platforms through ",[178,179,180],"code",{},"packages\u002Fsource-control",": a\nprovider-neutral boundary with one adapter per platform. The agent runtime consumes only shared\ncontracts (",[178,183,184],{},"ReviewInput",", ",[178,187,188],{},"FeedbackItem",[178,190,191],{},"PullRequestRef","); provider payload shapes, URLs, IDs,\nevent names, and credentials never cross the boundary. One deployment may connect repositories\nfrom several providers at once: inbound deliveries are routed to the adapter that recognizes\ntheir headers, and each configured provider keeps its own webhook secret.",[174,194,195],{},"The find → fix → verify workflow is identical on every provider. What differs is what each\nplatform can express, and the boundary makes those differences explicit instead of guessing.",[197,198,200],"h2",{"id":199},"contracts","Contracts",[202,203,204,211,217,227,247],"ul",{},[205,206,207,210],"li",{},[178,208,209],{},"SourceControlProvider"," — one platform: webhook recognition, authentication, event\nnormalization, and status publishing.",[205,212,213,216],{},[178,214,215],{},"ProviderCapabilities"," — what the adapter can actually deliver. Flags describe the webhook and\nAPI surface the adapter consumes, not the platform's brochure.",[205,218,219,222,223,226],{},[178,220,221],{},"ChangeRequestRef"," — a provider-neutral pull-\u002Fmerge-request reference. ",[178,224,225],{},"baseSha"," is present\nonly when the provider's payload carries a diff base.",[205,228,229,232,233,185,236,239,240,185,243,246],{},[178,230,231],{},"runOutcome"," — the provider-neutral meaning of a finished run (",[178,234,235],{},"success",[178,237,238],{},"failure",",\n",[178,241,242],{},"neutral",[178,244,245],{},"action-required","), derived from the evidence bundle in exactly one place.",[205,248,249,252,253,256],{},[178,250,251],{},"StatusPublication"," — what was actually reported, including a ",[178,254,255],{},"degraded"," note whenever an\noutcome had no native equivalent on the platform.",[197,258,260],{"id":259},"capability-matrix","Capability matrix",[262,263,264,289],"table",{},[265,266,267],"thead",{},[268,269,270,274,277,280,283,286],"tr",{},[271,272,273],"th",{},"Capability",[271,275,276],{},"GitHub",[271,278,279],{},"GitLab",[271,281,282],{},"Bitbucket Cloud",[271,284,285],{},"Bitbucket Data Center",[271,287,288],{},"Gitea \u002F Forgejo",[290,291,292,310,328,344,359,377,393,409,425],"tbody",{},[268,293,294,298,301,304,306,308],{},[295,296,297],"td",{},"Webhook authentication",[295,299,300],{},"HMAC-SHA256",[295,302,303],{},"shared token",[295,305,300],{},[295,307,300],{},[295,309,300],{},[268,311,312,315,318,321,324,326],{},[295,313,314],{},"Status reporting",[295,316,317],{},"check runs",[295,319,320],{},"commit status",[295,322,323],{},"build status",[295,325,323],{},[295,327,320],{},[268,329,330,333,336,338,340,342],{},[295,331,332],{},"Neutral conclusion",[295,334,335],{},"native",[295,337,255],{},[295,339,255],{},[295,341,255],{},[295,343,255],{},[268,345,346,349,351,353,355,357],{},[295,347,348],{},"Action-required",[295,350,335],{},[295,352,255],{},[295,354,255],{},[295,356,255],{},[295,358,255],{},[268,360,361,364,367,370,373,375],{},[295,362,363],{},"Review submissions",[295,365,366],{},"yes",[295,368,369],{},"notes only",[295,371,372],{},"comments only",[295,374,372],{},[295,376,366],{},[268,378,379,382,384,387,389,391],{},[295,380,381],{},"Formal change requests",[295,383,366],{},[295,385,386],{},"no text",[295,388,386],{},[295,390,386],{},[295,392,366],{},[268,394,395,398,400,402,404,407],{},[295,396,397],{},"Inline comment anchors",[295,399,366],{},[295,401,366],{},[295,403,366],{},[295,405,406],{},"not delivered",[295,408,406],{},[268,410,411,414,416,419,421,423],{},[295,412,413],{},"Bot author detection",[295,415,366],{},[295,417,418],{},"no",[295,420,418],{},[295,422,418],{},[295,424,418],{},[268,426,427,430,432,434,436,438],{},[295,428,429],{},"Diff base in payload",[295,431,366],{},[295,433,418],{},[295,435,366],{},[295,437,366],{},[295,439,366],{},[174,441,442],{},"Notes on explicit degradation:",[202,444,445,471,477,491],{},[205,446,447,451,452,454,455,458,459,462,463,466,467,470],{},[448,449,450],"strong",{},"Statuses."," Only GitHub can express ",[178,453,242],{}," and ",[178,456,457],{},"action_required",". Elsewhere a neutral\noutcome (for example, incorrect feedback rejected with evidence) is reported as the platform's\nsuccess state, and action-required maps to the platform's blocking state (",[178,460,461],{},"failed"," on GitLab\nand Bitbucket, ",[178,464,465],{},"warning"," on Gitea). Every mapping is returned in ",[178,468,469],{},"StatusPublication.degraded","\nso callers can surface it; a failed verification is never presented as success anywhere.",[205,472,473,476],{},[448,474,475],{},"Diff base."," GitLab merge-request webhooks carry no base commit. The adapter never invents\none: the run receives no pull-request range and falls back to runner-side diff discovery.",[205,478,479,482,483,486,487,490],{},[448,480,481],{},"Formal change requests."," GitLab approvals\u002F\"request changes\", Bitbucket's\n",[178,484,485],{},"changes_request_created",", and Bitbucket Data Center's ",[178,488,489],{},"needs_work"," arrive without text, so\nthere is no claim to validate and the events are ignored. Reviewer text arrives as comments.",[205,492,493,496,497,500,501,504],{},[448,494,495],{},"Bots."," Only GitHub payloads mark bot authors, so ",[178,498,499],{},"allowBots: false"," filters bots there and\nis documented as unenforceable elsewhere. Self-replies are prevented on every provider through\n",[178,502,503],{},"ignoreAuthors",".",[197,506,508],{"id":507},"webhook-routing","Webhook routing",[174,510,511],{},"Deliveries are identified by provider headers, not by URL:",[262,513,514,527],{},[265,515,516],{},[268,517,518,521,524],{},[271,519,520],{},"Provider",[271,522,523],{},"Event header",[271,525,526],{},"Authentication header",[290,528,529,548,563,579,593],{},[268,530,531,533,538],{},[295,532,276],{},[295,534,535],{},[178,536,537],{},"X-GitHub-Event",[295,539,540,543,544,547],{},[178,541,542],{},"X-Hub-Signature-256"," (",[178,545,546],{},"sha256=",")",[268,549,550,552,557],{},[295,551,279],{},[295,553,554],{},[178,555,556],{},"X-Gitlab-Event",[295,558,559,562],{},[178,560,561],{},"X-Gitlab-Token"," (constant-time)",[268,564,565,567,572],{},[295,566,282],{},[295,568,569],{},[178,570,571],{},"X-Event-Key",[295,573,574,543,577,547],{},[178,575,576],{},"X-Hub-Signature",[178,578,546],{},[268,580,581,583,587],{},[295,582,285],{},[295,584,585],{},[178,586,571],{},[295,588,589,543,591,547],{},[178,590,576],{},[178,592,546],{},[268,594,595,597,606],{},[295,596,288],{},[295,598,599,602,603],{},[178,600,601],{},"X-Gitea-Event"," \u002F ",[178,604,605],{},"X-Forgejo-Event",[295,607,608,602,611,614],{},[178,609,610],{},"X-Gitea-Signature",[178,612,613],{},"X-Forgejo-Signature"," (bare hex)",[174,616,617,618,621,622,625],{},"Gitea and Forgejo also send GitHub compatibility headers; the registry consults their adapter\nfirst and the GitHub adapter declines deliveries carrying a Gitea or Forgejo header. The two\nBitbucket products are distinguished by event-key shape (",[178,619,620],{},"pullrequest:*"," versus ",[178,623,624],{},"pr:*",").",[174,627,628,629,632],{},"Regardless of provider, a webhook can never escalate a run: parsed events produce ",[178,630,631],{},"observe","-mode\ninput unless the deployment's own policy chooses otherwise, and an unverifiable delivery is\nrejected before its payload is parsed.",[197,634,636],{"id":635},"status-credentials","Status credentials",[174,638,639,640,643],{},"Status publishing reads one fixed environment variable per provider; credentials are sent only\nas an ",[178,641,642],{},"Authorization"," header and are redacted from any error raised.",[262,645,646,658],{},[265,647,648],{},[268,649,650,652,655],{},[271,651,520],{},[271,653,654],{},"Variable",[271,656,657],{},"Notes",[290,659,660,672,687,699,713],{},[268,661,662,664,669],{},[295,663,276],{},[295,665,666],{},[178,667,668],{},"GITHUB_TOKEN",[295,670,671],{},"Checks API",[268,673,674,676,681],{},[295,675,279],{},[295,677,678],{},[178,679,680],{},"GITLAB_TOKEN",[295,682,683,686],{},[178,684,685],{},"baseUrl"," for GitLab Self-Managed",[268,688,689,691,696],{},[295,690,282],{},[295,692,693],{},[178,694,695],{},"BITBUCKET_CLOUD_TOKEN",[295,697,698],{},"access token with repository write scope",[268,700,701,703,708],{},[295,702,285],{},[295,704,705],{},[178,706,707],{},"BITBUCKET_DATA_CENTER_TOKEN",[295,709,710,712],{},[178,711,685],{}," required",[268,714,715,717,722],{},[295,716,288],{},[295,718,719],{},[178,720,721],{},"GITEA_TOKEN",[295,723,724,712],{},[178,725,685],{},[174,727,728],{},"The two Bitbucket products keep separate variables because a deployment may connect both with\ndistinct credentials; a shared variable would force one publication path to authenticate with\nthe other product's token.",[197,730,732],{"id":731},"conformance","Conformance",[174,734,735,736,739],{},"Every adapter must pass the same conformance suite (",[178,737,738],{},"src\u002Fconformance.ts","), driven by authentic\nsigned fixtures per provider: recognition, constant-time authentication with forgery and\ntampering rejection, proactive and feedback normalization, self-reply suppression, junk-payload\ntolerance, observe-by-default input, credential-free status publishing, and explicit degradation\nof unsupported conclusions. New provider adapters start by supplying fixtures to this suite.",{"title":741,"searchDepth":742,"depth":742,"links":743},"",2,[744,745,746,747,748],{"id":199,"depth":742,"text":200},{"id":259,"depth":742,"text":260},{"id":507,"depth":742,"text":508},{"id":635,"depth":742,"text":636},{"id":731,"depth":742,"text":732},"Agent Zero integrates with source-control platforms through packages\u002Fsource-control: a\nprovider-neutral boundary with one adapter per platform. The agent runtime consumes only shared\ncontracts (ReviewInput, FeedbackItem, PullRequestRef); provider payload shapes, URLs, IDs,\nevent names, and credentials never cross the boundary. One deployment may connect repositories\nfrom several providers at once: inbound deliveries are routed to the adapter that recognizes\ntheir headers, and each configured provider keeps its own webhook secret.","md",null,{},true,{"title":161,"description":749},"MXrC9E0ykvvV04e9zB5kQK8RPlb2rW3GMUcXVe954Ks",[757,759],{"title":157,"path":158,"stem":159,"description":758,"children":-1},"Agent Zero supports native OpenAI, Anthropic, and Google Generative AI adapters, Vercel AI Gateway, and arbitrary OpenAI-compatible endpoints — all behind one ModelProvider contract in packages\u002Fmodels, sharing one structured-output, usage-accounting, timeout, and error-redaction path.",{"title":165,"path":166,"stem":167,"description":760,"children":-1},"Agent Zero v0.3 defines the vendor-neutral lifecycle in packages\u002Frunner: provision a credential-free request, expose the resulting checkout only as a Runner, stop it explicitly, and expire bounded leases. A provider adapter owns its client and credentials privately. No SDK response or secret is copied into agent state, task history, lease snapshots, or logs.",1787482152997]