curl --request POST \
--url https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'X-Outerlayer-App-Id: <api-key>' \
--data '{}'import requests
url = "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens"
payload = {}
headers = {
"X-Outerlayer-App-Id": "<api-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Outerlayer-App-Id': '<api-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({})
};
fetch('https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"X-Outerlayer-App-Id: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Outerlayer-App-Id", "<api-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens")
.header("X-Outerlayer-App-Id", "<api-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Outerlayer-App-Id"] = '<api-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"data": {
"access": "read",
"expiresAt": "<string>",
"permissions": {},
"repository": "<string>",
"token": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}Issue a GitHub token for a work item's repository or its control plane
Returns a GitHub App installation token limited to the item’s repository. access is read (contents, issues, pull requests, actions, checks and statuses, read only) or push (contents write, plus workflows write when the repository default branch’s .outerlayer/policy.yaml sets build.workflows: allow). With target: "control_plane" (and access: "read") the token is limited to the one repository whose live governs list names the item’s repository, with contents read and no other permission; a runner uses it to fetch that repository’s context. Only the key that holds the item’s live lease may ask, and only when a member of the org asked for the build the lease answers. The response is sent with Cache-Control: no-store. The gateway records that a token was issued and never stores it. Refusals: claim_not_held (403), build_request_not_from_member (403), claim_expired (410), work_item_has_no_repository (422), repository_not_connected (422 on this route; the create routes answer 404), repository_not_in_installation (422), repository_permissions_pending (409, the installation has not accepted a permission this token needs), work_item_withdrawn (409), no_control_plane (422, no control plane governs the item’s repository), context_conflict (409, more than one does), control_plane_not_in_installation (422, no governing control plane was found and an installation of the GitHub App could not read a designated one), repository_tokens_unavailable (503, this gateway has no GitHub App) and github_unavailable (503, GitHub was rate limiting or failing; retry), and github_request_failed (502, GitHub refused a request for another reason, such as a rejected App credential).
curl --request POST \
--url https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'X-Outerlayer-App-Id: <api-key>' \
--data '{}'import requests
url = "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens"
payload = {}
headers = {
"X-Outerlayer-App-Id": "<api-key>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'X-Outerlayer-App-Id': '<api-key>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({})
};
fetch('https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"X-Outerlayer-App-Id: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens"
payload := strings.NewReader("{}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-Outerlayer-App-Id", "<api-key>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens")
.header("X-Outerlayer-App-Id", "<api-key>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.outerlayer.ai/v1/work-items/{workItemId}/claim/tokens")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-Outerlayer-App-Id"] = '<api-key>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{}"
response = http.request(request)
puts response.read_body{
"data": {
"access": "read",
"expiresAt": "<string>",
"permissions": {},
"repository": "<string>",
"token": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}{
"error": {
"code": "<string>",
"message": "<string>"
}
}Authorizations
Factory id the request is scoped to.
API key (sk_outerlayer_*)
Headers
HTTP Message Signature (RFC 9421) made with the runner key's host key: runner=:<base64>:.
The signature's covered components and parameters: runner=("@method" "@path" "@query" "content-digest");created=<unix seconds>;nonce="<random>";keyid="<host key fingerprint>";alg="ed25519".
RFC 9530 digest of the request body, always sent, including for a request with none: sha-256=:<base64>:.
Path Parameters
Body
Response
A token was issued. Sent with Cache-Control: no-store.
Show child attributes
Show child attributes