GitLab
GitLab.com or GitLab Self-Managed.
Access mode: Read-only
Required information
| Field | Details |
|---|---|
| Instance URL | https://gitlab.com or self-hosted URL. |
| Group / Projects | GitLab group ID or list of project paths. |
| Authentication | Project Access Token (preferred), Group Access Token, or Personal Access Token. |
| Access scope | read_repository, read_api. |
Network considerations
GitLab.com: HTTPS over 443. No VPN needed.
Self-managed: VPN, IP allowlist, or public endpoint. Ensure /api/v4/ is routable.
Reverse proxy: If behind one, confirm API endpoints are not blocked.
Credential and auth management
Preferred: Project Access Token. Scoped to single project, read_repository only. No human user.
Preferred: Group Access Token. Covers multiple projects in a group. Good for broad access.
Acceptable: Personal Access Token. Tied to a user account.
Token expiry: Configurable. Set rotation reminders.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Authentication | GET /api/v4/user | 200 with identity |
| Project access | GET /api/v4/projects/<id> | 200 with project info |
| Repository read | GET /api/v4/projects/<id>/repository/tree | Lists files |
| File content | GET /api/v4/projects/<id>/repository/files/<path>/raw | Returns file content |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.