---
title: "Create git configuration"
method: POST
path: "/api/v1/models/{modelId}/git"
tags: ["Models"]
---

# Create git configuration

`POST /api/v1/models/{modelId}/git`

Create git configuration for a model. For SSH auth, Omni generates a deploy keypair by default; supply deployPrivateKey (with deployKeyPassphrase for encrypted keys) to bring your own instead.

## Path parameters

- `modelId` string, uuid, required — Model UUID

## Request body

- ModelsGitCreateBody
  - `authMethod` 'ssh' | 'https_token' | 'github_app' — Authentication method. "ssh" for deploy key (default), "https_token" for deploy token/PAT, "github_app" for a GitHub App installation (github.com only).
  - `baseBranch` string — The target branch for Omni pull requests. Defaults to "main"
  - `branchPerPullRequest` boolean — If true, all pull requests will create a branch in Omni. Defaults to false
  - `cloneUrl` string — Clone URL of the git repository. SSH (git@...) for deploy key auth, HTTPS (https://...) for token or GitHub App auth.
  - `commitSigningCommitterEmail` string, email, nullable — Verified email of the GitHub user that owns the registered signing key, written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterName.
  - `commitSigningCommitterName` string, nullable — Display name written into signed commits (github_app auth only). Send a string to set it, null to clear it (disabling signing), or omit it to leave the stored value unchanged. Must be set, cleared, or omitted together with commitSigningCommitterEmail.
  - `deployKeyPassphrase` string — Passphrase for deployPrivateKey when it is encrypted. Omni uses it once to decrypt the key, then stores the key under its own encryption at rest; the passphrase itself is not retained.
  - `deployPrivateKey` string — Bring-your-own SSH deploy private key in PEM format (RSA or ED25519, as produced by ssh-keygen), used instead of an Omni-generated keypair. On update it replaces the current key, enabling zero-downtime rotation: authorize the matching public key with your git provider first, then set it here. Only valid for SSH auth.
  - `gitFollower` boolean — If true, the shared model will be read-only. Defaults to false
  - `gitServiceProvider` 'github' | 'gitlab' | 'azure_devops' | 'bitbucket' | 'bitbucket_datacenter' | 'auto' — The git provider type. Use "auto" for automatic detection. Defaults to "auto"
  - `githubAppInstallationId` string — Numeric GitHub App installation ID (the value in the URL after installing the Omni GitHub App on the repo). Required when authMethod is "github_app".
  - `modelPath` string — Path to model files in the repository. Defaults to omni/<model-name>. Use a plain name (e.g., "my_model") for omni/my_model, or a leading slash for a custom path (e.g., "/bi/models/sales")
  - `requirePullRequest` 'always' | 'users-only' | 'never' — Controls when pull requests are required. Defaults to "never"
  - `sshUrl` string — Deprecated — use cloneUrl. Clone URL of the git repository.
  - `token` string — HTTPS token for authentication (deploy token value, PAT, etc.). Required when authMethod is "https_token".
  - `webUrl` string — Custom web URL for the git repository. Use when the clone URL goes through a tunnel/VPC and differs from the inferred HTTPS address

## Response `201`

Git configuration created

- ModelsGitCreateResponse
  - `authMethod` 'ssh' | 'https_token' | 'github_app', required — Authentication method. "ssh" for deploy key, "https_token" for deploy token/PAT, "github_app" for a GitHub App installation.
  - `baseBranch` string, required — The target branch for Omni pull requests
  - `branchPerPullRequest` boolean, required — If true, all pull requests will create a branch in Omni, even those created outside of the tool
  - `cloneUrl` string, required — Clone URL of the git repository (SSH or HTTPS)
  - `commitSigningCommitterEmail` string, nullable, required — Committer email written into signed commits (github_app auth). Null when signing is not configured.
  - `commitSigningCommitterName` string, nullable, required — Committer display name written into signed commits (github_app auth). Null when signing is not configured.
  - `commitSigningPublicKey` string, nullable, required — SSHSIG signing public key to register on the committer’s GitHub user (github_app auth). Null for other auth methods.
  - `gitFollower` boolean, required — If true, the shared model is read-only and can only be updated by merging pull requests to the base branch
  - `gitServiceProvider` string, required — The git provider type
  - `githubAppInstallationId` string, nullable, required — GitHub App installation ID. Null unless github_app auth.
  - `modelPath` string, nullable, required — Path to model files in the repository
  - `publicKey` string, nullable, required — SSH public key for repository access (deploy key). Null for HTTPS token auth.
  - `requirePullRequest` 'always' | 'users-only' | 'never', required — When pull requests are required: "always" for all changes, "users-only" for user-initiated changes only, "never" for direct commits.
  - `sshUrl` string, required — Deprecated — use cloneUrl. Clone URL of the git repository.
  - `webUrl` string, nullable, required — Custom web URL for the git repository, or null if not set
  - `webhookSecret` string — Webhook secret for signature verification. Only included if requested via ?include=webhookSecret
  - `webhookUrl` string, required — Webhook URL to configure in your git provider

## Other responses

- `400` — Invalid SSH URL or configuration
- `401` — Authentication required
- `403` — Permission denied
- `404` — Model not found
- `409` — Git already configured for this model

---

[API](https://skmtc.net/omniapp/apis/omni-api.md) · [All operations](https://skmtc.net/omniapp/apis/omni-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/omniapp/omni-api/versions/4701f292c621/schema)
