Blocks a native client (#11, #12).
/api/v1/cmd 404s on gitbay.org: the route is registered only when cfg.API.Enabled, and /etc/gitbay/config.toml has no [api] section. The entire JSON API is off in production, so no client can talk to it.
Two parts:
-
Set [api] enabled = true on bay1. Do this alongside rate limiting (#39) rather than before it — the surface is unmetered today.
-
Token onboarding. token create is SSHOnly and the 401 body says 'mint one over SSH', which is a dead end on a device with no OpenSSH. The principle holds — a token is a credential and should not be minted in a browser — so the answer is transfer, not relocation: mint on a machine that has ssh, then paste into the app. Pasting already works end to end once the API is on.
Worth considering: token create --qr, printing the token as a QR in the terminal for the app's camera. Keeps the credential off the web entirely and reads as a CLI-first answer rather than an apology for one. Needs a small pure-Go QR dependency.