Skip to main content

Git Access for Coding Agents

Git Proxy lets a background agent run ordinary git clone, fetch, pull, and push against GitHub without a personal access token. Each agent gets an allowlist of repositories. When it runs a remote git command, Willow mints a short-lived GitHub App token scoped to that one repository, and the App's private key never leaves Willow.

This is separate from the GitHub MCP connector. The connector gives an agent tools for issues, pull requests, and the REST API. Git Proxy gives it the git command line.

Beta

Git Proxy is in beta. Ask your Willow contact to enable it for your organization. Until it is enabled, the settings card and the per-agent Git repositories section are hidden.

How it works​

  1. You create a GitHub App, install it on the repositories agents may use, and store its credentials in Willow.
  2. On each agent, you list the repositories it may use and whether it may push.
  3. The agent runs willow-git, a git credential helper from the @mcp-s/git package.
  4. On a remote git command, willow-git asks the Willow gateway for a token for that repository. Willow checks the allowlist and returns a token that works for that repository only and expires within the hour.

Local commands such as status, add, and commit never call Willow.

Where willow-git comes from depends on the platform:

PlatformWhat you do
Willow AgentsNothing beyond the allowlist. Willow sets it up on Deploy.
Claude Managed AgentsNothing beyond the allowlist. Willow sets it up in your Anthropic workspace on Deploy.
Custom, your own type, or the Kubernetes harnessInstall the CLI and set three environment variables in your runtime. See Custom runtimes.

Create the GitHub App​

Create an App under your GitHub organization at Settings > Developer settings > GitHub Apps > New GitHub App:

FieldValue
GitHub App nameAnything, for example Willow Coding Agents. Commits and pushes show this name.
Homepage URLYour Willow dashboard URL.
WebhookInactive.
Repository permissions > ContentsRead and write. This is what lets the agent push commits and branches. Read-only is enough only when agents never push.
Repository permissions > Pull requestsRead and write if the agent should open pull requests. Read-only lets it see pull requests, not create or update them.
Repository permissions > MetadataRead-only (required).
Where can this GitHub App be installed?Only on this account.

Opening a pull request needs both write permissions. Pull requests Read and write is what creates the pull request. Contents Read and write is what pushes the branch it points at. On the agent, that repository's access must be write as well: a read repository gets a read-only token, so it can neither push nor open a pull request.

Then:

  1. Select Generate a private key and keep the downloaded .pem file.
  2. Select Install App and choose the repositories agents may use. Willow can only mint tokens for repositories in this installation.
  3. Copy the App ID from the App's settings page.
  4. Copy the Installation ID from the installation URL, https://github.com/organizations/<org>/settings/installations/<installation-id>.

Connect the App to Willow​

Open Manage > Machine Users > Background Agents, select the gear icon, and find the GitHub App (coding agents) card. Select Set up.

  1. Paste the App ID, Installation ID, and Private key (PEM).
  2. Under Token permissions, optionally narrow Contents and Pull requests to read for every agent. Setting Pull requests to read here blocks opening pull requests even when the GitHub App allows it.
  3. Select Test connection & Save. Willow lists the installation's repositories to prove the credentials work.

The card then reads Configured with the App and installation IDs. The private key is encrypted and never shown again; to replace it, open Manage and paste a new one.

Choose an agent's repositories​

Open the agent, go to Settings, and expand Git repositories.

  1. Pick a repository from Select repository, which lists what the App installation can reach, or choose Custom… and type owner/name.
  2. Optionally set the default branch.
  3. Set access to write or read. The default is write.
  4. Save.

A read repository gets a read-only token, so GitHub rejects a push, and willow-git refuses it before it reaches GitHub. An agent with an empty list cannot get a token at all.

The allowlist is checked every time a token is requested, so removing a repository or switching it to read takes effect on the agent's next git command.

Willow Agents and Claude Managed Agents​

Nothing to install. Save the repository list and select Deploy; Willow sets up git for the agent. Deploy again whenever you change the list.

To check it, open Test on the agent's Overview tab and ask it to clone one of its repositories and list the files.

On Claude Managed Agents, the agent's Willow token is stored in your Anthropic vault as Willow git proxy token and is never visible inside the sandbox.

Open pull requests​

After pushing a branch, the agent opens a pull request with:

willow-git pr create --title "Fix README title" --body "What changed and why"

It runs from inside the clone and uses the current branch as the head and the repository's default branch as the base. Pass --base, --head, --repo, or --draft to change that. The pull request is opened by the GitHub App, so the repository must be write on the agent and the App needs Pull requests Read and write.

Willow Agents and Claude Managed Agents are told to use this command. They do not need gh or a GitHub token.

Custom runtimes​

On Custom, a type you register, or the Kubernetes harness, Willow does not control the machine the agent runs on, so install the CLI in your image or startup script:

npm i -g @mcp-s/git

export WILLOW_GATEWAY_URL=https://<your-run-gateway>
export WILLOW_AGENT_SLUG=<agent-slug>
export WILLOW_AGENT_TOKEN=<access_key>:<secret>

willow-git setup

Take these values from the agent's Git repositories section, which has a copy button for the whole block. Copying requires a revealed secret, so rotate the secret first if you no longer have it. Deploying also rotates the secret, so refresh WILLOW_AGENT_TOKEN after every deploy.

willow-git setup writes ~/.willow/git/config (mode 0600) and registers the credential helper for https://github.com. To route bare git through Willow as well, put the package's shim first on PATH:

export PATH="$(npm root -g)/@mcp-s/git/git-shim:$PATH"

SSH remotes such as git@github.com:owner/repo.git are rewritten to HTTPS for authentication, so existing clones keep working.

Troubleshooting​

willow-git prints the error Willow returns:

ErrorCauseFix
git_proxy_not_configuredThe agent has no repositories, or the GitHub App is not set up.Add repositories to the agent, or finish Connect the App to Willow.
repo_not_allowedThe repository is not on the agent's list, or belongs to a different owner than the installation.Add it under Git repositories.
repo_not_in_installationThe repository is on the list, but the GitHub App is not installed on it.In GitHub, add the repository to the App installation.
git_proxy_disabledGit Proxy is not enabled for your organization.Ask your Willow contact.
WILLOW_GATEWAY_URL is requiredwillow-git ran before setup.Run the exports and willow-git setup first. On managed platforms, tell the agent to follow its git setup instructions.
Git asks for a usernameThe credential helper is not registered in this session.Run willow-git setup. Managed sandboxes start fresh, so this is needed once per session.

Security​

  • Tokens are scoped to one repository and expire within the hour. willow-git caches them in memory and in a 0600 temp file until five minutes before expiry.
  • The GitHub App private key stays encrypted in Willow. Agents only ever hold their own gateway credential and the short-lived repository token.
  • Commits and pushes are attributed to the GitHub App.
  • Every token Willow issues is recorded in the security audit log as backgroundAgent.gitToken, with the agent and repository. The token itself is never logged.