gitcollect / examples

Real commands with real output — personal account and team/org scenarios side by side.

Authentication All users

Run once per platform. Tokens are stored in ~/.gitcollect/config. Every command that touches the platform reads from there.

Terminal
# GitHub (default) $ gitcollect auth Enter your GitHub personal access token: •••••••••••••••• ✓ Authenticated as jsmith (github.com) Token stored at ~/.gitcollect/config # GitLab (cloud) $ gitcollect auth --host gitlab.com Enter your GitLab personal access token (glpat-...): •••••••••••••••• ✓ Authenticated as jsmith (gitlab.com) # Self-hosted GitLab $ gitcollect auth --host git.acme-corp.com ✓ Authenticated as jsmith (git.acme-corp.com) # Confirm stored identities $ gitcollect whoami HOST LOGIN ID github.com jsmith 1042871 gitlab.com jsmith 99431

GitHub token scopes needed: repo, read:org (for team import), admin:org (to add collaborators to org repos). GitLab: api scope on a glpat-… token.

Create a personal collection Personal

Group your own repos — dotfiles, side projects, configs — into a named collection you can clone on any machine in one command.

Personal account — create and populate
$ gitcollect init my-dotfiles ✓ Created collection "my-dotfiles" (private) ~/.gitcollect/collections/my-dotfiles.yaml $ gitcollect add my-dotfiles neovim-config zsh-config tmux-config ✓ Added jsmith/neovim-config to "my-dotfiles" ✓ Added jsmith/zsh-config to "my-dotfiles" ✓ Added jsmith/tmux-config to "my-dotfiles" $ gitcollect show my-dotfiles Collection: my-dotfiles Owner: jsmith Visibility: private Host: github.com Repos (3): neovim-config zsh-config tmux-config

Add and remove repos Personal

Add with options
# Add a repo from a different user/org $ gitcollect add my-dotfiles --repo ohmyzsh/ohmyzsh ✓ Added ohmyzsh/ohmyzsh to "my-dotfiles" # Add multiple in one call $ gitcollect add my-dotfiles zsh-config tmux-config alacritty-theme ✓ Added jsmith/zsh-config ✓ Added jsmith/tmux-config ✓ Added jsmith/alacritty-theme # Remove a repo (confirmation required) $ gitcollect remove my-dotfiles alacritty-theme This will remove "alacritty-theme" from "my-dotfiles" (type "alacritty-theme" to confirm): alacritty-theme ✓ Removed alacritty-theme from "my-dotfiles" # List all your collections $ gitcollect list NAME HOST REPOS MEMBERS VISIBILITY my-dotfiles github.com 3 0 private side-projects github.com 7 0 private

Clone and pull updates Personal

Clone, pull, sync
# Clone all repos to ~/repos/ $ gitcollect clone my-dotfiles --dest ~/repos [1/3] Cloning neovim-config... [2/3] Cloning zsh-config... [3/3] Cloning tmux-config... ✓ Cloned 3 repos to ~/repos # Pull updates on every repo in the collection $ gitcollect pull my-dotfiles --dest ~/repos [1/3] Pulling neovim-config... ✓ up to date [2/3] Pulling zsh-config... ✓ updated (main → a3f91c2) [3/3] Pulling tmux-config... ✓ up to date ✓ Pulled 3 repos # Sync = clone missing + pull existing in one pass $ gitcollect sync my-dotfiles --dest ~/repos

Show and inspect Personal

Inspect the access matrix
# Full access matrix (more useful once you add members) $ gitcollect inspect my-dotfiles Collection: my-dotfiles Visibility: private Members: 0 No members or no repos to show in the access matrix. # Machine-readable output for any command $ gitcollect show my-dotfiles --json { "name": "my-dotfiles", "host": "github.com", "visibility": "private", "repos": [ {"name": "neovim-config", "groups": [], "users": []}, {"name": "zsh-config", "groups": [], "users": []}, {"name": "tmux-config", "groups": [], "users": []} ], "members": [] }

Create a team collection Org

Set --namespace to your GitHub org or GitLab group. gitcollect uses the namespace for all API calls and repo lookups — it does not have to match the collection name.

Personal
$ gitcollect init my-dotfiles ✓ Created "my-dotfiles" (private) Owner: jsmith Host: github.com
Org / Team
$ gitcollect init payments-team \ --namespace acme-corp \ --visibility private ✓ Created "payments-team" (private) Owner: jsmith Namespace: acme-corp Host: github.com
Add org repos (namespace is used automatically)
$ gitcollect add payments-team checkout-service payment-gateway fraud-detector ✓ Added acme-corp/checkout-service to "payments-team" ✓ Added acme-corp/payment-gateway to "payments-team" ✓ Added acme-corp/fraud-detector to "payments-team" $ gitcollect show payments-team Collection: payments-team Owner: jsmith Namespace: acme-corp Visibility: private Host: github.com Repos (3): checkout-service (open to all members) payment-gateway (open to all members) fraud-detector (open to all members) Members (0): No members yet. Run: gitcollect member add payments-team <username>

Members and groups Org

Members are platform users who can access repos. Groups are named subsets — use them to restrict specific repos to specific roles without giving everyone access to everything.

Add members, create groups, assign membership
# Add individual members (grants platform collaborator access to all repos) $ gitcollect member add payments-team alice bob carol ✓ Added alice to "payments-team" — granted access to 3 repos ✓ Added bob to "payments-team" — granted access to 3 repos ✓ Added carol to "payments-team" — granted access to 3 repos Note: GitHub will send them a collaborator invitation to accept. # List members $ gitcollect member list payments-team MEMBER GROUPS REPOS alice — 3 bob — 3 carol — 3 # Create groups and assign members $ gitcollect group add payments-team --name eng alice bob ✓ Created group "eng" in "payments-team" with 2 member(s) $ gitcollect group add payments-team --name security carol ✓ Created group "security" in "payments-team" with 1 member(s) # Remove a member — revokes all platform access $ gitcollect member remove payments-team bob ✓ Removed bob from "payments-team" — revoked access to 3 repos

gitcollect stores members by their immutable platform user ID, never by login. Renaming a GitHub or GitLab account never breaks membership — the cached login is kept alongside the ID for display only.

Repo access control Org

By default every member can reach every repo. Narrow that with per-repo rules: restrict to groups, specific users, or reopen to everyone.

Per-repo rules outrank visibility. A public collection opens its unrestricted repos to everyone, and leaves group- and user-restricted repos restricted. Marking a collection public is not a way to grant blanket access. Changed in v3.1.0 — earlier versions ignored per-repo rules entirely on public collections and sync pushed the resulting grants to the platform; run gitcollect diff after upgrading.

Restrict repos, then inspect the full matrix
# Restrict fraud-detector to security group only $ gitcollect repo access payments-team fraud-detector --groups security ✓ Updated access for fraud-detector Before: open to all members After: groups: security Run: gitcollect inspect payments-team --repo fraud-detector # Restrict payment-gateway to named individuals $ gitcollect repo access payments-team payment-gateway --users alice carol ✓ Updated access for payment-gateway Before: open to all members After: users: alice, carol # Re-open a restricted repo $ gitcollect repo access payments-team checkout-service --open ✓ Updated access for checkout-service (open to all members) # Full access matrix $ gitcollect inspect payments-team Collection: payments-team Visibility: private Members: 2 MEMBER checkout-service payment-gateway fraud-detector alice ✓ ✓ ✗ carol ✓ ✓ ✓ # Access breakdown for one user $ gitcollect inspect payments-team --user alice User: alice Collection: payments-team (private) Member: yes Groups: eng REPO ACCESS REASON checkout-service ✓ yes open to all members payment-gateway ✓ yes user: alice fraud-detector ✗ no restricted to group: security To fix: fraud-detector gitcollect repo access payments-team fraud-detector --groups security,eng # Who can reach a specific repo $ gitcollect inspect payments-team --repo fraud-detector Repo: fraud-detector Access: groups: security MEMBER ACCESS REASON alice ✗ no not in group: security carol ✓ yes group: security

Share collections and onboard new hires Org

The admin publishes a collection YAML to a shared config repo. New team members fetch it and clone their repos in a single command.

Admin publishes → new hire joins in one command
── Admin (on their machine) ───────────────────────────────────── $ gitcollect publish payments-team --repo acme-corp/gitcollect-config ✓ Published payments-team to acme-corp/gitcollect-config Committed to: collections/payments-team.yaml ── New hire (on their machine) ────────────────────────────────── # Fetch config + clone all accessible repos in one step $ gitcollect join \ --org acme-corp \ --team payments-team \ --repo acme-corp/gitcollect-config \ --clone --dest ~/dev ✓ Authenticated as dave (github.com) ✓ payments-team fetched (3 repos · 2 members) Written to ~/.gitcollect/collections/acme-corp-payments-team.yaml Cloning repos... [1/2] Cloning checkout-service... [2/2] Cloning payment-gateway... fraud-detector — no access (restricted to group: security) ✓ Joined acme-corp/payments-team — 2 repos cloned to ~/dev Welcome to the team. Next steps: gitcollect show acme-corp-payments-team see your full repo access gitcollect pull acme-corp-payments-team pull updates any time ── Alternative: pull-config without full join ──────────────────── $ gitcollect pull-config --repo acme-corp/gitcollect-config payments-team (new) frontend-team (new) ✓ Fetched 2 collection(s) # Overwrite if collections already exist locally $ gitcollect pull-config --repo acme-corp/gitcollect-config --overwrite payments-team (updated) frontend-team (updated) ✓ Fetched 2 collection(s)

Sync and publish Org

Keep collections current with the platform team state
# Refresh local collection from platform's current team membership $ gitcollect sync-config payments-team Syncing payments-team from github.com/acme-corp... Changes detected: + new member: dave (id: 1193847) - removed member: bob (no longer in platform team) + new repo: reporting-api Applying changes... ✓ payments-team synced Run: gitcollect sync payments-team to clone new repos and pull existing # Preview changes without applying $ gitcollect sync-config payments-team --dry-run Changes detected: + new repo: reporting-api [dry-run] No changes applied. # After sync-config, bring local checkouts up to date $ gitcollect sync payments-team --dest ~/dev [1/4] checkout-service → up to date [2/4] payment-gateway → updated (main → c2f914a) [3/4] fraud-detector → up to date [4/4] reporting-api → cloned (new) ✓ Synced 4 repos

Doctor — pre-flight health check All users

Check auth, token scopes, and stale collections
$ gitcollect doctor Checking gitcollect configuration... ✓ github.com auth Token valid (jsmith) ⚠ github.com scopes Missing read:org — team import will not work ⚠ payments-team Last updated 42 days ago — consider gitcollect sync-config ✓ my-dotfiles Last updated 2 days ago ✓ gitlab.com auth Token valid (jsmith) 2 warnings Fix: Add read:org scope to your GitHub token at github.com/settings/tokens Then run: gitcollect auth # Machine-readable output $ gitcollect doctor --json [ {"label":"github.com auth", "status":"ok", "message":"Token valid (jsmith)"}, {"label":"github.com scopes","status":"warn", "message":"Missing read:org", "fix":"gitcollect auth"}, {"label":"payments-team", "status":"warn", "message":"Last updated 42 days ago"} ]

Get-update — upgrade to the latest release All users

Compare against the latest release and install it
$ gitcollect get-update Checking for a newer gitcollect... ✓ Update available: v3.2.0 → 3.3.0 https://github.com/alby-tomy/gitcollect/releases/tag/v3.3.0 Install 3.3.0 now? [y/N]: y Downloading 3.3.0 for linux/amd64... ✓ Checksum verified ✓ Updated to 3.3.0 Replaced /usr/local/bin/gitcollect # Report only — changes nothing. Useful in a shell prompt or a script. $ gitcollect get-update --check # Skip the confirmation. $ gitcollect get-update --yes # Already current $ gitcollect get-update ✓ gitcollect v3.3.0 is the latest release

Requires v3.2.0 or newer. Earlier binaries do not carry this command. Check with gitcollect --version; if you are behind, upgrade once using the Method 1 or Method 2 commands on the install page, and get-update carries itself forward from then on.

The upgrade follows however gitcollect was installed:

  • Release binary — downloads the archive for your platform, verifies it against the published SHA-256 in checksums.txt, and replaces the binary in place. A download whose checksum does not match is refused, never installed.
  • go install — re-runs go install github.com/alby-tomy/gitcollect/v3@latest rather than overwriting the file, so the Go toolchain stays the source of truth for the binary it manages.
  • Built from source — refuses, and says so. A go build in a checkout reports a development version such as v3.0.2-0.20260914175157-eb4982ebc6d1+dirty; overwriting your own build with a published one would lose work.

Aliases: update, upgrade, self-update. If the binary lives somewhere unwritable (/usr/local/bin on most systems), get-update reports the permission error rather than half-replacing it — re-run with elevated privileges.

Verify — check repos still exist All users

Check reachability, optionally auto-remove broken entries
$ gitcollect verify payments-team ✓ checkout-service ok ✓ payment-gateway ok ⚠ fraud-detector archived ✗ reporting-api not found (deleted or renamed on platform) 1 repo not reachable Run: gitcollect verify payments-team --fix to remove broken entries # Auto-remove unreachable repos $ gitcollect verify payments-team --fix Removing reporting-api (not found)... ✓ payments-team updated (3 repos remaining) # Machine-readable $ gitcollect verify payments-team --json [ {"repo":"checkout-service","status":"ok", "message":""}, {"repo":"payment-gateway", "status":"ok", "message":""}, {"repo":"fraud-detector", "status":"archived", "message":""}, {"repo":"reporting-api", "status":"not_found","message":""} ]

Audit log Org

Every access-changing action is appended to ~/.gitcollect/audit/<collection>.log. Logs are local — export them with --json for off-machine backup.

View and export audit history
$ gitcollect audit payments-team TIME ACTOR ACTION TARGET RESULT 2026-07-01 09:12:04 jsmith init payments-team ok 2026-07-01 09:14:22 jsmith repo.add checkout-service ok 2026-07-01 09:15:01 jsmith member.add alice ok 2026-07-01 09:15:03 jsmith member.add bob ok 2026-07-02 11:03:42 jsmith repo.access.set fraud-detector ok 2026-07-05 14:22:10 jsmith member.remove bob ok # Filter by action type $ gitcollect audit payments-team --action member TIME ACTOR ACTION TARGET RESULT 2026-07-01 09:15:01 jsmith member.add alice ok 2026-07-01 09:15:03 jsmith member.add bob ok 2026-07-05 14:22:10 jsmith member.remove bob ok # Export for backup $ gitcollect audit payments-team --json > payments-team-audit.json

Export and import All users

Export, backup, and import from the platform
# Export a single collection as YAML (pure data — no colour, no ANSI) $ gitcollect export payments-team > payments-team-backup.yaml # Export as JSON $ gitcollect export payments-team --json > payments-team.json # Export all collections (YAML multi-document) $ gitcollect export --all > all-collections.yaml # Import a team directly from the GitHub/GitLab team API $ gitcollect import --org acme-corp --team payments-team ✓ Imported acme-corp/payments-team (3 repos, 4 members) Written to ~/.gitcollect/collections/acme-corp-payments-team.yaml # Import all teams in an org at once $ gitcollect import --org acme-corp --all-teams ✓ Imported acme-corp/payments-team (3 repos, 4 members) ✓ Imported acme-corp/platform-team (7 repos, 6 members) ✓ Imported acme-corp/frontend-team (5 repos, 3 members)

Discovery & dashboards All users

Four commands added in v3: find repos to collect, then see across them.

scan — group repos into collections by shared name
$ gitcollect scan --org acme-corp Scanning github.com/acme-corp... ✓ Found 9 repositories in github.com/acme-corp Groups discovered (3): payments 4 repos • payments-api • payments-gateway • payments-ledger • payments-webhooks auth 3 repos website 2 repos Use --apply to write collection files, or --dry-run to preview them. # Write one collection per discovered group $ gitcollect scan --org acme-corp --apply ✓ acme-corp-payments (4 repos) ✓ acme-corp-auth (3 repos) 1 collection already existed and was skipped. # A module split by region: the shared word is the category, not the prefix $ gitcollect scan --org acme-corp pricing 3 repos • china-pricing • eu-pricing • us-pricing # Your own account, private repos included $ gitcollect scan --user jsmith --interactive eu-pricing [pricing]: customer-tickets [pricing]: crm customer-tickets → crm old-spike [pricing]: d dropped old-spike

scan never overwrites. A collection that already exists is skipped, so re-running --apply cannot lose members, groups or per-repo access rules.

Choosing a grouping strategy. token (the default) buckets on the most widely shared meaningful word wherever it sits in the name, so china-pricing, eu-pricing and us-pricing form one pricing collection. A word must appear in at least two repos to name a group, and generic terms (service, api, core, …) are skipped so cart-service and search-service do not collapse into service. --group-by prefix uses only the first hyphenated segment — correct for a deliberate namespace like payments-gateway, but it splits regional variants of one module apart. --group-by flat puts everything in one collection.

Personal accounts. An org and a user are different API endpoints, so a personal account needs --user; --org with a username fails. Your own login includes private repos, someone else's returns only what your token can see.

Grouping by name is a guess. --interactive confirms each repo before anything is written — Enter accepts the suggested category, d drops the repo, and typing a name files it under that category instead. This is the check for an account holding several unrelated projects, where a repo can be matched to the wrong one.

pr — open pull requests across every repo you can reach
$ gitcollect pr payments-team REPO # TITLE AUTHOR UPDATED payments-gateway #214 Retry idempotency keys priya 2026-09-12 payments-api #87 Drop the legacy /v1 charge route sam 2026-09-11 payments-ledger #41 Backfill reconciliation job priya 2026-09-08 3 open PR(s) across 4 repo(s) # Filter by author (case-insensitive), or emit JSON $ gitcollect pr payments-team --author priya $ gitcollect pr payments-team --json
health — one dashboard for a whole collection
$ gitcollect health payments-team ✓ Access verified (priya · backend) 4 of 4 repos accessible REPO CLONED DIRTY BEHIND OPEN PRS payments-api yes 2 1 payments-gateway yes yes 1 payments-ledger yes 1 payments-webhooks no Summary for payments-team: Repos accessible : 4 / 4 Cloned locally : 3 / 4 Dirty (local changes): 1 Behind remote : 1 Open PRs/MRs : 3 Run: gitcollect sync payments-team # to clone missing repos

Unreadable repos are named, not counted as zero. If the platform refuses a repo — a 403, or a rate limit — pr and health say which repos they could not read and exclude them from the totals, rather than silently reporting no open PRs.

archive — retire a collection without deleting it
$ gitcollect archive legacy-billing ✓ Archived legacy-billing Pass --include-archived to list/sync/status to include it. # Hidden from the everyday views, still fully intact on disk $ gitcollect list --include-archived $ gitcollect unarchive legacy-billing ✓ Unarchived legacy-billing

Archive is not delete. The YAML file, its repos and every access rule stay exactly as they were — only the collection's visibility in list, sync --all and status --all changes. Only the collection owner can archive or unarchive.

All commands

Quick-reference table. See the full docs for every flag.

Command Scope Description
gitcollect authBothStore a platform token
gitcollect whoamiBothShow authenticated identities
gitcollect initBothCreate a new collection
gitcollect addBothAdd repos to a collection
gitcollect removeBothRemove a repo (revokes platform access)
gitcollect listBothList all local collections
gitcollect showBothShow a collection's contents
gitcollect inspectBothFull access matrix — who can reach what
gitcollect cloneBothClone all accessible repos
gitcollect pullBothPull updates in every local repo
gitcollect syncBothClone missing + pull existing
gitcollect member addOrgAdd a member and grant platform access
gitcollect member removeOrgRemove a member and revoke access
gitcollect member listOrgList members with group/repo breakdown
gitcollect group addOrgCreate a group or add members to it
gitcollect group removeOrgRemove a group or member from it
gitcollect repo accessOrgRestrict a repo to groups or users
gitcollect repo showOrgShow who can access a specific repo
gitcollect visibilityOrgChange collection visibility
gitcollect publishOrgPush collection YAML to a shared config repo
gitcollect pull-configOrgFetch collection files from a config repo
gitcollect joinOrgOne-command new-hire onboarding
gitcollect importOrgImport a team from the platform API
gitcollect sync-configOrgRefresh local collection from platform team state
gitcollect exportBothPrint collection(s) as YAML or JSON
gitcollect auditOrgView the local audit log
gitcollect verifyBothCheck repos are still reachable
gitcollect doctorBothHealth-check auth and collections
gitcollect get-updateBothUpgrade to the latest release
gitcollect --versionBothPrint the running version (also -v)
gitcollect deleteBothDelete a collection (revokes all access)
gitcollect conceptsBothExplain core concepts and mental model
gitcollect statusBothgit status across every cloned repo
gitcollect diffOrgCompare the manifest against platform reality
gitcollect findBothSearch local collections for a repo or member
gitcollect scanBothDiscover org or personal repos and group them into collections
gitcollect prBothOpen pull/merge requests across a collection
gitcollect healthBothCloned / dirty / behind / open-PR dashboard
gitcollect archiveBothHide a collection from list/sync/status (owner only)
gitcollect unarchiveBothRestore an archived collection (owner only)
gitcollect activityBothRecent commits across a collection (experimental)
gitcollect describeBothSet or clear a collection's description
gitcollect renameBothRename a collection
gitcollect copyBothCopy a collection to a new name
gitcollect moveBothMove a repo, or a whole module, between collections
gitcollect transferOrgTransfer ownership to another member
gitcollect scaleOrgSwitch between team and organisation tier
gitcollect completionBothShell completion for bash/zsh/fish/powershell
gitcollect versionBothPrint build version — also -v / --version

--offline: Pass to any command to disable all network calls. Commands that require the platform API return a clear error instead of attempting a connection.

Full flag reference: See index.html → Commands for every flag on every command.