> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# List the repositories this organisation selected on GitHub

> The repositories this organisation's installation of the Narya GitHub App carries, which is the set a person may name when creating an environment. **Served straight from GitHub on every request**, never from a copy narya keeps: the set is the customer's to change on GitHub at any moment, and a cache would drift from what they selected the instant they changed it.

An organisation that has connected no GitHub is answered with an **empty page carrying a notice** naming the gesture that connects one, rather than an error or a bare empty list — having connected nothing is a state with a remedy, not a failure. Every other cause fails closed: a host that cannot read what its organisation applies, and a GitHub that refuses, are both refusals naming what could not be done.



## OpenAPI

````yaml /es/openapi/v3-current/narya.yaml get /v1/github/repositories
openapi: 3.1.0
info:
  title: Narya Host API
  version: 1.0.0
  description: >-
    The contract between the Narya host and every client. One long-lived host
    serves this API over a Unix socket in your Narya home. The terminal client
    and the one-shot command that Lerian ships drive this API, and a client you
    write drives the same one.


    Requests authenticate with a bearer token issued by the identity provider
    the host is configured with. An operation that declares another security
    scheme also accepts that credential. A request without a valid credential
    gets 401 with NRY-0011. A caller whose role lacks the permission an
    operation needs gets 403 with NRY-0028.


    Submitting a message returns 202 with a turn id. Everything the turn
    produces streams over GET /v1/events as server-sent events with a typed
    envelope, and a stream resumes from a Last-Event-ID header.


    One error envelope: code, title and message. Codes are NRY- followed by four
    digits. Cursors are opaque.
servers: []
security:
  - bearerAuth: []
tags:
  - name: host
    description: The host process itself — version, uptime, mode, store.
  - name: sessions
    description: Durable conversation containers. Archive, never destroy.
  - name: messages
    description: Submitting work into a session and interrupting it.
  - name: events
    description: The server-sent event stream every client consumes.
  - name: lanes
    description: Parallel tracks inside a session — main, subagent, side.
  - name: agents
    description: Named recipes — instructions, tools, model, policy. Read-only in v1.
  - name: ladder
    description: >-
      What a person can type: the skills and command files in force for one
      repository, and expanding one into text. Five origins merged, nearest
      winning a name, the repository's own rungs gated on trust.
  - name: permissions
    description: Pending permission asks, decisions, and the decision audit.
  - name: intercom
    description: Sessions on one machine finding and messaging each other.
  - name: packages
    description: The one thing a user installs — resources, Go code, or both.
  - name: extensions
    description: >-
      Host-side extensions and the operations each exposes over the wire. This
      is the generic lane a host extension uses to serve its own client half (a
      TUI component, a web panel) or any API-only consumer, without adding
      routes to this contract.
  - name: workflows
    description: Deterministic multi-agent orchestration runs.
  - name: providers
    description: Model suppliers, their auth state, and the model catalogue.
  - name: monitors
    description: >-
      Long-running watchers a session keeps beside its conversation — a test
      runner in watch mode, a build, a log being followed. Started by the model
      or by the person, always listed, always killable.
  - name: records
    description: The queryable local record of everything that happened.
  - name: environments
    description: >-
      Where a session's code lives and its commands run — this machine, or a
      container narya operates. A session that names none runs here.
  - name: schedules
    description: >-
      Work the host's own clock starts with nobody present — a repository, a
      prompt, a rule and what one fire may spend. Cancel, never destroy.
  - name: sharing
    description: >-
      Publishing a session from a developer's own home to the organisation's,
      and what is held back before a byte leaves the machine.
  - name: refinements
    description: >-
      What this owner has taught narya and allowed it to keep — distilled facts,
      and the skills, agents and commands the model wrote for itself. Propose,
      read, consent, roll back. Nothing here fires until a person answers.
  - name: platform
    description: >-
      Calls Lerian's control plane made to a home it hosts, as this home
      recorded them.
paths:
  /v1/github/repositories:
    get:
      tags:
        - environments
      summary: List the repositories this organisation selected on GitHub
      description: >-
        The repositories this organisation's installation of the Narya GitHub
        App carries, which is the set a person may name when creating an
        environment. **Served straight from GitHub on every request**, never
        from a copy narya keeps: the set is the customer's to change on GitHub
        at any moment, and a cache would drift from what they selected the
        instant they changed it.


        An organisation that has connected no GitHub is answered with an **empty
        page carrying a notice** naming the gesture that connects one, rather
        than an error or a bare empty list — having connected nothing is a state
        with a remedy, not a failure. Every other cause fails closed: a host
        that cannot read what its organisation applies, and a GitHub that
        refuses, are both refusals naming what could not be done.
      operationId: listGitHubRepositories
      parameters:
        - $ref: '#/components/parameters/CursorParam'
        - $ref: '#/components/parameters/LimitParam'
      responses:
        '200':
          description: >-
            One page of the repositories this organisation's installation
            carries, in GitHub's own order.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GitHubRepositoryPage'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '500':
          $ref: '#/components/responses/InternalServerError'
components:
  parameters:
    CursorParam:
      name: cursor
      in: query
      required: false
      description: >-
        Opaque pagination cursor from a previous page's nextCursor or
        prevCursor.
      schema:
        type: string
        maxLength: 1024
    LimitParam:
      name: limit
      in: query
      required: false
      description: Maximum items per page.
      schema:
        type: integer
        minimum: 1
        maximum: 100
        default: 25
  schemas:
    GitHubRepositoryPage:
      type: object
      description: >-
        One page of the repositories this organisation's GitHub installation
        carries, plus whatever standing fact a person needs to read beside them.
      required:
        - items
        - limit
      properties:
        items:
          type: array
          items:
            $ref: '#/components/schemas/GitHubRepository'
        limit:
          type: integer
          minimum: 1
        nextCursor:
          type: string
        notices:
          type: array
          description: >-
            Standing facts about this listing in the words a person reads — the
            sentence that says this organisation has connected no GitHub at all
            and names the gesture that connects one. Scoped to this listing, the
            way SkillPage.notices is scoped to that one, and repeated on every
            request because they are conditions rather than events.
          items:
            type: string
      examples:
        - items:
            - fullName: acme/ledger
              cloneUrl: https://github.com/acme/ledger.git
              private: true
              defaultBranch: main
          limit: 25
    GitHubRepository:
      type: object
      description: >-
        One repository the customer selected on GitHub when they installed the
        Narya GitHub App. Every field is GitHub's own answer rather than
        anything narya assembled: a repository that moved, was renamed, or lives
        on an enterprise host is still clonable from what it reports.
      required:
        - fullName
        - cloneUrl
      properties:
        fullName:
          type: string
          maxLength: 512
          description: >-
            `owner/name`, which is how a person names a repository and how
            createEnvironment carries one.
        cloneUrl:
          type: string
          maxLength: 2048
          description: GitHub's own URL for cloning it.
        private:
          type: boolean
          description: >-
            Whether GitHub calls it private. Carried because a person picking
            one repository out of forty recognises their own by it, and because
            a public and a private fork of one name would otherwise be two
            identical rows to pick the wrong one from.
        defaultBranch:
          type: string
          maxLength: 255
          description: >-
            The branch a clone lands on, as GitHub reports it. Never assumed to
            be `main`, which is wrong on every repository older than 2020 and on
            every one whose owner renamed it.
      examples:
        - fullName: acme/ledger
          cloneUrl: https://github.com/acme/ledger.git
          private: true
          defaultBranch: main
    Error:
      type: object
      description: >-
        The single error envelope every operation returns. Codes are NRY-
        followed by four digits and are catalogued in the top-level
        x-error-catalog extension.
      required:
        - code
        - title
        - message
      properties:
        code:
          type: string
          pattern: ^NRY-[0-9]{4}$
          description: Machine-readable error code from the NRY catalogue.
        title:
          type: string
          maxLength: 256
          description: Short human-readable summary of the error class.
        message:
          type: string
          maxLength: 4096
          description: Specific, actionable description of what went wrong.
        fields:
          type: object
          description: Per-field validation problems.
          additionalProperties:
            type: string
      examples:
        - code: NRY-0002
          title: Session not found
          message: >-
            No session with id 6b9f6d2e-1c3a-4f5b-9d7e-2a8c4e6f0b1d exists on
            this host.
  responses:
    BadRequest:
      description: Malformed request — invalid parameter, cursor, or JSON body.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    Unauthorized:
      description: >-
        Authentication required — a request carrying no valid identity token
        (NRY-0011).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
    InternalServerError:
      description: The host failed — including a store that refuses writes (NRY-0012).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Enforced on every transport, with no exempt operation. A person's
        request — over the default local unix socket exactly as over a TCP
        listener — must carry a JWT issued by the configured identity provider,
        which the host verifies itself against that issuer's key set: signature,
        issuer, expiry, and the person and organisation it names. Requests
        without a valid one receive 401 NRY-0011. The socket's file permissions
        are transport and are not an authorisation.

````