> ## Documentation Index
> Fetch the complete documentation index at: https://evalgate.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Activate a connected repository

> Updates the exact-commit activation snapshot for an already durable organization/repository/root association and queues repository intelligence without minting or changing credentials. requestedRef is a symbolic branch; targetSha is the exact commit. Behind targets may activate when GitHub proves reachability. Reuse the same idempotencyKey for retries.



## OpenAPI

````yaml /api-reference/openapi.json post /api/onboarding/activation
openapi: 3.1.2
info:
  title: EvalGate API
  version: 5.1.0
  description: EvalGate API. See docs/api-contract.md for stability commitments.
servers:
  - url: https://evalgate.com
    description: Production
  - url: http://localhost:3000
    description: Local
security: []
paths:
  /api/onboarding/activation:
    post:
      tags:
        - onboarding
      summary: Activate a connected repository
      description: >-
        Updates the exact-commit activation snapshot for an already durable
        organization/repository/root association and queues repository
        intelligence without minting or changing credentials. requestedRef is a
        symbolic branch; targetSha is the exact commit. Behind targets may
        activate when GitHub proves reachability. Reuse the same idempotencyKey
        for retries.
      operationId: activateRepository
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/PostApiOnboardingActivationRequest'
      responses:
        '202':
          description: Successful response
          content:
            application/json:
              schema:
                $ref: >-
                  #/components/schemas/PostApiOnboardingActivationResponse202ApplicationJson
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '409':
          $ref: '#/components/responses/Conflict'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
        '503':
          $ref: '#/components/responses/ServiceUnavailable'
      security:
        - bearerAuth: []
components:
  schemas:
    PostApiOnboardingActivationRequest:
      type: object
      properties:
        repositoryId:
          type: number
        idempotencyKey:
          type: string
        requestedRef:
          type: string
        targetSha:
          type: string
        intakeManifestHash:
          type: string
        rootPath:
          type: string
        harnessPresetKey:
          type: string
        startScan:
          oneOf:
            - type: boolean
              enum:
                - false
            - type: boolean
              enum:
                - true
        confirmPrivileged:
          oneOf:
            - type: boolean
              enum:
                - false
            - type: boolean
              enum:
                - true
      additionalProperties: false
      required:
        - repositoryId
        - idempotencyKey
        - requestedRef
        - targetSha
        - intakeManifestHash
    PostApiOnboardingActivationResponse202ApplicationJson:
      type: object
      properties:
        repository:
          type: object
          properties:
            id:
              type: number
            fullName:
              type: string
            defaultBranch:
              type: string
            owner:
              type: string
            name:
              type: string
          additionalProperties: false
          required:
            - id
            - fullName
            - defaultBranch
            - owner
            - name
        activationRun:
          type: object
          properties:
            id:
              type: string
            lifecycle:
              oneOf:
                - type: string
                  enum:
                    - approved
                - type: string
                  enum:
                    - failed
                - type: string
                  enum:
                    - queued
                - type: string
                  enum:
                    - completed
                - type: string
                  enum:
                    - running
                - type: string
                  enum:
                    - stale
                - type: string
                  enum:
                    - partial
            progress:
              type: object
              properties:
                stage:
                  type: string
                completed:
                  oneOf:
                    - type: 'null'
                    - type: number
                total:
                  oneOf:
                    - type: 'null'
                    - type: number
                findings:
                  oneOf:
                    - type: 'null'
                    - type: number
              additionalProperties: false
              required:
                - stage
                - completed
                - total
                - findings
            failure:
              oneOf:
                - type: 'null'
                - type: object
                  properties:
                    code:
                      type: string
                    message:
                      type: string
                    retryable:
                      type: boolean
                  additionalProperties: false
                  required:
                    - message
                    - retryable
            identity:
              type: object
              properties:
                repositoryId:
                  type: number
                requestedRef:
                  type: string
                targetSha:
                  type: string
                rootPath:
                  type: string
                harnessPresetKey:
                  oneOf:
                    - type: 'null'
                    - type: string
                manifestHash:
                  type: string
              additionalProperties: false
              required:
                - repositoryId
                - requestedRef
                - targetSha
                - rootPath
                - harnessPresetKey
                - manifestHash
            observation:
              type: object
              properties:
                remoteHeadSha:
                  oneOf:
                    - type: 'null'
                    - type: string
                relation:
                  oneOf:
                    - type: 'null'
                    - type: string
                aheadBy:
                  oneOf:
                    - type: 'null'
                    - type: number
                behindBy:
                  oneOf:
                    - type: 'null'
                    - type: number
                observedAt:
                  oneOf:
                    - type: 'null'
                    - type: string
              additionalProperties: false
              required:
                - remoteHeadSha
                - relation
                - aheadBy
                - behindBy
                - observedAt
            result:
              oneOf:
                - type: 'null'
                - type: object
                  properties:
                    kind:
                      oneOf:
                        - type: 'null'
                        - type: string
                          enum:
                            - 'null'
                        - type: string
                          enum:
                            - baseline_ready
                        - type: string
                          enum:
                            - no_opportunities
                        - type: string
                          enum:
                            - partial_evidence
                    opportunityCount:
                      oneOf:
                        - type: 'null'
                        - type: number
                    checksPlanned:
                      oneOf:
                        - type: 'null'
                        - type: number
                  additionalProperties: false
                  required:
                    - kind
                    - opportunityCount
                    - checksPlanned
            report:
              oneOf:
                - type: 'null'
                - type: object
                  properties:
                    href:
                      type: string
                  additionalProperties: false
                  required:
                    - href
            createdAt:
              type: string
            updatedAt:
              type: string
          additionalProperties: false
          required:
            - id
            - lifecycle
            - progress
            - failure
            - identity
            - observation
            - result
            - report
            - createdAt
            - updatedAt
        installCommands:
          type: array
          items:
            type: string
      additionalProperties: false
      required:
        - repository
        - activationRun
        - installCommands
    ApiError:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - UNAUTHORIZED
                - FORBIDDEN
                - NOT_FOUND
                - INVALID_REFERENCE
                - VALIDATION_ERROR
                - RATE_LIMITED
                - CONFLICT
                - INTERNAL_ERROR
                - SERVICE_UNAVAILABLE
                - QUOTA_EXCEEDED
                - FEATURE_LIMIT_REACHED
                - NO_ORG_MEMBERSHIP
                - SHARE_REVOKED
                - SHARE_EXPIRED
                - SHARE_UNAVAILABLE
                - PROVIDER_KEY_MISSING
                - PROVIDER_KEY_EXPIRED
                - PROVIDER_RATE_LIMITED
                - PROVIDER_UNAUTHORIZED
                - PROVIDER_UNAVAILABLE
                - AGENT_HANDOFF_INVALID
                - AGENT_HANDOFF_EXPIRED
                - AGENT_HANDOFF_DENIED
                - AGENT_HANDOFF_CONSUMED
                - PAYLOAD_TOO_LARGE
                - METHOD_NOT_ALLOWED
            message:
              type: string
            details: {}
            requestId:
              type: string
              format: uuid
            redaction:
              type: object
              properties:
                applied:
                  type: boolean
                  enum:
                    - true
                fieldCount:
                  type: integer
                  minimum: 0
                secretCount:
                  type: integer
                  minimum: 0
              required:
                - applied
                - fieldCount
                - secretCount
          required:
            - code
            - message
      required:
        - error
  responses:
    ValidationError:
      description: Validation error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Unauthorized:
      description: Unauthorized
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
      headers:
        WWW-Authenticate:
          description: >-
            Bearer challenge. Agent-facing routes include the RFC 9728
            resource_metadata URL.
          schema:
            type: string
    Forbidden:
      description: Forbidden
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    NotFound:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    Conflict:
      description: Conflict
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    RateLimited:
      description: Rate limit exceeded
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
      headers:
        Retry-After:
          description: Delay in seconds before retrying when present.
          schema:
            type: integer
            minimum: 1
        RateLimit-Policy:
          description: IETF HTTPAPI structured quota policy (work in progress).
          schema:
            type: string
        RateLimit:
          description: >-
            IETF HTTPAPI structured remaining quota and reset delay (work in
            progress).
          schema:
            type: string
    InternalError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
    ServiceUnavailable:
      description: Service unavailable
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ApiError'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: EvalGate API key
      description: >-
        Organization-scoped EvalGate API key. Discover the supported agent
        scopes at /.well-known/oauth-protected-resource. Per-operation grants
        are listed in x-evalgate-required-scopes; OpenAPI bearer security
        requirement arrays remain empty as required for non-OAuth schemes.
      x-evalgate-scopes-supported:
        - eval:read
        - eval:write
        - objectives:read
        - objectives:write
        - runs:read
        - runs:write
        - traces:read
        - traces:write
        - exports:download
        - reports:write
        - prompt:publish
        - scorer:publish
        - red_team:read
        - red_team:run
        - red_team:approve
        - docs:read
        - agent:read
        - agent:execute
        - admin:keys
        - admin:org
      x-evalgate-protected-resource-metadata: https://www.evalgate.com/.well-known/oauth-protected-resource

````