Skip to main content

Overview

OneCLI connects AI agents to GitLab through OAuth. Agents can read projects, open and update issues and merge requests, comment, and manage branches. The gateway injects the token into every request, so your agent never sees it. GitLab uses your own GitLab OAuth application, on OneCLI Cloud and self-hosted alike. Setup takes about five minutes, once.

Connect GitLab

1

Create a GitLab OAuth application

In GitLab, open User settings > Applications and click Add new application. Name it OneCLI, and select the scopes api, read_user, read_repository, write_repository, and read_registry.
2

Add the redirect URI

In OneCLI, open Connections > GitLab > Custom credentials and copy the Redirect URI. Paste it into the GitLab application’s Redirect URI and save the application.
3

Add your credentials and connect

Copy the GitLab Application ID and Secret into Custom credentials, click Save credentials, then click Connect GitLab and Authorize in GitLab.
OneCLI connect window for GitLab showing Configuration required, the setup guide link, and the Configure credentials button.

The GitLab connect window in OneCLI before credentials are added.

What agents can do

Controlling access

Grant the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what’s blocked. Put Merge merge request and Delete branch behind approval. Organization rules add guardrails on top. A blocked request never reaches GitLab. To disconnect, remove the connection in Connections > GitLab, then revoke OneCLI in GitLab under User settings > Applications.