# GitLab: credentials

Under Connections, category Git, you connect GitLab.com or a self-hosted instance via OAuth or a personal access token so MainPath can create or import groups and projects there.

> Source: https://www.mainpath.ai/en/docs/gitlab-credentials/

**GitLab** lives under **Connections** in the **Git** category. **Connect with GitLab** (OAuth against GitLab.com) is recommended. Otherwise store a **personal access token**; that also covers self-hosted instances.

On the project, choose **GitLab** at the bottom instead of **Automatically generated** when application repositories should live on GitLab.com (or your instance). Platform infrastructure files stay in MainPath GitLab group.

## OAuth (GitLab.com)

1. Open **Connections → GitLab → Connect with GitLab**.
2. Sign in and grant `api` so MainPath can manage projects, files, and CI variables.
3. After the callback the connection is available.

OAuth requires `GITLAB_OAUTH_CLIENT_ID` / `GITLAB_OAUTH_CLIENT_SECRET` on the backend. If the app is missing, use a token.

## Personal access token

1. In GitLab, under **Preferences → Access Tokens** (or **Group → Access Tokens**), create a token with `api`.
2. Open **Connections → GitLab → Add API token**.
3. Enter **Name**, **Slug**, token, **GitLab URL** (`https://gitlab.com` or your instance), and optionally the **group path**.

## Pipelines on GitLab.com

MainPath writes `.gitlab-ci.yml` that includes the public pipeline library `doppelt-digital/app-project-pipelines` plus `templates-common/hosted-runner.yml`. Jobs run on GitLab-hosted Linux and macOS runners (`saas-linux-large-amd64`, `saas-macos-large-m2pro`) with ASDF instead of Tart.

