A GitLab connection lets workflows open and update issues, add notes, create and accept merge requests, commit files, create releases and run pipelines — and start a run when something happens in a project. It works with gitlab.com or a GitLab of your own on the internet, and connects with an access token you make in GitLab.

Who can do this

  • In Bizomate: workspace Admins and Editors, on every plan — GitLab is not a premium connection. Viewers see the connection but cannot add or change it.
  • In GitLab: anyone can make a personal access token for their own account. A project access token is made by a project Maintainer or Owner.
  • GitLab triggers add a webhook to the project, which needs the token's user — or the project token's role — to be Maintainer or Owner of the project.

Before you start

Decide which kind of token to make:

  • Personal access token — acts as you, in every project you are a member of.
  • Project access token — acts as a bot user in one project only. Choose its role when you make it: Developer for the steps, Maintainer if the project will also have GitLab triggers. On gitlab.com, project access tokens need a paid GitLab plan.

Either way, give it the api scope. Every GitLab step and trigger uses it; read_api lets the test pass but every change fails.

What the token's user or role must be allowed to do in the project:

Steps Role needed in the project
Create an issue, Update an issue, Add a note Reporter or above
Create a merge request, Create or update a file, Create a release, Run a pipeline Developer or above — Maintainer to commit to a protected branch
Accept a merge request Whoever may merge into the target branch — Developer, or Maintainer for a protected branch
Every GitLab trigger Maintainer or Owner

Steps

In GitLab, make a personal access token:

  1. Sign in to GitLab. Select your avatar, then Edit profile (on some versions, Preferences).
  2. In the menu on the left, select Access tokens, then Add new token.
  3. In Token name, type Bizomate.
  4. In Expiration date, choose a date, and note it — Bizomate can remind you before it. GitLab may require one; see Good to know.
  5. Under Select scopes, tick api.
  6. Select Create personal access token. Copy the token — it starts glpat-. GitLab shows it only once.

Or a project access token:

  1. Open the project — for example consulace/billing-service.
  2. Select Settings, then Access tokens, then Add new token.
  3. Type a name, choose an expiration date, choose the role, and tick api.
  4. Select Create project access token, and copy it.

In Bizomate, add the connection:

  1. Select Connections in the bar at the top, then + Add connection.
  2. Under Developer Tools, select GitLab. It reads "Stored credential".
  3. In Connection name, type a name — for example Consulace GitLab.
  4. In GitLab address (optional), leave it empty for gitlab.com. For a GitLab of your own, type its address — for example https://gitlab.consulace.com. Empty for gitlab.com. For your own GitLab, its https address — one on a private network cannot be reached from Bizomate.
  5. Paste the token in Access token — placeholder glpat-…. It is hidden as you type.
  6. Optional: in This token expires on · optional, choose the token's expiry date — If the service gave the token an end date. The workspace’s admins are reminded 30, 7 and 1 days before.
  7. Leave Test the connection before saving ticked. Bizomate asks GitLab who the token belongs to before keeping it.
  8. Select Save connection. The button reads Testing, then the dialog closes.

The toast "Connection added" says "“Consulace GitLab” is ready. Every workflow in this workspace can use it."

What happens next

  • Test in the connection's panel answers with the token's user and the GitLab it reached — for example "Reached @rohan.mehta · gitlab.com". A project access token answers with its bot user.
  • GitLab steps and triggers list it under Connection. Their Project list shows the projects the token is a member of, as group/name — consulace/billing-service — most recently active first.

Good to know

  • The address must be https. An address typed without https:// has it added. An http address is refused.
  • A GitLab on a private network cannot be reached — one inside your office network, or on an address such as 10.0.0.5. Bizomate calls GitLab over the internet, as HTTP Request does.
  • For triggers, your GitLab must be able to reach Bizomate over the internet, because GitLab sends each event to Bizomate.
  • The Project list shows up to 100 projects. For another, select Use a value above the list and type its path — consulace/billing-service.
  • Tokens end. GitLab tokens have an expiry date. After it, every GitLab step fails with "401 Unauthorized". With the date in This token expires on, the connection turns amber 30 days before, the workspace's admins are reminded 30, 7 and 1 days before, and its panel offers Replace token. Make a new token before then and replace it as below.
  • To replace the token, open the connection's panel and select Replace token, fill in the fields again and select Replace token. The old one is used until then, so no workflow fails in between. With Test the connection before saving ticked, nothing changes if GitLab refuses it. Once a date you entered has passed, the button reads Reconnect instead. The toast says "Token replaced".

If something goes wrong

What you see Why What to do
"Fill in Access token." Access token is empty. Paste the token.
GitLab refused it — "GitLab refused: 401 Unauthorized. Check the connection's details on Connections. Nothing was saved." The token was mistyped, has ended or was revoked — or it was made on another GitLab than the address. Copy the token again, or make a new one. Check GitLab address.
GitLab refused it — "GitLab address “http://gitlab.consulace.com” is not an https address. Nothing was saved." The address starts http://. Use the https:// address.
GitLab refused it — "Could not reach GitLab: gitlab.consulace.internal is not on the public internet, so workflows cannot call it. Nothing was saved." The GitLab is on a private network. Bizomate can only use a GitLab reachable from the internet.
"GitLab refused: insufficient_scope. Check the connection's details on Connections." (in a run) The token has read_api or another scope, not api. Make a token with api and replace it.
"GitLab refused: 403 Forbidden. Check the connection's details on Connections." (in a run) The token's user or role is not allowed to do this in the project. Give the user a higher role in the project — see the table above.
Nothing to pick — "The token reaches no project. Make it with the api scope, as a member of the projects its steps use, then Refresh." The token's user is in no project. Add the user to the project, then select Refresh.
"Could not reach GitLab: …" or "GitLab did not answer within 30 seconds." GitLab could not be reached. Try again in a few minutes.