> For the complete documentation index, see [llms.txt](https://docs.hivel.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hivel.ai/integrations/version-control/gitlab/gitlab-server-integration/gitlab-server-fine-grained-token.md).

# GitLab Server - Fine-grained token

**Data Access by Hivel**

* Hivel accesses the past 60-90 days of commits and pull requests from active repositories during the initial sync.

**Authorization Mechanism**

* Hivel employs GitLab Server's **personal access token** for authentication.
* Users maintain full control and can withdraw access by revoking the Personal Access Token.

**Effortlessly Connect Your GitLab Server with Hivel**

This easy-to-follow guide will lead you through each step, ensuring a smooth and efficient integration process to unlock efficiency insights across your org.&#x20;

### **Step 1: Gather Your GitLab Server Details**

First things first, let's get some essential information from your GitLab Server:

* **GitLab Server URL**: This is your gateway to accessing your GitLab Server. Look for an address in the format of `https://{your-git-domain}.com/`. Don't forget to replace `{your-git-domain}` with your actual domain.
* **GitLab Server Version**: Compatibility is key, and knowing your GitLab Server version is crucial. Here's how to find it:
  * Head over to your GitLab Server interface.
  * Click on the 'Help' section. It’s usually at the end of your GitLab URL, like this: `/help`.
  * You'll see your version info displayed, typically in the format of "GitLab Community Edition {x.x.x} / GitLab Enterprise Edition {x.x.x}".

### **Step 2: Whitelist Necessary IP Addresses**

For a secure and uninterrupted connection, make sure to whitelist the following IP addresses:

* **Mandatory IPs**:
  * 107.23.139.76
  * 3.219.89.23
* **Recommended but Optional IPs**:
  * 45.119.114.218
  * 183.82.116.218

### **Step 3: Prepare a Service Account**

1. **Log into the GitLab service account:**
   * Use a dedicated service account that has access to the required repositories for Hivel integration.
   * Avoid using personal GitLab accounts to ensure only the intended repositories are accessed.

### **Step 4: Open Access Tokens**

1. In your GitLab account, click your **avatar** in the top-right corner.
2. Select **Preferences**.

<img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FaS6JoPBQiJHc2RLlrLaw%2Funknown.png?alt=media&amp;token=eeb60074-62da-4fc0-957a-84a4735382c8" alt="" height="391" width="277">

1. On the left sidebar, select **Access > Personal access tokens**.

   <img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2F0wTvRn9CnpM8ZCDj04E9%2Funknown.png?alt=media&amp;token=12e40729-74e6-4de2-ba44-b427627cdedc" alt="" height="531" width="693">

### **Step 5: Click on the Generate token dropdown and select Fine-grained token.**

<img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FPTfNyP5OK2T2PibgGIpz%2Funknown.png?alt=media&amp;token=858adafb-25e4-47a2-99a0-6c1f7b204536" alt="" height="403" width="652">

### **Step 6: Configure the Fine-Grained Personal Access Token**

1. Enter a name (*e.g. Hivel*), description and set the **longest expiry date your organization's policy allows**. (GitLab requires an expiry date on personal access tokens. You can revoke the token manually when the engagement ends.)
2. Under **Group and project access**, choose between the following three options, based on what you've agreed to share with Hivel per your organization's data-sharing policy:

<div data-with-frame="true"><img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FDoJOyZBHr6bIw755jgOk%2Funknown.png?alt=media&amp;token=44f3547f-086f-4372-b8a6-1543014eb702" alt="" height="235" width="452"></div>

3. Grant permissions using the **Resource and permission selector**. It has three tabs: **Group and project, User, and Global**. Within a tab, the left panel lists resource categories (e.g. **Projects, Repository, Groups**). Each category row has a ‘›’  arrow - click it to expand the category and reveal its specific sub-permissions as checkboxes underneath. Checking one adds a row for it to the panel on the right.

**None of these rows default to Read.** After adding a permission, you must open its dropdown on the right-hand table and explicitly set it to **Read**.

**Worked example - selecting Project (Group and project tab):**

1. On the **Group and project tab**, find **Projects** in the left panel.
2. Click the ‘**›**’ arrow next to **Projects** to expand it.

   <img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FlziNnfD2DAAaxe3dkV1s%2Funknown.png?alt=media&amp;token=3c23d29a-5f40-49ec-af1e-da6885392cb0" alt="" height="374" width="625">
3. Check **Project** in the list that appears.

<img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FSfCzpAkpjSACXfgT8Hyt%2Funknown.png?alt=media&amp;token=4d08e7b8-ca53-4b46-821f-da08562f9584" alt="" height="273" width="558">

4. A **Project** row is added to the panel on the right. Open its dropdown in the right panel and set the “Select permissions” to **Read**.

<div data-with-frame="true"><img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2F8Bs3Nm2tQ9kQw4zrBuQT%2Funknown.png?alt=media&amp;token=fc7c12bc-aeb6-40c6-9d1a-181d9283b316" alt=""></div>

<img src="https://3057781534-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F5KAIOUWph0JLSgQqbzyT%2Fuploads%2FDvjqZsX5AqCjEavITqTt%2Funknown.png?alt=media&amp;token=5a7e5682-6aef-4fff-8dad-1d5932330093" alt="" height="429" width="711">

Repeat this same expand → check → set-to-Read pattern for every permission below. Where a category needs more than one sub-permission (e.g. Repository), expand it once and check all of them before moving to the next category.

**Group and project tab:**

* **Groups** → check **Group**
* **Projects** → check **Project**
* **Project Planning** → check **Work Item**
* **Repository** → check **Branch, Commit, Merge Request, Repository**
* **System Access** → check **Member**

**User tab:**

* **Groups** → check **Group**
* **Projects** → check **Project**
* **System Access** → check **Personal Access Token**

**Global tab:**

* **System Access** → check Metadata&#x20;

**Note:** By default, **no permission is selected at all**. Before moving on, go back through every item in the three lists above and cross-check two things for each: (1) it's actually checked in the left panel, and (2) its row on the right is explicitly set to **Read**. Any permission you skip, or leave unset, is simply left out of the token entirely - the connection may still work, but whatever that permission covers will be missing or fail for Hivel.

Once every permission above has been cross-checked and set to **Read**, continue to the next step.

### **Step 7: Connect in Hivel**

1. **Copy the generated token** immediately, as you won't be able to view it again.
2. **Submit:**\
   a. GitLab token\
   b. Email\
   c. base URL<br>

   <div data-gb-custom-block data-tag="hint" data-style="warning" class="hint hint-warning"><p><strong>Obtaining base URL:</strong></p><p>Open your <strong>GitLab dashboard</strong> or any project page and copy <strong>only the base URL</strong> from your browser’s address bar, excluding the project name and anything that follows it (e.g., <code>https://company.com</code>). For detailed instructions, <a href="/integrations/version-control/gitlab/gitlab-server-integration/how-to-find-your-gitlab-server-url.md">How to Find Your GitLab Server URL?</a></p></div>

   \
   d. username to Hivel.

Hivel validates the token instantly - if the token is wrong, expired, or missing any of the required permissions, Hivel shows a clear message telling you exactly what the problem is. Generate a new token with the correct permissions and reconnect.

That's it, all done!

***

**Continue setting up your integrations**

Now that GitLab Server is connected, connect the rest of your on-prem tools to complete your setup - [Back to Integrations](https://docs.hivel.ai/integrations#on-prem-server-integrations).
