Skip to content

How it works

From repository files to useful answers.

RepoMind combines code retrieval, repository relationships, and AI reasoning to help developers navigate unfamiliar software.

Repository connections are in development. This page describes how they are designed to work.

01

Connect and index.

  • Access repository files with the permissions you grant, and nothing more.
  • Exclude generated, vendored and sensitive-looking files.
  • Extract file contents and metadata.
  • Identify symbols and the references between them.
  • Build searchable representations of each file and its relationships.

Indexing pipeline (illustrative)

02

Retrieve relevant context.

Your question is matched against code, symbols and the reference graph. Instead of sending a whole repository to a model, RepoMind selects the few files and line ranges that matter, plus the files directly connected to them.

ask › Where is authentication handled?
session.tscart/route.tscheckout/route.ts

6 of 98 files selected as context

03

Generate a grounded explanation.

The model receives the selected code with paths and line numbers and is asked to cite what it relies on. Answers separate direct evidence, which you can see in the cited lines, from inference, which goes beyond them. Select any citation to open the lines it points to.

Explanation

Where is authentication handled?

Authentication lives in lib/auth/session.ts. getSession reads the session cookie and verifies it; requireUser wraps it and throws a 401 response. Only the cart and checkout handlers call requireUser, so product pages are public.

  1. getSession reads the session cookie and verifies the token.
  2. requireUser throws Response(401) when no session exists.
  3. Calls requireUser() before touching the cart.
  4. Calls requireUser() before creating a payment intent.

Direct evidence

Inference

lib/auth/session.ts

import { cookies } from "next/headers";
import { verifySessionToken } from "./tokens";
export type SessionUser = { id: string; email: string; discountRate: number };
export async function getSession(): Promise<{ user: SessionUser } | null> {
const token = (await cookies()).get("session")?.value;
if (!token) return null;
return verifySessionToken(token);
}
export async function requireUser(): Promise<SessionUser> {
const session = await getSession();
if (!session) {
throw new Response("Unauthorized", { status: 401 });
}
return session.user;
}

04

Explore and refine.

Investigations are rarely one question. Ask a follow-up, open a referenced file, inspect the functions it calls, and narrow down until you have what you need. Each step keeps the context of the last.

  1. AskHow does checkout calculate the amount?
  2. Openserver/checkout.ts L11–14
  3. FollowcalculateTotals → server/cart.ts L33–39
  4. AskWhich tests cover a discount?
  5. ResultNone. tests/cart.test.ts covers the zero-discount case only.

The simplest architecture that works.

Six parts, one database. Select a part to see what it does. This is the planned design for the first release.

Repository connector

Fetches repository contents with the narrowest permission the code host offers. Credentials stay server-side and can be revoked by disconnecting.

Security and privacy principles.

These are the principles repository connections are being built to. RepoMind holds no security certifications today, and we will not claim any until they are earned.

Least-privilege access
Read-only scopes, requested per repository rather than per account.
Credentials stay server-side
Tokens will be stored encrypted and never sent to the browser or to the model.
Clear access controls
You choose which repositories are connected and who in a workspace can query them.
Disconnect any time
Disconnecting a repository will revoke access and schedule its index for deletion.
Defined retention
Retention and deletion periods will be published before repository connections launch.
Careful with secrets
Files that look like credentials will be skipped, and detected secrets masked from context.
Transparent AI processing
We will document what is sent to the model provider, and why, for every request type.

Questions, answered plainly.

It indexes files, symbols and the references between them, then retrieves the most relevant code for each question and asks the model to explain it with citations. Understanding is limited to what can be read from the code. Highly dynamic patterns can be missed.

See it on a real question.