Obsidian Git
The workspace is a normal git repository, so Obsidian can open it as a vault and sync it with the Obsidian Git plugin.
Before you start
- You must be a workspace owner. A clone carries everything, sealed secrets included, so fetch needs a workspace-wide secret-level read and push needs
writeplusadmin. - Create a git token: Settings, Git and Obsidian, Create git token. It asks for step-up (TOTP, or your password when TOTP is not enrolled). The token starts with
nxg_, is shown once, lasts 365 days, and works only on/git.
Clone
git clone https://dev.nexara.ac/git/<workspace>.git nexara
# user: your email password: the nxg_ token
The workspace id is shown in the remote URL on the Settings page (the first owner's workspace is main unless WORKSPACE was set). Open the folder as an Obsidian vault, install Obsidian Git, and set pull on start and auto commit-and-sync. Add this to .gitignore:
.obsidian/workspace*.json
What a push may not contain
A pre-receive hook rejects the whole push if any commit:
- updates a ref other than
main, deletesmainor force-pushes; - adds a symlink or a submodule;
- contains an unsealed
<!-- secret -->block or asensitivity: secretbody in clear; - contains raw credentials (private keys, cloud tokens, Nexara keys);
- lowers the sensitivity of a Page or block.
Secret content appears in the clone only as nxc-sealed:v1: ciphertext. Edit secrets in the web app. After a successful push the server assigns missing ids and rebuilds the index.
Troubleshooting
| Symptom | Cause |
|---|---|
401 authentication required: use an nxg_ git token | You used your password or an nxc_ key. Use the nxg_ token as the password |
403 forbidden | You are not an owner of that workspace, or the token belongs to another workspace |
| Push rejected with a reason | One of the rules above. Fix the commit and push again |