# List who has access

> Who has access to a repository: the workspace's base_permission, and people, everyone with a role on it other than through it being public.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/repos/{owner}/{name}/collaborators</code></div>

Each person has their effective `role` (read, triage, write, maintain or admin), its `source` (`owner` of the workspace, the workspace's `base` permission, or a `direct` role on this repository), their `direct` role if they have one, and their `workspace_role` (`owner`, `member`, or null for an outside collaborator). Pending `invitations` are listed for those with the Admin role, and empty for anyone else. `viewer_role` is your own role, and `can_manage` whether you may change who has access. Needs the Write role or higher. People only.

Owners are listed with `source` `owner`, members with the base permission with `base`, and anyone given a role on this repository with `direct`; `role` is the highest of these, and `direct` shows a direct role even when ownership or the base permission gives more. `workspace_role` null means an outside collaborator. Anyone can read a public repository, which is not listed. `invitations` is empty unless you have the Admin role (`can_manage`). Refused with `403` below the Write role, and `404` for a private repository you cannot see. See [Access and roles](/guides/access-and-roles/).

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`access`](/reference/mcp/#access) with `action` `list_collaborators`, and the same inputs
- **Scope:** An access token needs [`access:read`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `owner` | string | Yes | The workspace that owns the repository. |
| `name` | string | Yes | The repository's name. |

## Example request

```sh
curl https://api.g1t.sh/repos/flagon-io/hello/collaborators \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
{
  "repo": "flagon-io/hello",
  "base_permission": "write",
  "people": [
    {
      "username": "syntaqx",
      "name": "Chase Pierce",
      "avatar": null,
      "role": "admin",
      "source": "owner",
      "direct": null,
      "workspace_role": "owner"
    },
    {
      "username": "linus",
      "name": null,
      "avatar": null,
      "role": "maintain",
      "source": "direct",
      "direct": "maintain",
      "workspace_role": "member"
    },
    {
      "username": "grace",
      "name": "Grace Hopper",
      "avatar": null,
      "role": "write",
      "source": "base",
      "direct": null,
      "workspace_role": "member"
    },
    {
      "username": "ada",
      "name": "Ada Lovelace",
      "avatar": null,
      "role": "triage",
      "source": "direct",
      "direct": "triage",
      "workspace_role": null
    }
  ],
  "invitations": [
    {
      "id": "rin_01kp3c4d5e6f7g8h9j0k1m2n3p",
      "repo": "flagon-io/hello",
      "repo_id": "rep_01m3m5q6p0e2qaw6mmjahk0qrr",
      "invitee": "alan",
      "email": null,
      "role": "write",
      "invited_by": "syntaqx",
      "inviter_avatar": null,
      "status": "pending",
      "created_at": "2026-10-05T17:00:00.000Z",
      "expires_at": "2026-10-12T17:00:00.000Z"
    },
    {
      "id": "rin_01kp3d7e8f9g0h1j2k3m4n5p6q",
      "repo": "flagon-io/hello",
      "repo_id": "rep_01m3m5q6p0e2qaw6mmjahk0qrr",
      "invitee": null,
      "email": "joan@example.com",
      "role": "read",
      "invited_by": "syntaqx",
      "inviter_avatar": null,
      "status": "pending",
      "created_at": "2026-10-05T17:00:00.000Z",
      "expires_at": "2026-10-12T17:00:00.000Z"
    }
  ],
  "viewer_role": "admin",
  "can_manage": true
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
