List who has access to a package
Who has a role on a package itself (read pulls, write publishes, admin deletes, restores and changes its settings), people and teams, with inherit_access: whether a linked package also takes its repository's roles.
GET
/workspaces/{workspace}/packages/{package_type}/{package_name}/accessOwners of the workspace administer every package. For the package’s admins.
Only the roles given on the package itself. With inherit_access on, a linked package’s repository roles count too, and the workspace’s owners administer every package.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
packagewithactionaccess, and the same inputs - Scope: An access token needs
packages:read.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
workspace |
string | Yes | The workspace’s slug, e.g. “flagon-io”. |
package_type |
string | Yes | The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer. |
package_name |
string | Yes | The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven. |
Example request
Section titled “Example request”curl https://api.g1t.sh/workspaces/acme/packages/container/web/access \ -H "Authorization: Bearer $G1T_TOKEN"Example response
Section titled “Example response”A successful request answers 200 with:
{ "inherit_access": true, "access": [ { "type": "team", "id": "team_01kq1a3c5e7g9j1l3n5q7s9u1w", "name": "acme/platform", "role": "admin", "created_at": "2026-10-01T09:00:00.000Z" }, { "type": "user", "id": "usr_01kkntcg1eeb98j62xjm7eh09q", "name": "dana", "role": "read", "created_at": "2026-10-02T13:30:00.000Z" } ]}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 422 | invalid |
The input is not valid. message says which field and why. |