Skip to content

Which repositories' workflows may use a package with their job token (G1T_TOKEN), with the read or write role: its linked repository (linked, always write) and those added under Manage Actions access.

GET/workspaces/{workspace}/packages/{package_type}/{package_name}/actions-access

A job’s token from any other repository is refused. For the package’s admins.

A workflow job’s G1T_TOKEN reaches the package only from these repositories. The linked repository is always listed, with write.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: package with action actions_access, and the same inputs
  • Scope: An access token needs packages:read.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
package_type string Yes The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer.
package_name string Yes The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven.
curl https://api.g1t.sh/workspaces/acme/packages/container/web/actions-access \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"repositories": [
{
"repository_id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0",
"repository": "acme/web",
"role": "write",
"linked": true,
"created_at": null
},
{
"repository_id": "rep_01kpw0d5f7h9k1m3p5r7t9v1x3",
"repository": "acme/deploy",
"role": "read",
"linked": false,
"created_at": "2026-10-03T10:00:00.000Z"
}
]
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.