List a package's Actions access
Which repositories' workflows may use a package with their job token (G1T_TOKEN), with the read or write role: its linked repository (linked, always write) and those added under Manage Actions access.
GET
/workspaces/{workspace}/packages/{package_type}/{package_name}/actions-accessA job’s token from any other repository is refused. For the package’s admins.
A workflow job’s G1T_TOKEN reaches the package only from these repositories. The linked repository is always listed, with write.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
packagewithactionactions_access, and the same inputs - Scope: An access token needs
packages:read.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
workspace |
string | Yes | The workspace’s slug, e.g. “flagon-io”. |
package_type |
string | Yes | The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer. |
package_name |
string | Yes | The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven. |
Example request
Section titled “Example request”curl https://api.g1t.sh/workspaces/acme/packages/container/web/actions-access \ -H "Authorization: Bearer $G1T_TOKEN"Example response
Section titled “Example response”A successful request answers 200 with:
{ "repositories": [ { "repository_id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0", "repository": "acme/web", "role": "write", "linked": true, "created_at": null }, { "repository_id": "rep_01kpw0d5f7h9k1m3p5r7t9v1x3", "repository": "acme/deploy", "role": "read", "linked": false, "created_at": "2026-10-03T10:00:00.000Z" } ]}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 422 | invalid |
The input is not valid. message says which field and why. |