Skip to content

Give a person (username) or a team of the workspace (team: its slug) the read, write or admin role on a package, or change theirs.

PUT/workspaces/{workspace}/packages/{package_type}/{package_name}/access

It adds to what its repository or workspace gives them. Takes the Admin role on the package. Returns everyone with a role on it.

Give username or team (a team of the workspace, by slug). The role adds to what the repository or workspace already gives.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: package with action set_access, and the same inputs
  • Scope: An access token needs packages:write.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
package_type string Yes The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer.
package_name string Yes The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
username string No The person’s username. Give this or team.
team string No A team of the workspace: its slug, or workspace/slug. Give this or username.
role string Yes read pulls, write publishes, admin deletes, restores and changes its settings. One of read, write, admin.
curl -X PUT https://api.g1t.sh/workspaces/acme/packages/container/web/access \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"username": "dana",
"role": "write"
}'

A successful request answers 200 with:

[
{
"type": "team",
"id": "team_01kq1a3c5e7g9j1l3n5q7s9u1w",
"name": "acme/platform",
"role": "admin",
"created_at": "2026-10-01T09:00:00.000Z"
},
{
"type": "user",
"id": "usr_01kkntcg1eeb98j62xjm7eh09q",
"name": "dana",
"role": "write",
"created_at": "2026-10-02T13:30:00.000Z"
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.