Update a package
Change a package's visibility (public or private: an unlinked package only, as a linked one has its repository's) or, for a linked package, inherit_access: whether it takes its repository's roles.
/workspaces/{workspace}/packages/{package_type}/{package_name}Off, only the roles given on the package itself and the workspace’s owners count. Takes the Admin role on the package. Returns the package.
With inherit_access off, the repository’s roles no longer reach the package: only the roles given on it (set_package_access) and the workspace’s owners. visibility is for an unlinked package; a linked one has its repository’s.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
packagewithactionupdate, and the same inputs - Scope: An access token needs
packages:write.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
workspace |
string | Yes | The workspace’s slug, e.g. “flagon-io”. |
package_type |
string | Yes | The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer. |
package_name |
string | Yes | The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven. |
Body parameters
Section titled “Body parameters”Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.
| Name | Type | Required | Description |
|---|---|---|---|
visibility |
string | No | Who may pull an unlinked package: anyone, or the workspace’s members by its base permission. One of public, private. |
inherit_access |
boolean | No | For a linked package: whether it takes its repository’s roles. |
Example request
Section titled “Example request”curl -X PATCH https://api.g1t.sh/workspaces/acme/packages/container/web \ -H "Authorization: Bearer $G1T_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "inherit_access": false }'Example response
Section titled “Example response”A successful request answers 200 with:
{ "id": "pkg_01kq7b3d5f7h9k1m3p5r7t9v1x", "name": "web", "package_type": "container", "workspace": "acme", "address": "g1t.sh/acme/web", "visibility": "private", "repository": { "id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0", "name": "web", "full_name": "acme/web" }, "description": null, "version_count": 12, "latest": "latest", "size_in_bytes": 48211932, "download_count": 1840, "inherit_access": false, "created_at": "2026-09-14T10:02:11.000Z", "updated_at": "2026-10-08T15:01:40.000Z", "deleted_at": null, "deleted_by": null, "purge_at": null, "html_url": "https://g1t.sh/acme/-/packages/container/web"}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 409 | conflict |
The request conflicts with the current state. |
| 422 | invalid |
The input is not valid. message says which field and why. |