Skip to content

Change a package's visibility (public or private: an unlinked package only, as a linked one has its repository's) or, for a linked package, inherit_access: whether it takes its repository's roles.

PATCH/workspaces/{workspace}/packages/{package_type}/{package_name}

Off, only the roles given on the package itself and the workspace’s owners count. Takes the Admin role on the package. Returns the package.

With inherit_access off, the repository’s roles no longer reach the package: only the roles given on it (set_package_access) and the workspace’s owners. visibility is for an unlinked package; a linked one has its repository’s.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: package with action update, and the same inputs
  • Scope: An access token needs packages:write.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
package_type string Yes The registry: container (also docker), npm, cargo, maven, nuget, rubygems or composer. One of container, npm, cargo, maven, nuget, rubygems, composer.
package_name string Yes The package’s name without the workspace: web for g1t.sh/acme/web, web/worker for an image with more parts, group:artifact for Maven.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
visibility string No Who may pull an unlinked package: anyone, or the workspace’s members by its base permission. One of public, private.
inherit_access boolean No For a linked package: whether it takes its repository’s roles.
curl -X PATCH https://api.g1t.sh/workspaces/acme/packages/container/web \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"inherit_access": false
}'

A successful request answers 200 with:

{
"id": "pkg_01kq7b3d5f7h9k1m3p5r7t9v1x",
"name": "web",
"package_type": "container",
"workspace": "acme",
"address": "g1t.sh/acme/web",
"visibility": "private",
"repository": {
"id": "rep_01kpw0a2c4e6g8j0m2p4r6t8v0",
"name": "web",
"full_name": "acme/web"
},
"description": null,
"version_count": 12,
"latest": "latest",
"size_in_bytes": 48211932,
"download_count": 1840,
"inherit_access": false,
"created_at": "2026-09-14T10:02:11.000Z",
"updated_at": "2026-10-08T15:01:40.000Z",
"deleted_at": null,
"deleted_by": null,
"purge_at": null,
"html_url": "https://g1t.sh/acme/-/packages/container/web"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.