Skip to content

A workspace's rules for its members' personal access tokens: allow_tokens_for_all_workspaces (a token made for every workspace of its owner reaches this one), allow_tokens_for_this_workspace (a token may be made for this workspace alone), require_approval (a token made for this workspace waits for an owner's approval; true unless an owner says, and never for an owner's own token), max_lifetime_days (the longest a token reaching it may last; null for no limit, and a token with an expiry lasts at most 366 days anyway) and forbid_no_expiry (a token that never expires does not reach it).

GET/workspaces/{workspace}/personal-access-token-policy

A token outside the rules keeps working elsewhere and reaches the workspace’s public repositories only. Members only.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action get_token_policy, and the same inputs
  • Scope: An access token needs workspace:read.
Name Type Required Description
workspace string Yes The workspace’s name, e.g. “acme”.
curl https://api.g1t.sh/workspaces/flagon-io/personal-access-token-policy \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

{
"allow_tokens_for_all_workspaces": true,
"allow_tokens_for_this_workspace": true,
"require_approval": true,
"max_lifetime_days": null,
"forbid_no_expiry": false,
"updated_by": null,
"updated_at": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.