Skip to content

The personal access tokens of the workspace's members and outside collaborators that can reach it and have not expired: every token made for this workspace, whatever its status, and every token made for all of its owner's workspaces.

GET/workspaces/{workspace}/personal-access-tokens

Each with its owner, name, description, permissions (each resource at its level, such as {“issues”: “write”}), scopes, workspace (the one it is made for; null for all of its owner’s), repository_selection (all, selected or public), repositories, status (active, pending, denied or revoked), when it was made, last used and expires, and whether it reaches the workspace now (reaches, and blocked_by when not: pending approval, denied, revoked, tokens for all workspaces not allowed, tokens made for this workspace not allowed, lasts too long, never expires). Never the token itself. Owners only, as people.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action list_member_tokens, and the same inputs
  • Scope: An access token needs access:read.
Name Type Required Description
workspace string Yes The workspace’s name, e.g. “acme”.
curl https://api.g1t.sh/workspaces/flagon-io/personal-access-tokens \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "tok_01HZX3K2M9V7Q4N8B6D5C3A2E1",
"name": "release-bot",
"owner": "ada",
"description": "Publishes releases from CI",
"created_at": "2026-10-08T09:00:00.000Z",
"created_by": null,
"last_used_at": null,
"expires_at": "2026-11-07T09:00:00.000Z",
"scopes": [
"repo:read",
"code:write"
],
"workspace": "flagon-io",
"repository_selection": "selected",
"repositories": [
"flagon-io/hello"
],
"permissions": {
"code": "write",
"repo": "read"
},
"status": "pending",
"review_reason": null,
"reaches": false,
"blocked_by": "pending approval"
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.