Skip to content

Change a workspace's rules for personal access tokens; fields left out stay as they are. max_lifetime_days of 0 removes the limit.

PATCH/workspaces/{workspace}/personal-access-token-policy

The rules apply from each token’s next request, to tokens made before them too. Owners only, as people.

From each token’s next request, tokens made for all of a member’s workspaces no longer reach this one (tokens made for it alone still do), and neither does a token that lasts longer than 90 days or never expires. They keep working everywhere else.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action set_token_policy, and the same inputs
  • Scope: An access token needs workspace:admin.
Name Type Required Description
workspace string Yes The workspace’s name, e.g. “acme”.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
allow_tokens_for_all_workspaces boolean No A token made for every workspace of its owner reaches this one.
allow_tokens_for_this_workspace boolean No A token may be made for this workspace alone.
require_approval boolean No A token made for this workspace waits for an owner’s approval.
max_lifetime_days integer No The longest a token reaching it may last, in days, 1 to 3650; 0 for no limit.
forbid_no_expiry boolean No A token that never expires does not reach the workspace.
curl -X PATCH https://api.g1t.sh/workspaces/flagon-io/personal-access-token-policy \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"allow_tokens_for_all_workspaces": false,
"max_lifetime_days": 90
}'

A successful request answers 200 with:

{
"allow_tokens_for_all_workspaces": false,
"allow_tokens_for_this_workspace": true,
"require_approval": true,
"max_lifetime_days": 90,
"forbid_no_expiry": false,
"updated_by": "ada",
"updated_at": "2026-10-08T09:30:00.000Z"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.