# List a repository's rulesets

> List a repository's rulesets: what may happen to its branches and tags, and what a pull request needs before it merges.

<div class="g1t-endpoint"><span class="g1t-method" data-method="get">GET</span><code>/repos/{owner}/{name}/rulesets</code></div>

With include_parents, also its workspace's rulesets that hold in it (level workspace). Each has its enforcement (active, evaluate: a dry run that records what it would have refused, or disabled), target (branch or tag), conditions (ref_name include and exclude patterns: fnmatch, ~DEFAULT_BRANCH, ~ALL), bypass_actors and rules. The one made from branch protection settings has source branch_protection.

With `include_parents`, the workspace's rulesets that hold in the repository come too, with `level` `workspace`. The ruleset made from the repository's branch protection settings has `source` `branch_protection`.

- **Authentication:** Optional. Public data can be read without a token; send one to see what is private.
- **MCP tool:** [`repository`](/reference/mcp/#repository) with `action` `list_rulesets`, and the same inputs
- **Scope:** An access token needs [`repo:read`](/guides/authentication/#scopes).

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `owner` | string | Yes | The workspace that owns the repository. |
| `name` | string | Yes | The repository's name. |

## Query parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `include_parents` | boolean | No | Also list the workspace's rulesets that hold in it. |

## Example request

```sh
curl "https://api.g1t.sh/repos/flagon-io/hello/rulesets?include_parents=true" \
  -H "Authorization: Bearer $G1T_TOKEN"
```

## Example response

A successful request answers `200` with:

```json
[
  {
    "id": "rs_01kq3a8b9c0d1e2f3g4h5j6k7m",
    "level": "repository",
    "workspace": "flagon-io",
    "repo_id": "rep_01kq0f3a7b8c9d0e1f2g3h4j5k",
    "repository": "flagon-io/hello",
    "name": "Protect main",
    "enforcement": "active",
    "target": "branch",
    "conditions": {
      "ref_name": {
        "include": [
          "~DEFAULT_BRANCH"
        ],
        "exclude": []
      }
    },
    "bypass_actors": [
      {
        "kind": "role",
        "value": "admin",
        "mode": "pull_requests"
      }
    ],
    "rules": [
      {
        "type": "deletion",
        "parameters": {},
        "applies_to": "everyone"
      },
      {
        "type": "non_fast_forward",
        "parameters": {},
        "applies_to": "everyone"
      },
      {
        "type": "pull_request",
        "parameters": {
          "required_approvals": 1,
          "count_agent_approvals": true,
          "dismiss_stale_reviews_on_push": true,
          "require_code_owner_review": true,
          "require_last_push_approval": false,
          "allowed_merge_methods": []
        },
        "applies_to": "everyone"
      },
      {
        "type": "required_status_checks",
        "parameters": {
          "checks": [
            {
              "context": "CI",
              "integration": "actions"
            }
          ],
          "strict": true,
          "paths": [],
          "allow_bypass_on_merge": false
        },
        "applies_to": "everyone"
      },
      {
        "type": "pull_request",
        "parameters": {
          "required_approvals": 1,
          "count_agent_approvals": false,
          "dismiss_stale_reviews_on_push": false,
          "require_code_owner_review": false,
          "require_last_push_approval": false,
          "allowed_merge_methods": []
        },
        "applies_to": "agents"
      },
      {
        "type": "file_path_restriction",
        "parameters": {
          "restricted_file_paths": [
            ".g1t/workflows/**",
            "CODEOWNERS"
          ]
        },
        "applies_to": "agents"
      }
    ],
    "created_by": "syntaqx",
    "created_at": "2026-10-07T14:02:11.318Z",
    "updated_by": "syntaqx",
    "updated_at": "2026-10-07T14:02:11.318Z"
  },
  {
    "id": "rs_01kq3b2c3d4e5f6g7h8j9k0m1n",
    "level": "workspace",
    "workspace": "flagon-io",
    "name": "Release freeze",
    "enforcement": "evaluate",
    "target": "branch",
    "conditions": {
      "ref_name": {
        "include": [
          "~DEFAULT_BRANCH",
          "release/**"
        ],
        "exclude": []
      },
      "repository": {
        "include": [
          "~ALL"
        ],
        "exclude": [
          "sandbox-*"
        ],
        "visibility": "any",
        "topics": []
      }
    },
    "bypass_actors": [
      {
        "kind": "team",
        "value": "flagon-io/release",
        "mode": "always"
      }
    ],
    "rules": [
      {
        "type": "merge_window",
        "parameters": {
          "time_zone": "-05:00",
          "windows": [
            {
              "days": [
                "mon",
                "tue",
                "wed",
                "thu"
              ],
              "start": "09:00",
              "end": "17:00"
            }
          ],
          "freezes": [
            {
              "start": "2026-12-20T00:00:00Z",
              "end": "2027-01-04T00:00:00Z",
              "reason": "Holidays"
            }
          ],
          "exceptions": []
        },
        "applies_to": "everyone"
      },
      {
        "type": "cost_cap",
        "parameters": {
          "max_usd": 25
        },
        "applies_to": "agents"
      }
    ],
    "created_by": "syntaqx",
    "created_at": "2026-10-07T14:02:11.318Z",
    "updated_by": "syntaqx",
    "updated_at": "2026-10-07T14:02:11.318Z"
  }
]
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
