Skip to content
PUT/workspaces/{workspace}/rulesets/{id}

Fields left out stay as they are; rules and bypass_actors, when given, replace the whole list. Owners only.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workspace with action update_ruleset, and the same inputs
  • Scope: An access token needs workspace:admin.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
id string Yes The ruleset’s id: rs_…

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
ruleset_name string No What people call it, at most 100 characters. A ruleset as exported names it name, which is read too.
enforcement string No active: its rules hold. evaluate: nothing is refused, and what would have been is recorded. disabled: kept, not evaluated. Default active. One of active, evaluate, disabled.
target string No What its name conditions match. Default branch. One of branch, tag.
conditions object No
conditions.ref_name object No Which branches or tags: include and exclude, each a list of fnmatch patterns (* within a path segment, ** across them), ~DEFAULT_BRANCH or ~ALL.
conditions.ref_name.include array of strings No
conditions.ref_name.exclude array of strings No
conditions.repository object No Which of the workspace’s repositories: include and exclude name patterns (or ~ALL), visibility (any, public, private) and topics (any of).
conditions.repository.include array of strings No
conditions.repository.exclude array of strings No
conditions.repository.visibility string No One of any, public, private.
conditions.repository.topics array of strings No
bypass_actors array of objects No Who it does not hold for. Nobody bypasses unless listed, g1t included. kind role takes read, triage, write, maintain, admin (that role or higher) or owner; team its slug or workspace/slug; user a username; token a token id, or workspace for any of the workspace’s tokens; g1t no value. mode always (pushes and merges) or pull_requests (merges only; a person merging asks to, with bypass_rules).
bypass_actors[].kind string Yes One of role, team, user, token, g1t.
bypass_actors[].value string No
bypass_actors[].mode string No One of always, pull_requests.
rules array of objects No Its rules. Each: type, parameters (left-out parameters take their defaults) and applies_to (everyone, agents or people). See the Rules guide for every type’s parameters.
rules[].type string Yes
rules[].parameters object No
rules[].applies_to string No One of everyone, agents, people.
curl -X PUT https://api.g1t.sh/workspaces/flagon-io/rulesets/rs_01kq3b2c3d4e5f6g7h8j9k0m1n \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"enforcement": "active"
}'

A successful request answers 200 with:

{
"id": "rs_01kq3b2c3d4e5f6g7h8j9k0m1n",
"level": "workspace",
"workspace": "flagon-io",
"name": "Release freeze",
"enforcement": "active",
"target": "branch",
"conditions": {
"ref_name": {
"include": [
"~DEFAULT_BRANCH",
"release/**"
],
"exclude": []
},
"repository": {
"include": [
"~ALL"
],
"exclude": [
"sandbox-*"
],
"visibility": "any",
"topics": []
}
},
"bypass_actors": [
{
"kind": "team",
"value": "flagon-io/release",
"mode": "always"
}
],
"rules": [
{
"type": "merge_window",
"parameters": {
"time_zone": "-05:00",
"windows": [
{
"days": [
"mon",
"tue",
"wed",
"thu"
],
"start": "09:00",
"end": "17:00"
}
],
"freezes": [
{
"start": "2026-12-20T00:00:00Z",
"end": "2027-01-04T00:00:00Z",
"reason": "Holidays"
}
],
"exceptions": []
},
"applies_to": "everyone"
},
{
"type": "cost_cap",
"parameters": {
"max_usd": 25
},
"applies_to": "agents"
}
],
"created_by": "syntaqx",
"created_at": "2026-10-07T14:02:11.318Z",
"updated_by": "syntaqx",
"updated_at": "2026-10-07T14:02:11.318Z"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.