Update a workspace ruleset
Change a workspace ruleset.
PUT
/workspaces/{workspace}/rulesets/{id}Fields left out stay as they are; rules and bypass_actors, when given, replace the whole list. Owners only.
- Authentication: Required. Send an access token as
Authorization: Bearer. - MCP tool:
workspacewithactionupdate_ruleset, and the same inputs - Scope: An access token needs
workspace:admin.
Path parameters
Section titled “Path parameters”| Name | Type | Required | Description |
|---|---|---|---|
workspace |
string | Yes | The workspace’s slug, e.g. “flagon-io”. |
id |
string | Yes | The ruleset’s id: rs_… |
Body parameters
Section titled “Body parameters”Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.
| Name | Type | Required | Description |
|---|---|---|---|
ruleset_name |
string | No | What people call it, at most 100 characters. A ruleset as exported names it name, which is read too. |
enforcement |
string | No | active: its rules hold. evaluate: nothing is refused, and what would have been is recorded. disabled: kept, not evaluated. Default active. One of active, evaluate, disabled. |
target |
string | No | What its name conditions match. Default branch. One of branch, tag. |
conditions |
object | No | |
conditions.ref_name |
object | No | Which branches or tags: include and exclude, each a list of fnmatch patterns (* within a path segment, ** across them), ~DEFAULT_BRANCH or ~ALL. |
conditions.ref_name.include |
array of strings | No | |
conditions.ref_name.exclude |
array of strings | No | |
conditions.repository |
object | No | Which of the workspace’s repositories: include and exclude name patterns (or ~ALL), visibility (any, public, private) and topics (any of). |
conditions.repository.include |
array of strings | No | |
conditions.repository.exclude |
array of strings | No | |
conditions.repository.visibility |
string | No | One of any, public, private. |
conditions.repository.topics |
array of strings | No | |
bypass_actors |
array of objects | No | Who it does not hold for. Nobody bypasses unless listed, g1t included. kind role takes read, triage, write, maintain, admin (that role or higher) or owner; team its slug or workspace/slug; user a username; token a token id, or workspace for any of the workspace’s tokens; g1t no value. mode always (pushes and merges) or pull_requests (merges only; a person merging asks to, with bypass_rules). |
bypass_actors[].kind |
string | Yes | One of role, team, user, token, g1t. |
bypass_actors[].value |
string | No | |
bypass_actors[].mode |
string | No | One of always, pull_requests. |
rules |
array of objects | No | Its rules. Each: type, parameters (left-out parameters take their defaults) and applies_to (everyone, agents or people). See the Rules guide for every type’s parameters. |
rules[].type |
string | Yes | |
rules[].parameters |
object | No | |
rules[].applies_to |
string | No | One of everyone, agents, people. |
Example request
Section titled “Example request”curl -X PUT https://api.g1t.sh/workspaces/flagon-io/rulesets/rs_01kq3b2c3d4e5f6g7h8j9k0m1n \ -H "Authorization: Bearer $G1T_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "enforcement": "active" }'Example response
Section titled “Example response”A successful request answers 200 with:
{ "id": "rs_01kq3b2c3d4e5f6g7h8j9k0m1n", "level": "workspace", "workspace": "flagon-io", "name": "Release freeze", "enforcement": "active", "target": "branch", "conditions": { "ref_name": { "include": [ "~DEFAULT_BRANCH", "release/**" ], "exclude": [] }, "repository": { "include": [ "~ALL" ], "exclude": [ "sandbox-*" ], "visibility": "any", "topics": [] } }, "bypass_actors": [ { "kind": "team", "value": "flagon-io/release", "mode": "always" } ], "rules": [ { "type": "merge_window", "parameters": { "time_zone": "-05:00", "windows": [ { "days": [ "mon", "tue", "wed", "thu" ], "start": "09:00", "end": "17:00" } ], "freezes": [ { "start": "2026-12-20T00:00:00Z", "end": "2027-01-04T00:00:00Z", "reason": "Holidays" } ], "exceptions": [] }, "applies_to": "everyone" }, { "type": "cost_cap", "parameters": { "max_usd": 25 }, "applies_to": "agents" } ], "created_by": "syntaqx", "created_at": "2026-10-07T14:02:11.318Z", "updated_by": "syntaqx", "updated_at": "2026-10-07T14:02:11.318Z"}Errors
Section titled “Errors”A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.
| Status | Code | When |
|---|---|---|
| 401 | unauthenticated |
A token is required, or the one sent is not valid. |
| 403 | forbidden |
The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | not_found |
It does not exist, or you cannot see it. |
| 409 | conflict |
The request conflicts with the current state. |
| 422 | invalid |
The input is not valid. message says which field and why. |