Skip to content

Set default_workflow_permissions to read, write (refused where the workspace's maximum is read) or inherit (back to the workspace's default, or write for a repository made before restricted tokens), and can_approve_pull_request_reviews, "Allow g1t Actions to create and approve pull requests" (refused where the workspace does not allow it).

PUT/repos/{owner}/{name}/actions/permissions/workflow

Workflows that write permissions: get what they write either way, and a pull request’s run from outside gets read-only. Needs the Admin role.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: workflow with action set_permissions, and the same inputs
  • Scope: An access token needs repo:admin.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
default_workflow_permissions string No One of read, write, inherit.
can_approve_pull_request_reviews boolean No Allow g1t Actions to create and approve pull requests.
curl -X PUT https://api.g1t.sh/repos/flagon-io/g1t/actions/permissions/workflow \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"default_workflow_permissions": "write"
}'

A successful request answers 200 with:

{
"default_workflow_permissions": "write",
"default_chosen": true,
"max_workflow_permissions": "write",
"can_approve_pull_request_reviews": false
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.