# Change runner settings for a workspace

> Change where g1t agent work runs and whether pull requests from forks may use self-hosted runners, for a workspace or one repository.

<div class="g1t-endpoint"><span class="g1t-method" data-method="patch">PATCH</span><code>/workspaces/{workspace}/actions/runner-settings</code></div>

Left out is unchanged; `inherit` drops a repository's own settings. Allowing forks lets anyone who can open a pull request run code on your machines. Owners of the workspace, or admins of the repository.

Agent work on your runners still uses g1t's model proxy, paid as before, unless the workspace has its own model provider.

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`workflow`](/reference/mcp/#workflow) with `action` `update_runner_settings`, and the same inputs
- **Scope:** An access token needs [`runners:admin`](/guides/authentication/#scopes).
- **Also at:** [`PATCH /repos/{owner}/{name}/actions/runner-settings`](/reference/api/runners/update-runner-settings/)

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `workspace` | string | Yes | Instead of repo: the workspace, for the runners its repositories share. |

## Body parameters

Send a JSON object. Names are `snake_case`, as in responses; the `camelCase` spelling is accepted too.

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `agents_on_self_hosted` | boolean | No | Run agent runs, checks, reviews and the merge queue on self-hosted runners. |
| `agent_labels` | array of strings | No | The labels a runner needs to take agent work. self-hosted is always one. |
| `fork_pull_requests` | boolean | No | Let jobs of pull requests from forks run on self-hosted runners. |
| `inherit` | boolean | No | For a repository: drop its own settings and follow its workspace's. |

## Example request

```sh
curl -X PATCH https://api.g1t.sh/workspaces/flagon-io/actions/runner-settings \
  -H "Authorization: Bearer $G1T_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "agents_on_self_hosted": true,
    "agent_labels": [
      "linux"
    ]
  }'
```

## Example response

A successful request answers `200` with:

```json
{
  "agents_on_self_hosted": true,
  "agent_labels": [
    "self-hosted",
    "linux"
  ],
  "fork_pull_requests": false,
  "inherited": false
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 409 | `conflict` | The request conflicts with the current state. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
