Skip to content

Push past push protection for a blocked secret, with a reason: false_positive or used_in_tests (the alert is closed with that reason) or will_fix_later (it stays open, to be rotated).

POST/repos/{owner}/{name}/secret-scanning/alerts/{id}/bypass

Recorded on the alert and in the audit log. With delegated bypass on, someone who does not review bypasses makes a request instead, which owners and the repository’s admins approve or deny; the answer says which happened. Push again once it is bypassed or approved.

Reason The alert
false_positive Closed as a false positive
used_in_tests Closed as used in tests
will_fix_later Stays open, to be rotated

With delegated bypass on, a call from someone who does not review bypasses makes a request instead: request is set and the secret is still blocked until an owner or admin approves it. Push again once it is bypassed.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action bypass, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
id string Yes The alert’s id: sec_…

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
reason string Yes false_positive: not a secret. used_in_tests: a value for tests. will_fix_later: real, to be rotated (the alert stays open). One of false_positive, used_in_tests, will_fix_later.
comment string No Why, in a sentence; kept with the alert. At most 500 characters.
curl -X POST https://api.g1t.sh/repos/flagon-io/hello/secret-scanning/alerts/sec_01kq2m7d4e5f6g7h8j9k0m1n2p/bypass \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"reason": "will_fix_later",
"comment": "Rotating it this afternoon."
}'

A successful request answers 200 with:

{
"secret": {
"id": "sec_01kq2m7d4e5f6g7h8j9k0m1n2p",
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"kind": "github_token",
"label": "a GitHub token",
"path": "scripts/release.sh",
"line": 12,
"commit": "4807077b296e6edbf410d55e72749d3e1170c291",
"preview": "ghp_X7…",
"status": "open",
"source": "push",
"found_by": "syntaqx",
"found_at": "2026-10-06T09:14:02.118Z",
"decided_by": null,
"reason": null,
"decided_at": null,
"dismissed_reason": null,
"test_value": null,
"state": "open",
"validity": null,
"validity_checked_at": null,
"bypass": {
"reason": "will_fix_later",
"comment": "Rotating it this afternoon.",
"by": "syntaqx",
"at": "2026-10-06T09:14:02.118Z",
"approved_by": null
},
"pattern_id": null,
"pattern_name": null,
"locations": 1
},
"request": null
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.