Skip to content

Approve or deny a bypass request (owners, security managers and the repository's admins, never your own), or cancel your own.

PATCH/workspaces/{workspace}/secret-scanning/bypass-requests/{id}

An approved request bypasses push protection for that secret, as its requester asked.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: security with action review_bypass, and the same inputs
  • Scope: An access token needs security:write.
Name Type Required Description
workspace string Yes The workspace’s slug, e.g. “flagon-io”.
id string Yes The request’s id: byp_…

Send a JSON object. Names are snake_case, as in responses; the camelCase spelling is accepted too.

Name Type Required Description
decision string Yes approve or deny (reviewers), or cancel (your own). One of approve, deny, cancel.
comment string No Why, in a sentence; kept with the alert. At most 500 characters.
curl -X PATCH https://api.g1t.sh/workspaces/flagon-io/secret-scanning/bypass-requests/byp_01kq2n8e5f6g7h8j9k0m1n2p3q \
-H "Authorization: Bearer $G1T_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"decision": "approve",
"comment": "A fixture."
}'

A successful request answers 200 with:

{
"id": "byp_01kq2n8e5f6g7h8j9k0m1n2p3q",
"repo_id": "rep_01kp0a1b2c3d4e5f6g7h8j9k0m",
"workspace": "flagon-io",
"repo": "hello",
"secret_id": "sec_01kq2m7d4e5f6g7h8j9k0m1n2p",
"label": "a GitHub token",
"path": "scripts/release.sh",
"line": 12,
"preview": "ghp_X7…",
"requester": "ana",
"reason": "used_in_tests",
"comment": "A token from the test fixtures, never issued.",
"state": "approved",
"reviewer": "syntaqx",
"review_comment": "A fixture.",
"created_at": "2026-10-06T09:14:02.118Z",
"reviewed_at": "2026-10-06T09:20:41.502Z"
}

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
409 conflict The request conflicts with the current state.
422 invalid The input is not valid. message says which field and why.