Grants and scopes
Scopes
Section titled “Scopes”| Value | Meaning |
|---|---|
ALL_REPO |
All current and future repositories you own |
SELECTED_REPO |
Only repository_ids listed at create/update |
Grants
Section titled “Grants”ALL matches every check. GIT_HTTP_WRITE implies GIT_HTTP_READ. API_REPOS_WRITE implies API_REPOS_READ.
| Operation | Grant |
|---|---|
GET /v1/account/usage |
any token |
GET /v1/repositories |
API_REPOS_READ (filtered by scope) |
GET /v1/repos/{user}/{name} |
API_REPOS_READ and a scope that includes that repo |
| Create / delete repo | API_REPOS_WRITE |
git clone / fetch |
GIT_HTTP_READ |
git push |
GIT_HTTP_WRITE |
| Branches / commits / contents API | API_COMMITS_READ |
| Webhooks | API_WEBHOOKS |
| BYO storage | API_STORAGE |
| OIDC trust rules | API_OIDC_TRUST (and ALL_REPO) |
| Access token admin | ALL and ALL_REPO |
OIDC-exchanged tokens carry the grants on the matching trust rule.