Skip to content

Grants and scopes

Value Meaning
ALL_REPO All current and future repositories you own
SELECTED_REPO Only repository_ids listed at create/update

ALL matches every check. GIT_HTTP_WRITE implies GIT_HTTP_READ. API_REPOS_WRITE implies API_REPOS_READ.

Operation Grant
GET /v1/account/usage any token
GET /v1/repositories API_REPOS_READ (filtered by scope)
GET /v1/repos/{user}/{name} API_REPOS_READ and a scope that includes that repo
Create / delete repo API_REPOS_WRITE
git clone / fetch GIT_HTTP_READ
git push GIT_HTTP_WRITE
Branches / commits / contents API API_COMMITS_READ
Webhooks API_WEBHOOKS
BYO storage API_STORAGE
OIDC trust rules API_OIDC_TRUST (and ALL_REPO)
Access token admin ALL and ALL_REPO

OIDC-exchanged tokens carry the grants on the matching trust rule.