Skip to content

Get allowed actions and reusable workflows for a repository

GET
/repos/{owner}/{repo}/actions/permissions/selected-actions

Gets the settings for selected actions and reusable workflows that are allowed in a repository. To use this endpoint, the repository policy for allowed_actions must be configured to selected. For more information, see “Set GitHub Actions permissions for a repository.”

OAuth tokens and personal access tokens (classic) need the repo scope to use this endpoint.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

Response

Media type application/json
object
github_owned_allowed

Whether GitHub-owned actions are allowed. For example, this includes the actions in the actions organization.

boolean
verified_allowed

Whether actions from GitHub Marketplace verified creators are allowed. Set to true to allow all actions by GitHub Marketplace verified creators.

boolean
patterns_allowed

Specifies a list of string-matching patterns to allow specific action(s) and reusable workflow(s). Wildcards, tags, and SHAs are allowed. For example, monalisa/octocat@*, monalisa/octocat@v2, monalisa/*.

[!NOTE] The patterns_allowed setting only applies to public repositories.

Array<string>
Examples
Example default
{
"github_owned_allowed": true,
"verified_allowed": false,
"patterns_allowed": [
"monalisa/octocat@*",
"docker/*"
]
}