Skip to content

Set allowed actions and reusable workflows for an organization

PUT
/orgs/{org}/actions/permissions/selected-actions

Sets the actions and reusable workflows that are allowed in an organization. To use this endpoint, the organization permission policy for allowed_actions must be configured to selected. For more information, see “Set GitHub Actions permissions for an organization.”

OAuth app tokens and personal access tokens (classic) need the admin:org scope to use this endpoint.

API method documentation

org
required
string

The organization name. The name is not case sensitive.

Media type application/json
object
github_owned_allowed

Whether GitHub-owned actions are allowed. For example, this includes the actions in the actions organization.

boolean
verified_allowed

Whether actions from GitHub Marketplace verified creators are allowed. Set to true to allow all actions by GitHub Marketplace verified creators.

boolean
patterns_allowed

Specifies a list of string-matching patterns to allow specific action(s) and reusable workflow(s). Wildcards, tags, and SHAs are allowed. For example, monalisa/octocat@*, monalisa/octocat@v2, monalisa/*.

[!NOTE] The patterns_allowed setting only applies to public repositories.

Array<string>
Examples
Example selected_actions
{
"github_owned_allowed": true,
"verified_allowed": false,
"patterns_allowed": [
"monalisa/octocat@*",
"docker/*"
]
}

Response