Skip to content

Set allowed actions and reusable workflows for a repository

PUT
/repos/{owner}/{repo}/actions/permissions/selected-actions

Sets the actions and reusable workflows that are allowed in a repository. To use this endpoint, the repository permission policy for allowed_actions must be configured to selected. For more information, see “Set GitHub Actions permissions for a repository.”

OAuth app tokens and personal access tokens (classic) need the repo scope to use this endpoint.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

Media type application/json
object
github_owned_allowed

Whether GitHub-owned actions are allowed. For example, this includes the actions in the actions organization.

boolean
verified_allowed

Whether actions from GitHub Marketplace verified creators are allowed. Set to true to allow all actions by GitHub Marketplace verified creators.

boolean
patterns_allowed

Specifies a list of string-matching patterns to allow specific action(s) and reusable workflow(s). Wildcards, tags, and SHAs are allowed. For example, monalisa/octocat@*, monalisa/octocat@v2, monalisa/*.

[!NOTE] The patterns_allowed setting only applies to public repositories.

Array<string>
Examples
Example selected_actions
{
"github_owned_allowed": true,
"verified_allowed": false,
"patterns_allowed": [
"monalisa/octocat@*",
"docker/*"
]
}

Response