Skip to content

Set default workflow permissions for a repository

PUT
/repos/{owner}/{repo}/actions/permissions/workflow

Sets the default workflow permissions granted to the GITHUB_TOKEN when running workflows in a repository, and sets if GitHub Actions can submit approving pull request reviews. For more information, see “Setting the permissions of the GITHUB_TOKEN for your repository.”

OAuth app tokens and personal access tokens (classic) need the repo scope to use this endpoint.

API method documentation

owner
required
string

The account owner of the repository. The name is not case sensitive.

repo
required
string

The name of the repository without the .git extension. The name is not case sensitive.

Media type application/json
object
default_workflow_permissions

The default workflow permissions granted to the GITHUB_TOKEN when running workflows.

string
Allowed values: read write
can_approve_pull_request_reviews

Whether GitHub Actions can approve pull requests. Enabling this can be a security risk.

boolean
Examples
Example default

Give read-only permission, and allow approving PRs.

{
"default_workflow_permissions": "read",
"can_approve_pull_request_reviews": true
}

Success response

Conflict response when changing a setting is prevented by the owning organization