Skip to content

Set GitHub Actions permissions for an organization

PUT
/orgs/{org}/actions/permissions

Sets the GitHub Actions permissions policy for repositories and allowed actions and reusable workflows in an organization.

OAuth app tokens and personal access tokens (classic) need the admin:org scope to use this endpoint.

API method documentation

org
required
string

The organization name. The name is not case sensitive.

Media type application/json
object
enabled_repositories
required

The policy that controls the repositories in the organization that are allowed to run GitHub Actions.

string
Allowed values: all none selected
allowed_actions

The permissions policy that controls the actions and reusable workflows that are allowed to run.

string
Allowed values: all local_only selected
sha_pinning_required

Whether actions must be pinned to a full-length commit SHA.

boolean
Examples
Example default
{
"enabled_repositories": "all",
"allowed_actions": "selected",
"sha_pinning_required": true
}

Response