Skip to main content
Skip to content
Die REST-API ist jetzt versioniert. Weitere Informationen findest du unter Informationen zur API-Versionsverwaltung.

REST API endpoints for GitHub Actions policies

Use the REST API to view and manage policies for GitHub Actions.

List organization Actions policies

List all Actions policies for an organization.

Feinkörnige Zugriffstoken für "List organization Actions policies"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" organization permissions (write)

Parameter für "List organization Actions policies"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
org string Erforderlich

The organization name. The name is not case sensitive.

Abfrageparameter
Name, Typ, BESCHREIBUNG
per_page integer

The number of results per page (max 100). For more information, see "Using pagination in the REST API."

Standard: 30

page integer

The page number of the results to fetch. For more information, see "Using pagination in the REST API."

Standard: 1

has_parents boolean

Include policies configured at higher levels that apply to this organization

Standard: true

HTTP-Antwortstatuscodes für "List organization Actions policies"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

500

Internal Error

Codebeispiele für "List organization Actions policies"

Anforderungsbeispiel

get/orgs/{org}/actions/policies
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/actions/policies

Response

Status: 200
{ "total_count": 2, "policies": [ { "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "node_id": "RUL_lA", "_links": { "self": { "href": "https://api.github.com/enterprises/enterprise/actions/policies/1" }, "html": { "href": "https://github.com/enterprises/enterprise/settings/policies/actions/1" } }, "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }, { "id": 2, "name": "Restrict workflow events", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "evaluate", "node_id": "RUL_lB", "_links": { "self": { "href": "https://api.github.com/enterprises/enterprise/actions/policies/2" }, "html": { "href": "https://github.com/enterprises/enterprise/settings/policies/actions/2" } }, "created_at": "2024-01-15T11:00:00Z", "updated_at": "2024-01-15T11:00:00Z" } ] }

Create an organization Actions policy

Create an Actions policy for an organization. Omitting workflow_path targets all workflows without storing an explicit condition.

Feinkörnige Zugriffstoken für "Create an organization Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" organization permissions (write)

Parameter für "Create an organization Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
org string Erforderlich

The organization name. The name is not case sensitive.

Körperparameter
Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the policy.

enforcement string Erforderlich

The enforcement level of the ruleset. evaluate allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (evaluate is only available with GitHub Enterprise).

Kann eine der folgenden sein: disabled, active, evaluate

conditions object

Conditions for an organization Actions policy. The conditions object should contain one of repository_name, repository_id, or repository_property, and may also contain workflow_path.

Name, Typ, BESCHREIBUNG
Repository ruleset conditions for repository names object

Parameters for a repository name condition

Name, Typ, BESCHREIBUNG
repository_name object Erforderlich
Name, Typ, BESCHREIBUNG
include array of strings

Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts ~ALL to include all repositories.

exclude array of strings

Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match.

protected boolean

Whether renaming of target repositories is prevented.

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

Repository ruleset conditions for repository IDs object

Parameters for a repository ID condition

Name, Typ, BESCHREIBUNG
repository_id object Erforderlich
Name, Typ, BESCHREIBUNG
repository_ids array of integers

The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass.

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

Repository ruleset conditions for repository properties object

Parameters for a repository property condition

Name, Typ, BESCHREIBUNG
repository_property object Erforderlich
Name, Typ, BESCHREIBUNG
include array of objects

The repository properties and values to include. All of these properties must match for the condition to pass.

Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the repository property to target

property_values array of strings Erforderlich

The values to match for the repository property

source string

The source of the repository property. Defaults to 'custom' if not specified.

Kann eine der folgenden sein: custom, system

exclude array of objects

The repository properties and values to exclude. The condition will not pass if any of these properties match.

Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the repository property to target

property_values array of strings Erforderlich

The values to match for the repository property

source string

The source of the repository property. Defaults to 'custom' if not specified.

Kann eine der folgenden sein: custom, system

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

rules array of objects

An array of rules within the policy.

Name, Typ, BESCHREIBUNG
restrict_actions_actors object

Choose specific actors that are authorized to trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_actions_actors

parameters object
Name, Typ, BESCHREIBUNG
allowed_actors array of objects Erforderlich

Select the actors who can run Actions workflows.

Name, Typ, BESCHREIBUNG
id integer Erforderlich

ID of the actor authorized to trigger Actions workflows.

type string Erforderlich

The type of the actor

Kann eine der folgenden sein: User, Bot, Team, BusinessTeam, EnterpriseTeam, IntegrationInstallation, App, RepositoryRole

restrict_action_events object

Choose specific GitHub events that will trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_action_events

parameters object
Name, Typ, BESCHREIBUNG
allowed_events array of strings Erforderlich

Select the events that can trigger Actions workflows. Supported values are: branch_protection_rule, check_run, check_suite, create, delete, deployment, deployment_status, discussion, discussion_comment, fork, gollum, image_version, issue_comment, issues, label, merge_group, milestone, page_build, project, project_card, project_column, public, pull_request, pull_request_review, pull_request_review_comment, pull_request_target, push, registry_package, release, repository_dispatch, schedule, status, watch, workflow_call, workflow_dispatch, workflow_run

HTTP-Antwortstatuscodes für "Create an organization Actions policy"

StatuscodeBESCHREIBUNG
201

Created

404

Resource not found

422

Validation failed, or the endpoint has been spammed.

500

Internal Error

Codebeispiele für "Create an organization Actions policy"

Anforderungsbeispiel

post/orgs/{org}/actions/policies
curl -L \ -X POST \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/actions/policies \ -d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'

Response

Status: 201
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Get an organization Actions policy

Get a specific Actions policy for an organization.

Feinkörnige Zugriffstoken für "Get an organization Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" organization permissions (write)

Parameter für "Get an organization Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
org string Erforderlich

The organization name. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

HTTP-Antwortstatuscodes für "Get an organization Actions policy"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

500

Internal Error

Codebeispiele für "Get an organization Actions policy"

Anforderungsbeispiel

get/orgs/{org}/actions/policies/{policy_id}
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/actions/policies/POLICY_ID

Response

Status: 200
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Update an organization Actions policy

Update an Actions policy for an organization. Omitting workflow_path preserves the policy's existing workflow targeting.

Feinkörnige Zugriffstoken für "Update an organization Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" organization permissions (write)

Parameter für "Update an organization Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
org string Erforderlich

The organization name. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

Körperparameter
Name, Typ, BESCHREIBUNG
name string

The name of the policy.

enforcement string

The enforcement level of the ruleset. evaluate allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (evaluate is only available with GitHub Enterprise).

Kann eine der folgenden sein: disabled, active, evaluate

conditions object

Conditions for an organization Actions policy. The conditions object should contain one of repository_name, repository_id, or repository_property, and may also contain workflow_path.

Name, Typ, BESCHREIBUNG
Repository ruleset conditions for repository names object

Parameters for a repository name condition

Name, Typ, BESCHREIBUNG
repository_name object Erforderlich
Name, Typ, BESCHREIBUNG
include array of strings

Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts ~ALL to include all repositories.

exclude array of strings

Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match.

protected boolean

Whether renaming of target repositories is prevented.

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

Repository ruleset conditions for repository IDs object

Parameters for a repository ID condition

Name, Typ, BESCHREIBUNG
repository_id object Erforderlich
Name, Typ, BESCHREIBUNG
repository_ids array of integers

The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass.

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

Repository ruleset conditions for repository properties object

Parameters for a repository property condition

Name, Typ, BESCHREIBUNG
repository_property object Erforderlich
Name, Typ, BESCHREIBUNG
include array of objects

The repository properties and values to include. All of these properties must match for the condition to pass.

Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the repository property to target

property_values array of strings Erforderlich

The values to match for the repository property

source string

The source of the repository property. Defaults to 'custom' if not specified.

Kann eine der folgenden sein: custom, system

exclude array of objects

The repository properties and values to exclude. The condition will not pass if any of these properties match.

Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the repository property to target

property_values array of strings Erforderlich

The values to match for the repository property

source string

The source of the repository property. Defaults to 'custom' if not specified.

Kann eine der folgenden sein: custom, system

workflow_path object
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

rules array of objects

An array of rules within the policy.

Name, Typ, BESCHREIBUNG
restrict_actions_actors object

Choose specific actors that are authorized to trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_actions_actors

parameters object
Name, Typ, BESCHREIBUNG
allowed_actors array of objects Erforderlich

Select the actors who can run Actions workflows.

Name, Typ, BESCHREIBUNG
id integer Erforderlich

ID of the actor authorized to trigger Actions workflows.

type string Erforderlich

The type of the actor

Kann eine der folgenden sein: User, Bot, Team, BusinessTeam, EnterpriseTeam, IntegrationInstallation, App, RepositoryRole

restrict_action_events object

Choose specific GitHub events that will trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_action_events

parameters object
Name, Typ, BESCHREIBUNG
allowed_events array of strings Erforderlich

Select the events that can trigger Actions workflows. Supported values are: branch_protection_rule, check_run, check_suite, create, delete, deployment, deployment_status, discussion, discussion_comment, fork, gollum, image_version, issue_comment, issues, label, merge_group, milestone, page_build, project, project_card, project_column, public, pull_request, pull_request_review, pull_request_review_comment, pull_request_target, push, registry_package, release, repository_dispatch, schedule, status, watch, workflow_call, workflow_dispatch, workflow_run

HTTP-Antwortstatuscodes für "Update an organization Actions policy"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

422

Validation failed, or the endpoint has been spammed.

500

Internal Error

Codebeispiele für "Update an organization Actions policy"

Anforderungsbeispiel

put/orgs/{org}/actions/policies/{policy_id}
curl -L \ -X PUT \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/actions/policies/POLICY_ID \ -d '{"name":"Updated policy name","enforcement":"active"}'

Response

Status: 200
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Delete an organization Actions policy

Delete an Actions policy for an organization.

Feinkörnige Zugriffstoken für "Delete an organization Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" organization permissions (write)

Parameter für "Delete an organization Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
org string Erforderlich

The organization name. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

HTTP-Antwortstatuscodes für "Delete an organization Actions policy"

StatuscodeBESCHREIBUNG
204

No Content

404

Resource not found

500

Internal Error

Codebeispiele für "Delete an organization Actions policy"

Anforderungsbeispiel

delete/orgs/{org}/actions/policies/{policy_id}
curl -L \ -X DELETE \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/actions/policies/POLICY_ID

Response

Status: 204

List repository Actions policies

List all Actions policies for a repository.

Feinkörnige Zugriffstoken für "List repository Actions policies"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" repository permissions (write)

Parameter für "List repository Actions policies"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
owner string Erforderlich

The account owner of the repository. The name is not case sensitive.

repo string Erforderlich

The name of the repository without the .git extension. The name is not case sensitive.

Abfrageparameter
Name, Typ, BESCHREIBUNG
per_page integer

The number of results per page (max 100). For more information, see "Using pagination in the REST API."

Standard: 30

page integer

The page number of the results to fetch. For more information, see "Using pagination in the REST API."

Standard: 1

has_parents boolean

Include policies configured at higher levels that apply to this repository

Standard: true

HTTP-Antwortstatuscodes für "List repository Actions policies"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

500

Internal Error

Codebeispiele für "List repository Actions policies"

Anforderungsbeispiel

get/repos/{owner}/{repo}/actions/policies
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/repos/OWNER/REPO/actions/policies

Response

Status: 200
{ "total_count": 2, "policies": [ { "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "node_id": "RUL_lA", "_links": { "self": { "href": "https://api.github.com/enterprises/enterprise/actions/policies/1" }, "html": { "href": "https://github.com/enterprises/enterprise/settings/policies/actions/1" } }, "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }, { "id": 2, "name": "Restrict workflow events", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "evaluate", "node_id": "RUL_lB", "_links": { "self": { "href": "https://api.github.com/enterprises/enterprise/actions/policies/2" }, "html": { "href": "https://github.com/enterprises/enterprise/settings/policies/actions/2" } }, "created_at": "2024-01-15T11:00:00Z", "updated_at": "2024-01-15T11:00:00Z" } ] }

Create a repository Actions policy

Create an Actions policy for a repository. Omitting workflow_path targets all workflows without storing an explicit condition.

Feinkörnige Zugriffstoken für "Create a repository Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" repository permissions (write)

Parameter für "Create a repository Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
owner string Erforderlich

The account owner of the repository. The name is not case sensitive.

repo string Erforderlich

The name of the repository without the .git extension. The name is not case sensitive.

Körperparameter
Name, Typ, BESCHREIBUNG
name string Erforderlich

The name of the policy.

enforcement string Erforderlich

The enforcement level of the ruleset. evaluate allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (evaluate is only available with GitHub Enterprise).

Kann eine der folgenden sein: disabled, active, evaluate

conditions object

Conditions for a repository Actions policy. The object may be empty to preserve or use the default workflow targeting, or contain only workflow_path.

Name, Typ, BESCHREIBUNG
object
Actions policy workflow path condition object

Parameters for an Actions policy workflow path condition. Omitting workflow_path when creating a policy targets all workflows without storing an explicit condition. Omitting it when updating a policy preserves the existing workflow targeting. For new or changed workflow conditions, the API requires at least one included or excluded pattern. This is validated server-side rather than by this schema, which can also describe existing stored conditions.

Name, Typ, BESCHREIBUNG
workflow_path object Erforderlich
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

rules array of objects

An array of rules within the policy.

Name, Typ, BESCHREIBUNG
restrict_actions_actors object

Choose specific actors that are authorized to trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_actions_actors

parameters object
Name, Typ, BESCHREIBUNG
allowed_actors array of objects Erforderlich

Select the actors who can run Actions workflows.

Name, Typ, BESCHREIBUNG
id integer Erforderlich

ID of the actor authorized to trigger Actions workflows.

type string Erforderlich

The type of the actor

Kann eine der folgenden sein: User, Bot, Team, BusinessTeam, EnterpriseTeam, IntegrationInstallation, App, RepositoryRole

restrict_action_events object

Choose specific GitHub events that will trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_action_events

parameters object
Name, Typ, BESCHREIBUNG
allowed_events array of strings Erforderlich

Select the events that can trigger Actions workflows. Supported values are: branch_protection_rule, check_run, check_suite, create, delete, deployment, deployment_status, discussion, discussion_comment, fork, gollum, image_version, issue_comment, issues, label, merge_group, milestone, page_build, project, project_card, project_column, public, pull_request, pull_request_review, pull_request_review_comment, pull_request_target, push, registry_package, release, repository_dispatch, schedule, status, watch, workflow_call, workflow_dispatch, workflow_run

HTTP-Antwortstatuscodes für "Create a repository Actions policy"

StatuscodeBESCHREIBUNG
201

Created

404

Resource not found

422

Validation failed, or the endpoint has been spammed.

500

Internal Error

Codebeispiele für "Create a repository Actions policy"

Anforderungsbeispiel

post/repos/{owner}/{repo}/actions/policies
curl -L \ -X POST \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/repos/OWNER/REPO/actions/policies \ -d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'

Response

Status: 201
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Get a repository Actions policy

Get a specific Actions policy for a repository.

Feinkörnige Zugriffstoken für "Get a repository Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" repository permissions (write)

Parameter für "Get a repository Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
owner string Erforderlich

The account owner of the repository. The name is not case sensitive.

repo string Erforderlich

The name of the repository without the .git extension. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

HTTP-Antwortstatuscodes für "Get a repository Actions policy"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

500

Internal Error

Codebeispiele für "Get a repository Actions policy"

Anforderungsbeispiel

get/repos/{owner}/{repo}/actions/policies/{policy_id}
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_ID

Response

Status: 200
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Update a repository Actions policy

Update an Actions policy for a repository. Omitting workflow_path preserves the policy's existing workflow targeting.

Feinkörnige Zugriffstoken für "Update a repository Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" repository permissions (write)

Parameter für "Update a repository Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
owner string Erforderlich

The account owner of the repository. The name is not case sensitive.

repo string Erforderlich

The name of the repository without the .git extension. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

Körperparameter
Name, Typ, BESCHREIBUNG
name string

The name of the policy.

enforcement string

The enforcement level of the ruleset. evaluate allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (evaluate is only available with GitHub Enterprise).

Kann eine der folgenden sein: disabled, active, evaluate

conditions object

Conditions for a repository Actions policy. The object may be empty to preserve or use the default workflow targeting, or contain only workflow_path.

Name, Typ, BESCHREIBUNG
object
Actions policy workflow path condition object

Parameters for an Actions policy workflow path condition. Omitting workflow_path when creating a policy targets all workflows without storing an explicit condition. Omitting it when updating a policy preserves the existing workflow targeting. For new or changed workflow conditions, the API requires at least one included or excluded pattern. This is validated server-side rather than by this schema, which can also describe existing stored conditions.

Name, Typ, BESCHREIBUNG
workflow_path object Erforderlich
Name, Typ, BESCHREIBUNG
include array of strings Erforderlich

Array of workflow file paths or glob patterns to include. An empty array includes all workflows not matched by an excluded pattern. Use ~ALL by itself to include all workflows. ~ALL cannot be combined with other included patterns.

exclude array of strings Erforderlich

Array of workflow file paths or glob patterns to exclude. The condition will not pass if any of these patterns match. ~ALL is not allowed in this array.

rules array of objects

An array of rules within the policy.

Name, Typ, BESCHREIBUNG
restrict_actions_actors object

Choose specific actors that are authorized to trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_actions_actors

parameters object
Name, Typ, BESCHREIBUNG
allowed_actors array of objects Erforderlich

Select the actors who can run Actions workflows.

Name, Typ, BESCHREIBUNG
id integer Erforderlich

ID of the actor authorized to trigger Actions workflows.

type string Erforderlich

The type of the actor

Kann eine der folgenden sein: User, Bot, Team, BusinessTeam, EnterpriseTeam, IntegrationInstallation, App, RepositoryRole

restrict_action_events object

Choose specific GitHub events that will trigger Actions workflows.

Name, Typ, BESCHREIBUNG
type string Erforderlich

Wert: restrict_action_events

parameters object
Name, Typ, BESCHREIBUNG
allowed_events array of strings Erforderlich

Select the events that can trigger Actions workflows. Supported values are: branch_protection_rule, check_run, check_suite, create, delete, deployment, deployment_status, discussion, discussion_comment, fork, gollum, image_version, issue_comment, issues, label, merge_group, milestone, page_build, project, project_card, project_column, public, pull_request, pull_request_review, pull_request_review_comment, pull_request_target, push, registry_package, release, repository_dispatch, schedule, status, watch, workflow_call, workflow_dispatch, workflow_run

HTTP-Antwortstatuscodes für "Update a repository Actions policy"

StatuscodeBESCHREIBUNG
200

OK

404

Resource not found

422

Validation failed, or the endpoint has been spammed.

500

Internal Error

Codebeispiele für "Update a repository Actions policy"

Anforderungsbeispiel

put/repos/{owner}/{repo}/actions/policies/{policy_id}
curl -L \ -X PUT \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_ID \ -d '{"name":"Updated policy name","enforcement":"active"}'

Response

Status: 200
{ "id": 1, "name": "Restrict workflow modifications", "target": "actions", "source_type": "Enterprise", "source": "enterprise", "enforcement": "active", "conditions": { "organization_name": { "include": [ "octo-org" ], "exclude": [] }, "repository_name": { "include": [ "octo-repo" ], "exclude": [] } }, "rules": [ { "type": "restrict_actions_actors", "parameters": { "allowed_actors": [ { "id": 5, "type": "User" }, { "id": 1234, "type": "Team" } ] } } ], "node_id": "RUL_lA", "created_at": "2024-01-15T10:30:00Z", "updated_at": "2024-01-15T10:30:00Z" }

Delete a repository Actions policy

Delete an Actions policy for a repository.

Feinkörnige Zugriffstoken für "Delete a repository Actions policy"

Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:

Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:

  • "Administration" repository permissions (write)

Parameter für "Delete a repository Actions policy"

Header
Name, Typ, BESCHREIBUNG
accept string

Setting to application/vnd.github+json is recommended.

Pfadparameter
Name, Typ, BESCHREIBUNG
owner string Erforderlich

The account owner of the repository. The name is not case sensitive.

repo string Erforderlich

The name of the repository without the .git extension. The name is not case sensitive.

policy_id integer Erforderlich

The ID of the policy.

HTTP-Antwortstatuscodes für "Delete a repository Actions policy"

StatuscodeBESCHREIBUNG
204

No Content

404

Resource not found

500

Internal Error

Codebeispiele für "Delete a repository Actions policy"

Anforderungsbeispiel

delete/repos/{owner}/{repo}/actions/policies/{policy_id}
curl -L \ -X DELETE \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_ID

Response

Status: 204