REST API endpoints for GitHub Actions policies
Use the REST API to view and manage policies for GitHub Actions.
List organization Actions policies
List all Actions policies for an organization.
Feinkörnige Zugriffstoken für "List organization Actions policies"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" organization permissions (write)
Parameter für "List organization Actions policies"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
org string ErforderlichThe organization name. The name is not case sensitive. |
| Name, Typ, BESCHREIBUNG |
|---|
per_page integer The number of results per page (max 100). For more information, see "Using pagination in the REST API." Standard: |
page integer The page number of the results to fetch. For more information, see "Using pagination in the REST API." Standard: |
has_parents boolean Include policies configured at higher levels that apply to this organization Standard: |
HTTP-Antwortstatuscodes für "List organization Actions policies"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "List organization Actions policies"
Anforderungsbeispiel
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policiesResponse
Status: 200{
"total_count": 2,
"policies": [
{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"node_id": "RUL_lA",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/1"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/1"
}
},
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
},
{
"id": 2,
"name": "Restrict workflow events",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "evaluate",
"node_id": "RUL_lB",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/2"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/2"
}
},
"created_at": "2024-01-15T11:00:00Z",
"updated_at": "2024-01-15T11:00:00Z"
}
]
}Create an organization Actions policy
Create an Actions policy for an organization.
Omitting workflow_path targets all workflows without storing an explicit condition.
Feinkörnige Zugriffstoken für "Create an organization Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" organization permissions (write)
Parameter für "Create an organization Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
org string ErforderlichThe organization name. The name is not case sensitive. |
| Name, Typ, BESCHREIBUNG | ||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string ErforderlichThe name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string ErforderlichThe enforcement level of the ruleset. Kann eine der folgenden sein: | ||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an organization Actions policy. The conditions object should contain one of
| ||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
workflow_path object Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository IDs object Parameters for a repository ID condition
Properties of Repository ruleset conditions for repository IDs
| Name, Typ, BESCHREIBUNG | |||
|---|---|---|---|
repository_id object Erforderlich | |||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
repository_ids array of integers The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
workflow_path object Properties of workflow_path
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository properties object Parameters for a repository property condition
Properties of Repository ruleset conditions for repository properties
| Name, Typ, BESCHREIBUNG | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
repository_property object Erforderlich | |||||||||||||
Properties of |
| Name, Typ, BESCHREIBUNG | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
name string ErforderlichThe name of the repository property to target |
property_values array of strings ErforderlichThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Kann eine der folgenden sein: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Name, Typ, BESCHREIBUNG |
|---|
name string ErforderlichThe name of the repository property to target |
property_values array of strings ErforderlichThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Kann eine der folgenden sein: |
workflow_path object Properties of workflow_path
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Name, Typ, BESCHREIBUNG | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Name, Typ, BESCHREIBUNG | ||||||
|---|---|---|---|---|---|---|
type string ErforderlichWert: | ||||||
parameters object | ||||||
Properties of |
| Name, Typ, BESCHREIBUNG | |||
|---|---|---|---|
allowed_actors array of objects ErforderlichSelect the actors who can run Actions workflows. | |||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
id integer ErforderlichID of the actor authorized to trigger Actions workflows. |
type string ErforderlichThe type of the actor Kann eine der folgenden sein: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Name, Typ, BESCHREIBUNG | ||
|---|---|---|
type string ErforderlichWert: | ||
parameters object | ||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
allowed_events array of strings ErforderlichSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-Antwortstatuscodes für "Create an organization Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
201 | Created |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Codebeispiele für "Create an organization Actions policy"
Anforderungsbeispiel
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies \
-d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'Response
Status: 201{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Get an organization Actions policy
Get a specific Actions policy for an organization.
Feinkörnige Zugriffstoken für "Get an organization Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" organization permissions (write)
Parameter für "Get an organization Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
org string ErforderlichThe organization name. The name is not case sensitive. |
policy_id integer ErforderlichThe ID of the policy. |
HTTP-Antwortstatuscodes für "Get an organization Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "Get an organization Actions policy"
Anforderungsbeispiel
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_IDResponse
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Update an organization Actions policy
Update an Actions policy for an organization.
Omitting workflow_path preserves the policy's existing workflow targeting.
Feinkörnige Zugriffstoken für "Update an organization Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" organization permissions (write)
Parameter für "Update an organization Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
org string ErforderlichThe organization name. The name is not case sensitive. |
policy_id integer ErforderlichThe ID of the policy. |
| Name, Typ, BESCHREIBUNG | ||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string The name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string The enforcement level of the ruleset. Kann eine der folgenden sein: | ||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an organization Actions policy. The conditions object should contain one of
| ||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
workflow_path object Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository IDs object Parameters for a repository ID condition
Properties of Repository ruleset conditions for repository IDs
| Name, Typ, BESCHREIBUNG | |||
|---|---|---|---|
repository_id object Erforderlich | |||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
repository_ids array of integers The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
workflow_path object Properties of workflow_path
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository properties object Parameters for a repository property condition
Properties of Repository ruleset conditions for repository properties
| Name, Typ, BESCHREIBUNG | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
repository_property object Erforderlich | |||||||||||||
Properties of |
| Name, Typ, BESCHREIBUNG | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
name string ErforderlichThe name of the repository property to target |
property_values array of strings ErforderlichThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Kann eine der folgenden sein: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Name, Typ, BESCHREIBUNG |
|---|
name string ErforderlichThe name of the repository property to target |
property_values array of strings ErforderlichThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Kann eine der folgenden sein: |
workflow_path object Properties of workflow_path
| Name, Typ, BESCHREIBUNG |
|---|
include array of strings ErforderlichArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings ErforderlichArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Name, Typ, BESCHREIBUNG | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Name, Typ, BESCHREIBUNG | ||||||
|---|---|---|---|---|---|---|
type string ErforderlichWert: | ||||||
parameters object | ||||||
Properties of |
| Name, Typ, BESCHREIBUNG | |||
|---|---|---|---|
allowed_actors array of objects ErforderlichSelect the actors who can run Actions workflows. | |||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
id integer ErforderlichID of the actor authorized to trigger Actions workflows. |
type string ErforderlichThe type of the actor Kann eine der folgenden sein: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Name, Typ, BESCHREIBUNG | ||
|---|---|---|
type string ErforderlichWert: | ||
parameters object | ||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
allowed_events array of strings ErforderlichSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-Antwortstatuscodes für "Update an organization Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Codebeispiele für "Update an organization Actions policy"
Anforderungsbeispiel
curl -L \
-X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_ID \
-d '{"name":"Updated policy name","enforcement":"active"}'Response
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Delete an organization Actions policy
Delete an Actions policy for an organization.
Feinkörnige Zugriffstoken für "Delete an organization Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" organization permissions (write)
Parameter für "Delete an organization Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
org string ErforderlichThe organization name. The name is not case sensitive. |
policy_id integer ErforderlichThe ID of the policy. |
HTTP-Antwortstatuscodes für "Delete an organization Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
204 | No Content |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "Delete an organization Actions policy"
Anforderungsbeispiel
curl -L \
-X DELETE \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_IDResponse
Status: 204List repository Actions policies
List all Actions policies for a repository.
Feinkörnige Zugriffstoken für "List repository Actions policies"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" repository permissions (write)
Parameter für "List repository Actions policies"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
owner string ErforderlichThe account owner of the repository. The name is not case sensitive. |
repo string ErforderlichThe name of the repository without the |
| Name, Typ, BESCHREIBUNG |
|---|
per_page integer The number of results per page (max 100). For more information, see "Using pagination in the REST API." Standard: |
page integer The page number of the results to fetch. For more information, see "Using pagination in the REST API." Standard: |
has_parents boolean Include policies configured at higher levels that apply to this repository Standard: |
HTTP-Antwortstatuscodes für "List repository Actions policies"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "List repository Actions policies"
Anforderungsbeispiel
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policiesResponse
Status: 200{
"total_count": 2,
"policies": [
{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"node_id": "RUL_lA",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/1"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/1"
}
},
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
},
{
"id": 2,
"name": "Restrict workflow events",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "evaluate",
"node_id": "RUL_lB",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/2"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/2"
}
},
"created_at": "2024-01-15T11:00:00Z",
"updated_at": "2024-01-15T11:00:00Z"
}
]
}Create a repository Actions policy
Create an Actions policy for a repository.
Omitting workflow_path targets all workflows without storing an explicit condition.
Feinkörnige Zugriffstoken für "Create a repository Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" repository permissions (write)
Parameter für "Create a repository Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
owner string ErforderlichThe account owner of the repository. The name is not case sensitive. |
repo string ErforderlichThe name of the repository without the |
| Name, Typ, BESCHREIBUNG | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string ErforderlichThe name of the policy. | |||||||||||||||||||||
enforcement string ErforderlichThe enforcement level of the ruleset. Kann eine der folgenden sein: | |||||||||||||||||||||
conditions object Conditions for a repository Actions policy. The object may be empty to preserve or use the
default workflow targeting, or contain only | |||||||||||||||||||||
Can be one of these objects:
| |||||||||||||||||||||
rules array of objects An array of rules within the policy. | |||||||||||||||||||||
Can be one of these objects:
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows. Properties of |
| Name, Typ, BESCHREIBUNG | ||
|---|---|---|
type string ErforderlichWert: | ||
parameters object | ||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
allowed_events array of strings ErforderlichSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-Antwortstatuscodes für "Create a repository Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
201 | Created |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Codebeispiele für "Create a repository Actions policy"
Anforderungsbeispiel
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies \
-d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'Response
Status: 201{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Get a repository Actions policy
Get a specific Actions policy for a repository.
Feinkörnige Zugriffstoken für "Get a repository Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" repository permissions (write)
Parameter für "Get a repository Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
owner string ErforderlichThe account owner of the repository. The name is not case sensitive. |
repo string ErforderlichThe name of the repository without the |
policy_id integer ErforderlichThe ID of the policy. |
HTTP-Antwortstatuscodes für "Get a repository Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "Get a repository Actions policy"
Anforderungsbeispiel
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_IDResponse
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Update a repository Actions policy
Update an Actions policy for a repository.
Omitting workflow_path preserves the policy's existing workflow targeting.
Feinkörnige Zugriffstoken für "Update a repository Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" repository permissions (write)
Parameter für "Update a repository Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
owner string ErforderlichThe account owner of the repository. The name is not case sensitive. |
repo string ErforderlichThe name of the repository without the |
policy_id integer ErforderlichThe ID of the policy. |
| Name, Typ, BESCHREIBUNG | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string The name of the policy. | |||||||||||||||||||||
enforcement string The enforcement level of the ruleset. Kann eine der folgenden sein: | |||||||||||||||||||||
conditions object Conditions for a repository Actions policy. The object may be empty to preserve or use the
default workflow targeting, or contain only | |||||||||||||||||||||
Can be one of these objects:
| |||||||||||||||||||||
rules array of objects An array of rules within the policy. | |||||||||||||||||||||
Can be one of these objects:
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows. Properties of |
| Name, Typ, BESCHREIBUNG | ||
|---|---|---|
type string ErforderlichWert: | ||
parameters object | ||
Properties of |
| Name, Typ, BESCHREIBUNG |
|---|
allowed_events array of strings ErforderlichSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-Antwortstatuscodes für "Update a repository Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
200 | OK |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Codebeispiele für "Update a repository Actions policy"
Anforderungsbeispiel
curl -L \
-X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_ID \
-d '{"name":"Updated policy name","enforcement":"active"}'Response
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Delete a repository Actions policy
Delete an Actions policy for a repository.
Feinkörnige Zugriffstoken für "Delete a repository Actions policy"
Dieser Endpunkt funktioniert mit den folgenden differenzierten Tokentypen.:
- GitHub App-Benutzerzugriffstoken
- GitHub-App-Installations-Zugriffstoken
- Feingranulare persönliche Zugriffstoken
Das differenzierte Token muss über den folgenden Berechtigungssatz verfügen.:
- "Administration" repository permissions (write)
Parameter für "Delete a repository Actions policy"
| Name, Typ, BESCHREIBUNG |
|---|
accept string Setting to |
| Name, Typ, BESCHREIBUNG |
|---|
owner string ErforderlichThe account owner of the repository. The name is not case sensitive. |
repo string ErforderlichThe name of the repository without the |
policy_id integer ErforderlichThe ID of the policy. |
HTTP-Antwortstatuscodes für "Delete a repository Actions policy"
| Statuscode | BESCHREIBUNG |
|---|---|
204 | No Content |
404 | Resource not found |
500 | Internal Error |
Codebeispiele für "Delete a repository Actions policy"
Anforderungsbeispiel
curl -L \
-X DELETE \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_IDResponse
Status: 204