REST API endpoints for GitHub Actions policies
Use the REST API to view and manage policies for GitHub Actions.
List enterprise Actions policies
List all Actions policies for an enterprise.
Детализированные токены доступа для «List enterprise Actions policies»
Эта конечная точка работает со следующими точными типами маркеров:
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Enterprise administration" enterprise permissions (write)
Параметры для «List enterprise Actions policies»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
enterprise string Обязательное полеThe slug version of the enterprise name. |
| Имя., Тип, Description |
|---|
per_page integer The number of results per page (max 100). For more information, see "Using pagination in the REST API." По умолчанию.: |
page integer The page number of the results to fetch. For more information, see "Using pagination in the REST API." По умолчанию.: |
HTTP-коды статуса ответа для «List enterprise Actions policies»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «List enterprise Actions policies»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/enterprises/ENTERPRISE/actions/policiesResponse
Status: 200{
"total_count": 2,
"policies": [
{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"node_id": "RUL_lA",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/1"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/1"
}
},
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
},
{
"id": 2,
"name": "Restrict workflow events",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "evaluate",
"node_id": "RUL_lB",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/2"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/2"
}
},
"created_at": "2024-01-15T11:00:00Z",
"updated_at": "2024-01-15T11:00:00Z"
}
]
}Create an enterprise Actions policy
Create an Actions policy for an enterprise.
Omitting workflow_path targets all workflows without storing an explicit condition.
Детализированные токены доступа для «Create an enterprise Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Enterprise administration" enterprise permissions (write)
Параметры для «Create an enterprise Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
enterprise string Обязательное полеThe slug version of the enterprise name. |
| Имя., Тип, Description | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string Обязательное полеThe name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string Обязательное полеThe enforcement level of the ruleset. Возможные значения: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an enterprise Actions policy. The conditions object supports one organization
target ( | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
repository_name object Обязательное полеProperties of |
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_name_and_repository_property object Conditions to target organizations by name and repositories by property
Properties of organization_name_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_name object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description |
|---|
include array of strings Array of organization names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of organization names or patterns to exclude. The condition will not pass if any of these patterns match. |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_id_and_repository_name object Conditions to target organizations by id and repositories by name
Properties of organization_id_and_repository_name
| Имя., Тип, Description | ||||
|---|---|---|---|---|
organization_id object Обязательное поле | ||||
Properties of |
| Имя., Тип, Description |
|---|
organization_ids array of integers The organization IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
repository_name object Обязательное полеProperties of repository_name
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_id_and_repository_property object Conditions to target organizations by id and repositories by property
Properties of organization_id_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_id object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description |
|---|
organization_ids array of integers The organization IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_property_and_repository_name object Conditions to target organizations by property and repositories by name
Properties of organization_property_and_repository_name
| Имя., Тип, Description | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
organization_property object Обязательное поле | |||||||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
include array of objects The organization properties and values to include. All of these properties must match for the condition to pass. | |||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
exclude array of objects The organization properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
repository_name object Обязательное полеProperties of repository_name
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_property_and_repository_property object Conditions to target organizations by property and repositories by property
Properties of organization_property_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_property object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
include array of objects The organization properties and values to include. All of these properties must match for the condition to pass. | |||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
exclude array of objects The organization properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Имя., Тип, Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Имя., Тип, Description | ||||||
|---|---|---|---|---|---|---|
type string Обязательное полезначение: | ||||||
parameters object | ||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
allowed_actors array of objects Обязательное полеSelect the actors who can run Actions workflows. | |||
Properties of |
| Имя., Тип, Description |
|---|
id integer Обязательное полеID of the actor authorized to trigger Actions workflows. |
type string Обязательное полеThe type of the actor Возможные значения: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Create an enterprise Actions policy»
| Код состояния | Description |
|---|---|
201 | Created |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Create an enterprise Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/enterprises/ENTERPRISE/actions/policies \
-d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'Response
Status: 201{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Get an enterprise Actions policy
Get a specific Actions policy for an enterprise.
Детализированные токены доступа для «Get an enterprise Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Enterprise administration" enterprise permissions (write)
Параметры для «Get an enterprise Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
enterprise string Обязательное полеThe slug version of the enterprise name. |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Get an enterprise Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Get an enterprise Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/enterprises/ENTERPRISE/actions/policies/POLICY_IDResponse
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Update an enterprise Actions policy
Update an Actions policy for an enterprise.
Omitting workflow_path preserves the policy's existing workflow targeting.
Детализированные токены доступа для «Update an enterprise Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Enterprise administration" enterprise permissions (write)
Параметры для «Update an enterprise Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
enterprise string Обязательное полеThe slug version of the enterprise name. |
policy_id integer Обязательное полеThe ID of the policy. |
| Имя., Тип, Description | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string The name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string The enforcement level of the ruleset. Возможные значения: | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an enterprise Actions policy. The conditions object supports one organization
target ( | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
repository_name object Обязательное полеProperties of |
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_name_and_repository_property object Conditions to target organizations by name and repositories by property
Properties of organization_name_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_name object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description |
|---|
include array of strings Array of organization names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of organization names or patterns to exclude. The condition will not pass if any of these patterns match. |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_id_and_repository_name object Conditions to target organizations by id and repositories by name
Properties of organization_id_and_repository_name
| Имя., Тип, Description | ||||
|---|---|---|---|---|
organization_id object Обязательное поле | ||||
Properties of |
| Имя., Тип, Description |
|---|
organization_ids array of integers The organization IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
repository_name object Обязательное полеProperties of repository_name
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_id_and_repository_property object Conditions to target organizations by id and repositories by property
Properties of organization_id_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_id object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description |
|---|
organization_ids array of integers The organization IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_property_and_repository_name object Conditions to target organizations by property and repositories by name
Properties of organization_property_and_repository_name
| Имя., Тип, Description | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
organization_property object Обязательное поле | |||||||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
include array of objects The organization properties and values to include. All of these properties must match for the condition to pass. | |||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
exclude array of objects The organization properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
repository_name object Обязательное полеProperties of repository_name
| Имя., Тип, Description |
|---|
include array of strings Array of repository names or patterns to include. One of these patterns must match for the condition to pass. Also accepts |
exclude array of strings Array of repository names or patterns to exclude. The condition will not pass if any of these patterns match. |
protected boolean Whether renaming of target repositories is prevented. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
organization_property_and_repository_property object Conditions to target organizations by property and repositories by property
Properties of organization_property_and_repository_property
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
organization_property object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
include array of objects The organization properties and values to include. All of these properties must match for the condition to pass. | |||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
exclude array of objects The organization properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the organization property to target |
property_values array of strings Обязательное полеThe values to match for the organization property |
repository_property object Обязательное полеProperties of repository_property
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Имя., Тип, Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Имя., Тип, Description | ||||||
|---|---|---|---|---|---|---|
type string Обязательное полезначение: | ||||||
parameters object | ||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
allowed_actors array of objects Обязательное полеSelect the actors who can run Actions workflows. | |||
Properties of |
| Имя., Тип, Description |
|---|
id integer Обязательное полеID of the actor authorized to trigger Actions workflows. |
type string Обязательное полеThe type of the actor Возможные значения: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Update an enterprise Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Update an enterprise Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/enterprises/ENTERPRISE/actions/policies/POLICY_ID \
-d '{"name":"Updated policy name","enforcement":"active"}'Response
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Delete an enterprise Actions policy
Delete an Actions policy for an enterprise.
Детализированные токены доступа для «Delete an enterprise Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Enterprise administration" enterprise permissions (write)
Параметры для «Delete an enterprise Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
enterprise string Обязательное полеThe slug version of the enterprise name. |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Delete an enterprise Actions policy»
| Код состояния | Description |
|---|---|
204 | No Content |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Delete an enterprise Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X DELETE \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/enterprises/ENTERPRISE/actions/policies/POLICY_IDResponse
Status: 204List organization Actions policies
List all Actions policies for an organization.
Детализированные токены доступа для «List organization Actions policies»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" organization permissions (write)
Параметры для «List organization Actions policies»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
org string Обязательное полеThe organization name. The name is not case sensitive. |
| Имя., Тип, Description |
|---|
per_page integer The number of results per page (max 100). For more information, see "Using pagination in the REST API." По умолчанию.: |
page integer The page number of the results to fetch. For more information, see "Using pagination in the REST API." По умолчанию.: |
has_parents boolean Include policies configured at higher levels that apply to this organization По умолчанию.: |
HTTP-коды статуса ответа для «List organization Actions policies»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «List organization Actions policies»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policiesResponse
Status: 200{
"total_count": 2,
"policies": [
{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"node_id": "RUL_lA",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/1"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/1"
}
},
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
},
{
"id": 2,
"name": "Restrict workflow events",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "evaluate",
"node_id": "RUL_lB",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/2"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/2"
}
},
"created_at": "2024-01-15T11:00:00Z",
"updated_at": "2024-01-15T11:00:00Z"
}
]
}Create an organization Actions policy
Create an Actions policy for an organization.
Omitting workflow_path targets all workflows without storing an explicit condition.
Детализированные токены доступа для «Create an organization Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" organization permissions (write)
Параметры для «Create an organization Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
org string Обязательное полеThe organization name. The name is not case sensitive. |
| Имя., Тип, Description | ||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string Обязательное полеThe name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string Обязательное полеThe enforcement level of the ruleset. Возможные значения: | ||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an organization Actions policy. The conditions object should contain one of
| ||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
workflow_path object Properties of |
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository IDs object Parameters for a repository ID condition
Properties of Repository ruleset conditions for repository IDs
| Имя., Тип, Description | |||
|---|---|---|---|
repository_id object Обязательное поле | |||
Properties of |
| Имя., Тип, Description |
|---|
repository_ids array of integers The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository properties object Parameters for a repository property condition
Properties of Repository ruleset conditions for repository properties
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
repository_property object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Имя., Тип, Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Имя., Тип, Description | ||||||
|---|---|---|---|---|---|---|
type string Обязательное полезначение: | ||||||
parameters object | ||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
allowed_actors array of objects Обязательное полеSelect the actors who can run Actions workflows. | |||
Properties of |
| Имя., Тип, Description |
|---|
id integer Обязательное полеID of the actor authorized to trigger Actions workflows. |
type string Обязательное полеThe type of the actor Возможные значения: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Create an organization Actions policy»
| Код состояния | Description |
|---|---|
201 | Created |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Create an organization Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies \
-d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'Response
Status: 201{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Get an organization Actions policy
Get a specific Actions policy for an organization.
Детализированные токены доступа для «Get an organization Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" organization permissions (write)
Параметры для «Get an organization Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
org string Обязательное полеThe organization name. The name is not case sensitive. |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Get an organization Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Get an organization Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_IDResponse
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Update an organization Actions policy
Update an Actions policy for an organization.
Omitting workflow_path preserves the policy's existing workflow targeting.
Детализированные токены доступа для «Update an organization Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" organization permissions (write)
Параметры для «Update an organization Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
org string Обязательное полеThe organization name. The name is not case sensitive. |
policy_id integer Обязательное полеThe ID of the policy. |
| Имя., Тип, Description | ||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string The name of the policy. | ||||||||||||||||||||||||||||||||||||||||||||||||||
enforcement string The enforcement level of the ruleset. Возможные значения: | ||||||||||||||||||||||||||||||||||||||||||||||||||
conditions object Conditions for an organization Actions policy. The conditions object should contain one of
| ||||||||||||||||||||||||||||||||||||||||||||||||||
Can be one of these objects:
workflow_path object Properties of |
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository IDs object Parameters for a repository ID condition
Properties of Repository ruleset conditions for repository IDs
| Имя., Тип, Description | |||
|---|---|---|---|
repository_id object Обязательное поле | |||
Properties of |
| Имя., Тип, Description |
|---|
repository_ids array of integers The repository IDs that the ruleset applies to. One of these IDs must match for the condition to pass. |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
Repository ruleset conditions for repository properties object Parameters for a repository property condition
Properties of Repository ruleset conditions for repository properties
| Имя., Тип, Description | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
repository_property object Обязательное поле | |||||||||||||
Properties of |
| Имя., Тип, Description | ||||
|---|---|---|---|---|
include array of objects The repository properties and values to include. All of these properties must match for the condition to pass. | ||||
Properties of |
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
exclude array of objects The repository properties and values to exclude. The condition will not pass if any of these properties match.
Properties of exclude
| Имя., Тип, Description |
|---|
name string Обязательное полеThe name of the repository property to target |
property_values array of strings Обязательное полеThe values to match for the repository property |
source string The source of the repository property. Defaults to 'custom' if not specified. Возможные значения: |
workflow_path object Properties of workflow_path
| Имя., Тип, Description |
|---|
include array of strings Обязательное полеArray of workflow file paths or glob patterns to include. An empty array includes all
workflows not matched by an excluded pattern. Use |
exclude array of strings Обязательное полеArray of workflow file paths or glob patterns to exclude. The condition will not pass
if any of these patterns match. |
rules array of objects An array of rules within the policy.
Can be one of these objects:
| Имя., Тип, Description | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|
restrict_actions_actors object Choose specific actors that are authorized to trigger Actions workflows. | ||||||||||
Properties of |
| Имя., Тип, Description | ||||||
|---|---|---|---|---|---|---|
type string Обязательное полезначение: | ||||||
parameters object | ||||||
Properties of |
| Имя., Тип, Description | |||
|---|---|---|---|
allowed_actors array of objects Обязательное полеSelect the actors who can run Actions workflows. | |||
Properties of |
| Имя., Тип, Description |
|---|
id integer Обязательное полеID of the actor authorized to trigger Actions workflows. |
type string Обязательное полеThe type of the actor Возможные значения: |
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows.
Properties of restrict_action_events
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Update an organization Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Update an organization Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_ID \
-d '{"name":"Updated policy name","enforcement":"active"}'Response
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Delete an organization Actions policy
Delete an Actions policy for an organization.
Детализированные токены доступа для «Delete an organization Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" organization permissions (write)
Параметры для «Delete an organization Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
org string Обязательное полеThe organization name. The name is not case sensitive. |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Delete an organization Actions policy»
| Код состояния | Description |
|---|---|
204 | No Content |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Delete an organization Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X DELETE \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/actions/policies/POLICY_IDResponse
Status: 204List repository Actions policies
List all Actions policies for a repository.
Детализированные токены доступа для «List repository Actions policies»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" repository permissions (write)
Параметры для «List repository Actions policies»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
owner string Обязательное полеThe account owner of the repository. The name is not case sensitive. |
repo string Обязательное полеThe name of the repository without the |
| Имя., Тип, Description |
|---|
per_page integer The number of results per page (max 100). For more information, see "Using pagination in the REST API." По умолчанию.: |
page integer The page number of the results to fetch. For more information, see "Using pagination in the REST API." По умолчанию.: |
has_parents boolean Include policies configured at higher levels that apply to this repository По умолчанию.: |
HTTP-коды статуса ответа для «List repository Actions policies»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «List repository Actions policies»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policiesResponse
Status: 200{
"total_count": 2,
"policies": [
{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"node_id": "RUL_lA",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/1"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/1"
}
},
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
},
{
"id": 2,
"name": "Restrict workflow events",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "evaluate",
"node_id": "RUL_lB",
"_links": {
"self": {
"href": "https://api.github.com/enterprises/enterprise/actions/policies/2"
},
"html": {
"href": "https://github.com/enterprises/enterprise/settings/policies/actions/2"
}
},
"created_at": "2024-01-15T11:00:00Z",
"updated_at": "2024-01-15T11:00:00Z"
}
]
}Create a repository Actions policy
Create an Actions policy for a repository.
Omitting workflow_path targets all workflows without storing an explicit condition.
Детализированные токены доступа для «Create a repository Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" repository permissions (write)
Параметры для «Create a repository Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
owner string Обязательное полеThe account owner of the repository. The name is not case sensitive. |
repo string Обязательное полеThe name of the repository without the |
| Имя., Тип, Description | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string Обязательное полеThe name of the policy. | |||||||||||||||||||||
enforcement string Обязательное полеThe enforcement level of the ruleset. Возможные значения: | |||||||||||||||||||||
conditions object Conditions for a repository Actions policy. The object may be empty to preserve or use the
default workflow targeting, or contain only | |||||||||||||||||||||
Can be one of these objects:
| |||||||||||||||||||||
rules array of objects An array of rules within the policy. | |||||||||||||||||||||
Can be one of these objects:
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows. Properties of |
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Create a repository Actions policy»
| Код состояния | Description |
|---|---|
201 | Created |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Create a repository Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X POST \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies \
-d '{"name":"Require approved actors","enforcement":"active","rules":[{"type":"restrict_actions_actors","parameters":{"allowed_actors":[{"id":1234,"type":"Team"}]}}]}'Response
Status: 201{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Get a repository Actions policy
Get a specific Actions policy for a repository.
Детализированные токены доступа для «Get a repository Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" repository permissions (write)
Параметры для «Get a repository Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
owner string Обязательное полеThe account owner of the repository. The name is not case sensitive. |
repo string Обязательное полеThe name of the repository without the |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Get a repository Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Get a repository Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_IDResponse
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Update a repository Actions policy
Update an Actions policy for a repository.
Omitting workflow_path preserves the policy's existing workflow targeting.
Детализированные токены доступа для «Update a repository Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" repository permissions (write)
Параметры для «Update a repository Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
owner string Обязательное полеThe account owner of the repository. The name is not case sensitive. |
repo string Обязательное полеThe name of the repository without the |
policy_id integer Обязательное полеThe ID of the policy. |
| Имя., Тип, Description | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
name string The name of the policy. | |||||||||||||||||||||
enforcement string The enforcement level of the ruleset. Возможные значения: | |||||||||||||||||||||
conditions object Conditions for a repository Actions policy. The object may be empty to preserve or use the
default workflow targeting, or contain only | |||||||||||||||||||||
Can be one of these objects:
| |||||||||||||||||||||
rules array of objects An array of rules within the policy. | |||||||||||||||||||||
Can be one of these objects:
restrict_action_events object Choose specific GitHub events that will trigger Actions workflows. Properties of |
| Имя., Тип, Description | ||
|---|---|---|
type string Обязательное полезначение: | ||
parameters object | ||
Properties of |
| Имя., Тип, Description |
|---|
allowed_events array of strings Обязательное полеSelect the events that can trigger Actions workflows.
Supported values are: |
HTTP-коды статуса ответа для «Update a repository Actions policy»
| Код состояния | Description |
|---|---|
200 | OK |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
500 | Internal Error |
Примеры кода для «Update a repository Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X PUT \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_ID \
-d '{"name":"Updated policy name","enforcement":"active"}'Response
Status: 200{
"id": 1,
"name": "Restrict workflow modifications",
"target": "actions",
"source_type": "Enterprise",
"source": "enterprise",
"enforcement": "active",
"conditions": {
"organization_name": {
"include": [
"octo-org"
],
"exclude": []
},
"repository_name": {
"include": [
"octo-repo"
],
"exclude": []
}
},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": 5,
"type": "User"
},
{
"id": 1234,
"type": "Team"
}
]
}
}
],
"node_id": "RUL_lA",
"created_at": "2024-01-15T10:30:00Z",
"updated_at": "2024-01-15T10:30:00Z"
}Delete a repository Actions policy
Delete an Actions policy for a repository.
Детализированные токены доступа для «Delete a repository Actions policy»
Эта конечная точка работает со следующими точными типами маркеров:
- Жетоны доступа пользователей приложения GitHub
- Токены доступа к установке приложений GitHub
- Точные личные маркеры доступа
Маркер с точной детализацией должен иметь следующий набор разрешений.:
- "Administration" repository permissions (write)
Параметры для «Delete a repository Actions policy»
| Имя., Тип, Description |
|---|
accept string Setting to |
| Имя., Тип, Description |
|---|
owner string Обязательное полеThe account owner of the repository. The name is not case sensitive. |
repo string Обязательное полеThe name of the repository without the |
policy_id integer Обязательное полеThe ID of the policy. |
HTTP-коды статуса ответа для «Delete a repository Actions policy»
| Код состояния | Description |
|---|---|
204 | No Content |
404 | Resource not found |
500 | Internal Error |
Примеры кода для «Delete a repository Actions policy»
Если вы получаете доступ к GitHub на GHE.com, замените api.github.com на выделенный поддомен вашего предприятия в api.SUBDOMAIN.ghe.com.
Пример запроса
curl -L \
-X DELETE \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/repos/OWNER/REPO/actions/policies/POLICY_IDResponse
Status: 204