How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

GitHub Permissions API

The Permissions API from GitHub — 10 operation(s) for permissions.

GitHub Permissions API is one of 350 APIs that GitHub publishes on the APIs.io network, described by a machine-readable OpenAPI specification and an AsyncAPI event-driven specification.

Tagged areas include Permissions. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an AsyncAPI specification, and an API reference.

This API exposes 18 operations across 10 paths, and defines 20 schemas. It is described by OpenAPI 3.2.0, at version 1.1.4.

Requests are made against 2 base URLs: {protocol}://{hostname}/api/v3, {protocol}://{hostname}.

18 operations 10 paths 20 schemas 10 GET8 PUT

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.2.0
API Version
1.1.4
Base URL
https://api.github.com
Authentication
HTTP Bearer
License
Terms of Service
Resource Areas
1

Authentication & Security 1

GitHub Permissions API declares 1 security scheme for authenticating requests. It accepts HTTP bearer tokens (bearerHttpAuthentication).

  • bearerHttpAuthentication — Bearer Token

Paths & Operations 18

Across 10 paths, the API surfaces 18 operations — 10 GET, 8 PUT. Each is listed below with its method, path, parameters, and response codes.

Permissions 18
GET
/orgs/{org}/actions/permissions
GitHub Get Github Actions Permissions for an Organization
getGithubActionsPermissionsForAnOrganization 1 param → 200
PUT
/orgs/{org}/actions/permissions
GitHub Set Github Actions Permissions for an Organization
setGithubActionsPermissionsForAnOrganization 1 param body → 204
GET
/orgs/{org}/actions/permissions/workflow
GitHub Get Default Workflow Permissions for an Organization
getDefaultWorkflowPermissionsForAnOrganization 1 param → 200
PUT
/orgs/{org}/actions/permissions/workflow
GitHub Set Default Workflow Permissions for an Organization
setDefaultWorkflowPermissionsForAnOrganization 1 param body → 204409
GET
/orgs/{org}/repository-fine-grained-permissions
GitHub List Repository Fine-grained Permissions for an Organization
listRepositoryFinegrainedPermissionsForAnOrganization 1 param → 200
GET
/orgs/{org}/teams/{team_slug}/projects/{project_id}
GitHub Check Team Permissions for Project
checkTeamPermissionsForProject 3 params → 200404
PUT
/orgs/{org}/teams/{team_slug}/projects/{project_id}
GitHub Add or Update Team Project Permissions
addOrUpdateTeamProjectPermissions 3 params body → 204403
GET
/orgs/{org}/teams/{team_slug}/repos/{owner}/{repo}
GitHub Check Team Permissions for Repository
checkTeamPermissionsForRepository 4 params → 200204404
PUT
/orgs/{org}/teams/{team_slug}/repos/{owner}/{repo}
GitHub Add or Update Team Repository Permissions
addOrUpdateTeamRepositoryPermissions 4 params body → 204
GET
/teams/{team_id}/projects/{project_id}deprecated
GitHub Check Team Permissions for Project (legacy)
checkTeamPermissionsForProjectLegacy 2 params → 200404
PUT
/teams/{team_id}/projects/{project_id}deprecated
GitHub Add or Update Team Project Permissions (legacy)
addOrUpdateTeamProjectPermissionsLegacy 2 params body → 204403404422
GET
/repos/{owner}/{repo}/actions/permissions
GitHub Get Github Actions Permissions for Repository
getGithubActionsPermissionsForRepository 5 params → 200
PUT
/repos/{owner}/{repo}/actions/permissions
GitHub Set Github Actions Permissions for Repository
setGithubActionsPermissionsForRepository 5 params body → 204
GET
/repos/{owner}/{repo}/actions/permissions/workflow
GitHub Get Default Workflow Permissions for Repository
getDefaultWorkflowPermissionsForRepository 5 params → 200
PUT
/repos/{owner}/{repo}/actions/permissions/workflow
GitHub Set Default Workflow Permissions for Repository
setDefaultWorkflowPermissionsForRepository 5 params body → 204409
GET
/repos/{owner}/{repo}/collaborators/{username}/permission
GitHub Get Repository Permissions for User
getRepositoryPermissionsForUser 6 params → 200404
GET
/teams/{team_id}/repos/{owner}/{repo}deprecated
GitHub Check Team Permissions for Repository (legacy)
checkTeamPermissionsForRepositoryLegacy 3 params → 200204404
PUT
/teams/{team_id}/repos/{owner}/{repo}deprecated
GitHub Add or Update Team Repository Permissions (legacy)
addOrUpdateTeamRepositoryPermissionsLegacy 3 params body → 204403422

Schemas 20

The contract defines 20 schemas that model the data the API accepts and returns. The most detailed are team-repository (89 properties), nullable-collaborator (22 properties), simple-user (21 properties), nullable-simple-user (21 properties). Each schema is shown below with its type and property counts.

actions-get-default-workflow-permissions
object
2 properties 2 required
simple-user
object
A GitHub user.
21 properties 18 required
actions-can-approve-pull-request-reviews
boolean
Whether GitHub Actions can approve pull requests. Enabling this can be a security risk.
actions-default-workflow-permissions
string
The default workflow permissions granted to the GITHUBTOKEN when running workflows.
selected-actions-url
string
The API URL to use to get or set the actions that are allowed to run, when allowedactions is set to selected.
allowed-actions
string
The permissions policy that controls the actions that are allowed to run.
actions-organization-permissions
object
4 properties 1 required
repository-fine-grained-permission
object
A fine-grained permission that protects repository resources.
2 properties 2 required
enabled-repositories
string
The policy that controls the repositories in the organization that are allowed to run GitHub Actions.
nullable-simple-user
objectnull
A GitHub user.
21 properties 18 required
team-repository
object
A team's access to a repository.
89 properties 73 required
team-project
object
A team's access to a project.
16 properties 14 required
nullable-license-simple
objectnull
License Simple
6 properties 5 required
actions-set-default-workflow-permissions
object
2 properties
validation-error
object
Validation Error
3 properties 2 required
basic-error
object
Basic Error
4 properties
actions-enabled
boolean
Whether GitHub Actions is enabled on the repository.
actions-repository-permissions
object
3 properties 1 required
nullable-collaborator
object
Collaborator
22 properties 18 required
repository-collaborator-permission
object
Repository Collaborator Permission
3 properties 3 required

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

github-permissions-api-openapi.yml Raw ↑

Other APIs GitHub publishes across the network.

GitHub Events API
GitHub Feeds API
GitHub Gists API
GitHub Issues API
GitHub Licenses API
GitHub Markdown API
GitHub Meta API
GitHub Notifications API
GitHub Octocat API
GitHub Projects API
GitHub Repos API
GitHub Search API
Where this information came from

This is an independent, third-party profile of GitHub Permissions API, published by API Evangelist. We do not operate, host, resell, or support these APIs, and we are not affiliated with or endorsed by the company unless stated above. Everything here is built from publicly available information — the company's own site, developer portal, documentation, public repositories, and the specifications it publishes for public use. Nothing is obtained by breaching a system, defeating an access control, or using credentials.

The Kin Score and Agent Readiness rating are independently calculated assessments of a company's public API artifacts, scored against a published rubric. They are not certifications, endorsements, security assessments, or audits.

Corrections, re-scores, and removal are free — no partnership or purchase required, and you do not need to justify the request. A removed company is recorded as unrated, never scored zero for having asked. Acknowledgement within one business day; removal within two.

info@apievangelist.com · Read the full data-sourcing policy →
On a security or compliance team? Put security in the subject line and you will get a person, not a form — we will tell you exactly which public URLs this profile was built from.