GitHub · Authentication
Fine-grained repository permissions
Fine-grained personal access tokens limit access to one owner, selected repositories, and specific permissions. Use this list to choose only what your command or integration needs.
GitHub may show extra permissions for enabled or preview features. Most permissions offer read or read and write access; Metadata stays read-only, and Workflows is write-only.
Repository permissions
36 permissions- Actions
- View or manage workflow runs, jobs, artifacts, caches, and repository runners.
- Administration
- Manage repository settings, access, rules, visibility, transfer, or deletion.
- Agent secrets
- Manage encrypted secrets used by GitHub Copilot coding agents.
- Agent tasks
- Create, view, and manage tasks assigned to GitHub Copilot coding agents.
- Agent variables
- Manage non-secret variables used by GitHub Copilot coding agents.
- Artifact metadata
- Read or create storage and deployment records for published artifacts.
- Attestations
- Read or create artifact provenance and software supply-chain attestations.
- Code quality
- View code-quality and maintainability findings.
- Code scanning alerts
- View or manage CodeQL and other code-scanning security findings.
- Codespaces
- Create, start, stop, and manage Codespaces for the repository.
- Codespaces lifecycle admin
- Administer the lifecycle of repository Codespaces, including forced stop or deletion.
- Codespaces metadata
- View Codespace names, state, machine, owner, and other metadata.
- Codespaces secrets
- Manage encrypted secrets available inside Codespaces.
- Commit statuses
- Read or post pending, success, error, and failure statuses on commits.
- Contents
- Read or change code, files, commits, branches, tags, and releases. Write access allows pushes.
- Copilot agent settings
- View GitHub Copilot coding-agent configuration for the repository.
- Custom properties
- Read or set organization-defined property values on the repository.
- Dependabot alerts
- View or manage alerts for vulnerable dependencies.
- Dependabot secrets
- Manage encrypted secrets Dependabot uses to access private registries.
- Deployments
- Read or create deployments and update their statuses.
- Discussions
- Read or manage discussions, comments, answers, and moderation.
- Environments
- Manage deployment environments, protection rules, secrets, and variables.
- Issues
- Read or manage issues, comments, labels, milestones, and assignees.
- License compliance alerts
- View or manage alerts for dependencies that violate license policies.
- Merge queues
- View or manage pull requests in a repository merge queue.
- Metadata
- Read basic repository information. GitHub includes this permission automatically.
- Pages
- Read or manage GitHub Pages configuration, builds, domains, and deployments.
- Pull requests
- Read or manage pull requests, reviews, comments, and requested reviewers.
- Repository security advisories
- Read, draft, update, and publish private vulnerability advisories.
- Secret scanning alert dismissal requests
- Review requests to dismiss secret-scanning alerts.
- Secret scanning alerts
- View or manage alerts for credentials detected in repository history.
- Secret scanning push protection bypass requests
- Review requests to bypass secret scanning when pushing detected credentials.
- Secrets
- Manage encrypted secrets used by GitHub Actions workflows.
- Variables
- Manage non-secret variables used by GitHub Actions workflows.
- Webhooks
- Read or manage repository webhooks and delivery attempts.
- Workflows
- Change files in
.github/workflows. This permission is write-only.