GitHub · Authentication

Fine-grained repository permissions

Fine-grained personal access tokens limit access to one owner, selected repositories, and specific permissions. Use this list to choose only what your command or integration needs.

GitHub may show extra permissions for enabled or preview features. Most permissions offer read or read and write access; Metadata stays read-only, and Workflows is write-only.

Repository permissions

36 permissions
Actions
View or manage workflow runs, jobs, artifacts, caches, and repository runners.
Administration
Manage repository settings, access, rules, visibility, transfer, or deletion.
Agent secrets
Manage encrypted secrets used by GitHub Copilot coding agents.
Agent tasks
Create, view, and manage tasks assigned to GitHub Copilot coding agents.
Agent variables
Manage non-secret variables used by GitHub Copilot coding agents.
Artifact metadata
Read or create storage and deployment records for published artifacts.
Attestations
Read or create artifact provenance and software supply-chain attestations.
Code quality
View code-quality and maintainability findings.
Code scanning alerts
View or manage CodeQL and other code-scanning security findings.
Codespaces
Create, start, stop, and manage Codespaces for the repository.
Codespaces lifecycle admin
Administer the lifecycle of repository Codespaces, including forced stop or deletion.
Codespaces metadata
View Codespace names, state, machine, owner, and other metadata.
Codespaces secrets
Manage encrypted secrets available inside Codespaces.
Commit statuses
Read or post pending, success, error, and failure statuses on commits.
Contents
Read or change code, files, commits, branches, tags, and releases. Write access allows pushes.
Copilot agent settings
View GitHub Copilot coding-agent configuration for the repository.
Custom properties
Read or set organization-defined property values on the repository.
Dependabot alerts
View or manage alerts for vulnerable dependencies.
Dependabot secrets
Manage encrypted secrets Dependabot uses to access private registries.
Deployments
Read or create deployments and update their statuses.
Discussions
Read or manage discussions, comments, answers, and moderation.
Environments
Manage deployment environments, protection rules, secrets, and variables.
Issues
Read or manage issues, comments, labels, milestones, and assignees.
License compliance alerts
View or manage alerts for dependencies that violate license policies.
Merge queues
View or manage pull requests in a repository merge queue.
Metadata
Read basic repository information. GitHub includes this permission automatically.
Pages
Read or manage GitHub Pages configuration, builds, domains, and deployments.
Pull requests
Read or manage pull requests, reviews, comments, and requested reviewers.
Repository security advisories
Read, draft, update, and publish private vulnerability advisories.
Secret scanning alert dismissal requests
Review requests to dismiss secret-scanning alerts.
Secret scanning alerts
View or manage alerts for credentials detected in repository history.
Secret scanning push protection bypass requests
Review requests to bypass secret scanning when pushing detected credentials.
Secrets
Manage encrypted secrets used by GitHub Actions workflows.
Variables
Manage non-secret variables used by GitHub Actions workflows.
Webhooks
Read or manage repository webhooks and delivery attempts.
Workflows
Change files in .github/workflows. This permission is write-only.