apicheats.dev github/llms.txt Raw .md
POST

POST /repos/{owner}/{repo}/actions/policies — GitHub API

GitHub token (required); https://api.github.com

GitHub API

Create a repository Actions policy

Base URL
https://api.github.com
Auth
Authorization: Bearer <GITHUB_API_KEY>
Last verified
2026-09-18 · upstream hash matched
Actions Try in browser
Agents: curl -H "Accept: text/markdown" this URL
→ 319 tokens · Vary: Accept

Critical gotchas

GitHub recommends an Accept: application/vnd.github+json header and an explicit X-GitHub-Api-Version header.

Fine-grained tokens only authorize repositories and permissions selected when the token is created.

cURL

curl -X POST 'https://api.github.com/repos/example-owner/example-repo/actions/policies' \  -H "Authorization: Bearer $GITHUB_TOKEN" \  -H 'Accept: application/vnd.github+json' \  -H 'X-GitHub-Api-Version: 2026-03-10' \  -H 'Content-Type: application/json' \  -d '{  "name": "example-name",  "enforcement": "disabled"}'

Parameters

Name In Type Required Description
owner path string Yes The account owner of the repository. The name is not case sensitive.
repo path string Yes The name of the repository without the `.git` extension. The name is not case sensitive.
name body string Yes The name of the policy.
enforcement body string Yes The enforcement level of the ruleset. `evaluate` allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (`evaluate` is only available with GitHub Enterprise).
conditions body object No Conditions for a repository Actions policy. The object may be empty to preserve or use the default workflow targeting, or contain only `workflow_path`.
rules body object[] No An array of rules within the policy.

Response 200 OK

{
  "id": 0,
  "name": "string",
  "target": "actions",
  "source_type": "Repository",
  "source": "string",
  "enforcement": "disabled",
  "conditions": {},
  "rules": [
    {
      "type": "restrict_actions_actors",
      "parameters": {
        "allowed_actors": [
          {
            "id": "[recursive or deeply nested schema]",
            "type": "[recursive or deeply nested schema]"
          }
        ]
      }
    }
  ],
  "node_id": "string",
  "_links": {
    "self": {
      "href": "string"
    },
    "html": {
      "href": "string"
    }
  },
  "created_at": "2026-09-03T00:00:00Z",
  "updated_at": "2026-09-03T00:00:00Z"
}
Get a free GitHub API key → sponsored