POST
POST /repos/{owner}/{repo}/actions/policies — GitHub API
GitHub token (required); https://api.github.com
GitHub APICreate a repository Actions policy
- Base URL
- https://api.github.com
- Auth
- Authorization: Bearer <GITHUB_API_KEY>
- Last verified
- 2026-09-18 · upstream hash matched
Actions Try in browser→
Agents: curl -H "Accept: text/markdown" this URL
→ 319 tokens · Vary: Accept
→ 319 tokens · Vary: Accept
Critical gotchas
GitHub recommends an Accept: application/vnd.github+json header and an explicit X-GitHub-Api-Version header.
Fine-grained tokens only authorize repositories and permissions selected when the token is created.
cURL
curl -X POST 'https://api.github.com/repos/example-owner/example-repo/actions/policies' \ -H "Authorization: Bearer $GITHUB_TOKEN" \ -H 'Accept: application/vnd.github+json' \ -H 'X-GitHub-Api-Version: 2026-03-10' \ -H 'Content-Type: application/json' \ -d '{ "name": "example-name", "enforcement": "disabled"}'
Parameters
| Name | In | Type | Required | Description |
|---|---|---|---|---|
| owner | path | string | Yes | The account owner of the repository. The name is not case sensitive. |
| repo | path | string | Yes | The name of the repository without the `.git` extension. The name is not case sensitive. |
| name | body | string | Yes | The name of the policy. |
| enforcement | body | string | Yes | The enforcement level of the ruleset. `evaluate` allows admins to test rules before enforcing them. Admins can view insights on the Rule Insights page (`evaluate` is only available with GitHub Enterprise). |
| conditions | body | object | No | Conditions for a repository Actions policy. The object may be empty to preserve or use the default workflow targeting, or contain only `workflow_path`. |
| rules | body | object[] | No | An array of rules within the policy. |
Response 200 OK
{
"id": 0,
"name": "string",
"target": "actions",
"source_type": "Repository",
"source": "string",
"enforcement": "disabled",
"conditions": {},
"rules": [
{
"type": "restrict_actions_actors",
"parameters": {
"allowed_actors": [
{
"id": "[recursive or deeply nested schema]",
"type": "[recursive or deeply nested schema]"
}
]
}
}
],
"node_id": "string",
"_links": {
"self": {
"href": "string"
},
"html": {
"href": "string"
}
},
"created_at": "2026-09-03T00:00:00Z",
"updated_at": "2026-09-03T00:00:00Z"
} Get a free GitHub API key → sponsored