Skip to content

g1t/packages/contracts/src/scopes.ts

521 lines25,437 bytesCodeBlame

Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.

Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step1/**
2 * Scopes: what an access token may do on its owner's behalf. Mirrors
3 * `crates/contracts/src/scopes.rs`, which is the source of truth; a Rust
4 * test keeps the tables here the same.
5 *
6 * A token reaches whatever its owner can reach (a workspace's token, that
7 * workspace); what a request may do is the intersection of the owner's
8 * role and the token's scopes.
9 */
10
11export type ScopeResource =
12 | "repo"
13 | "code"
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar14 | "security"
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member15 | "packages"
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step16 | "issues"
17 | "pull_requests"
18 | "agents"
19 | "workflows"
Merge checks: statuses and check runs on every commit20 | "checks"
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9721 | "deployments"
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step22 | "memory"
23 | "account"
API: notifications over REST and MCP, with notifications scopes24 | "notifications"
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step25 | "workspace"
Usage, Billing settings and prepaid AI credit; fixes from the UX audit26 | "billing"
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step27 | "access"
28 | "webhooks"
Fast pages, required checks on the branch, self-hosted runners, honest incidents29 | "secrets"
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens30 | "runners"
31 | "models";
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step32
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member33export type ScopeLevel = "read" | "write" | "run" | "delete" | "admin";
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step34
35/** Every scope, grouped by resource, least first. */
36export const SCOPES = [
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9737 { scope: "repo:read", description: "See repositories, their settings, labels, timelines, releases, languages, contributors and security alerts, and search" },
38 { scope: "repo:write", description: "Create repositories, rename branches, change how pull requests merge and publish releases" },
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge39 { scope: "repo:admin", description: "Rename, archive, transfer, delete or change who can see a repository, change its rulesets, and dismiss security alerts" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step40 { scope: "code:read", description: "Clone and fetch private repositories with git" },
41 { scope: "code:write", description: "Push commits with git" },
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar42 { scope: "security:read", description: "See secret scanning, code scanning and vulnerability alerts, custom patterns, the dependency graph and SBOM, and security settings" },
43 { scope: "security:write", description: "Dismiss and reopen alerts, bypass push protection, review bypass requests, manage custom patterns, upload SARIF and change security settings" },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member44 { scope: "packages:read", description: "Pull container images and install private packages" },
45 { scope: "packages:write", description: "Push container images and publish packages" },
46 { scope: "packages:delete", description: "Delete packages and their versions" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step47 { scope: "issues:read", description: "Read issues, comments and plans" },
48 { scope: "issues:write", description: "Open, edit, close and comment on issues" },
49 { scope: "pull_requests:read", description: "Read pull requests, their changes, sessions and merge queues" },
50 { scope: "pull_requests:write", description: "Open, review, close and merge pull requests" },
51 { scope: "agents:run", description: "Put g1t agents to work and message them, which uses the workspace's money" },
52 { scope: "workflows:read", description: "Read workflows, runs and logs" },
53 { scope: "workflows:write", description: "Run, cancel, rerun and turn workflows on or off" },
Merge checks: statuses and check runs on every commit54 { scope: "checks:read", description: "Read commits' statuses, check runs, check suites and annotations" },
55 { scope: "checks:write", description: "Report statuses and check runs on commits, and ask for checks to run again" },
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9756 { scope: "deployments:read", description: "See deployments, their statuses and environments" },
57 { scope: "deployments:write", description: "Report deployments and their statuses, from any CI" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step58 { scope: "memory:read", description: "Recall memory and search the workspace's context" },
59 { scope: "memory:write", description: "Save memory for the next agent" },
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9760 { scope: "account:read", description: "Read your email addresses, invites, invitations, pinned projects and stars" },
61 { scope: "account:write", description: "Change your email addresses, make invites, answer invitations, pin projects and star repositories" },
API: notifications over REST and MCP, with notifications scopes62 { scope: "notifications:read", description: "See your inbox, its threads, and what you subscribe to and watch" },
63 { scope: "notifications:write", description: "Mark notifications read, done, saved or snoozed, subscribe to threads and watch repositories" },
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge64 { scope: "workspace:read", description: "Read workspace settings, invites, integrations, model routes, teams and rulesets" },
65 { scope: "workspace:admin", description: "Create and delete workspaces, invite members, connect integrations, create, change and delete teams, and change the workspace's rulesets" },
Usage, Billing settings and prepaid AI credit; fixes from the UX audit66 { scope: "billing:read", description: "See a workspace's usage, budget, AI credit and invoices" },
67 { scope: "billing:write", description: "Change a workspace's budget and buy AI credit" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step68 { scope: "access:read", description: "See who has access to repositories" },
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar69 { scope: "access:admin", description: "Give and take away access to repositories, a team's included" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step70 { scope: "webhooks:read", description: "See webhooks and their deliveries" },
71 { scope: "webhooks:admin", description: "Create, change and delete webhooks" },
72 { scope: "secrets:read", description: "List secrets (never their values) and read variables" },
73 { scope: "secrets:admin", description: "Set and delete secrets and variables" },
Fast pages, required checks on the branch, self-hosted runners, honest incidents74 { scope: "runners:read", description: "See self-hosted runners, their groups and where agents run" },
75 { scope: "runners:admin", description: "Register and remove self-hosted runners, change their groups and settings" },
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens76 { scope: "models:read", description: "See the workspace's AI Gateway requests: their models, tokens, cost and status" },
77 { scope: "models:write", description: "Send model requests through the AI Gateway, which uses the workspace's AI credit" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step78] as const;
79
80export type Scope = (typeof SCOPES)[number]["scope"];
81
82/** Resources in the order settings show them, with their names for people. */
83export const SCOPE_RESOURCES: { resource: ScopeResource; label: string }[] = [
84 { resource: "repo", label: "Repositories" },
85 { resource: "code", label: "Code" },
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar86 { resource: "security", label: "Security" },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member87 { resource: "packages", label: "Packages" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step88 { resource: "issues", label: "Issues" },
89 { resource: "pull_requests", label: "Pull requests" },
90 { resource: "agents", label: "g1t agents" },
91 { resource: "workflows", label: "Workflows" },
Merge checks: statuses and check runs on every commit92 { resource: "checks", label: "Checks and statuses" },
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb9793 { resource: "deployments", label: "Deployments" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step94 { resource: "memory", label: "Memory and context" },
95 { resource: "account", label: "Your account" },
API: notifications over REST and MCP, with notifications scopes96 { resource: "notifications", label: "Notifications" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step97 { resource: "workspace", label: "Workspaces" },
Usage, Billing settings and prepaid AI credit; fixes from the UX audit98 { resource: "billing", label: "Billing" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step99 { resource: "access", label: "Who has access" },
100 { resource: "webhooks", label: "Webhooks" },
101 { resource: "secrets", label: "Secrets and variables" },
Fast pages, required checks on the branch, self-hosted runners, honest incidents102 { resource: "runners", label: "Self-hosted runners" },
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens103 { resource: "models", label: "AI Gateway" },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step104];
105
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member106const LEVEL_ORDER: Record<ScopeLevel, number> = { read: 0, write: 1, run: 2, delete: 3, admin: 4 };
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step107
108export function scopeResource(scope: Scope): ScopeResource {
109 return scope.split(":")[0] as ScopeResource;
110}
111
112export function scopeLevel(scope: Scope): ScopeLevel {
113 return scope.split(":")[1] as ScopeLevel;
114}
115
116export function isScope(text: string): text is Scope {
117 return SCOPES.some((row) => row.scope === text);
118}
119
120/** Changes that are hard to undo, or decide who can reach what. */
121export function isDangerous(scope: Scope): boolean {
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member122 const level = scopeLevel(scope);
123 return level === "admin" || level === "delete";
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step124}
125
126export function describeScope(scope: Scope): string {
127 return SCOPES.find((row) => row.scope === scope)?.description ?? scope;
128}
129
130/** Whether holding `held` gives `needed`: the same resource, at its level or lower. */
131export function scopeIncludes(held: Scope, needed: Scope): boolean {
132 return (
133 scopeResource(held) === scopeResource(needed) &&
134 LEVEL_ORDER[scopeLevel(held)] >= LEVEL_ORDER[scopeLevel(needed)]
135 );
136}
137
138/** The levels a resource has, least first. */
139export function levelsOf(resource: ScopeResource): ScopeLevel[] {
140 return SCOPES.filter((row) => scopeResource(row.scope) === resource).map((row) => scopeLevel(row.scope));
141}
142
143/** Scopes from text separated by spaces or commas, in table order; unknown ones are left out. */
144export function parseScopes(text: string): Scope[] {
145 const given = new Set(text.split(/[\s,]+/).map((part) => part.trim().toLowerCase()));
146 return SCOPES.map((row) => row.scope).filter((scope) => given.has(scope));
147}
148
149/** What a token stores for full access. */
150export const FULL_ACCESS = "*";
151
152export type PresetId = "read_only" | "agent" | "ci" | "full";
153
154/** Starting points for choosing scopes. `*` is full access. */
155export const PRESET_SCOPES = {
156 read_only: [
Merge checks: statuses and check runs on every commit157 "repo:read", "code:read", "security:read", "packages:read", "issues:read", "pull_requests:read", "workflows:read", "checks:read", "deployments:read", "memory:read", "account:read", "notifications:read", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "runners:read", "models:read",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step158 ] as const,
159 agent: [
Merge checks: statuses and check runs on every commit160 "repo:read", "code:read", "code:write", "security:read", "packages:read", "issues:read", "issues:write", "pull_requests:read", "pull_requests:write", "agents:run", "workflows:read", "checks:read", "deployments:read", "memory:read", "memory:write", "account:read", "notifications:read", "notifications:write", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "models:read",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step161 ] as const,
162 ci: [
Merge checks: statuses and check runs on every commit163 "repo:read", "code:read", "code:write", "packages:read", "packages:write", "workflows:read", "workflows:write", "checks:read", "checks:write", "deployments:read", "deployments:write",
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step164 ] as const,
165 full: [
166 "*",
167 ] as const,
168};
169
170export const PRESETS: { id: PresetId; label: string; description: string }[] = [
171 { id: "read_only", label: "Read only", description: "Read everything you can read; change nothing." },
172 { id: "agent", label: "Agent", description: "Read everything, work on issues and pull requests, push code and run g1t agents." },
Merge checks: statuses and check runs on every commit173 { id: "ci", label: "CI", description: "Clone and push code, push and pull packages, run workflows, and report checks and deployments." },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step174 { id: "full", label: "Full access", description: "Everything you can do, including deleting repositories and changing who has access." },
175];
176
177/** The scopes of a preset, or null for full access. */
178export function presetScopes(id: PresetId): Scope[] | null {
179 if (id === "full") return null;
180 return [...PRESET_SCOPES[id]] as Scope[];
181}
182
183/** What an OAuth client gets when it asks for nothing in particular. */
184export const OAUTH_DEFAULT_SCOPES: Scope[] = [...PRESET_SCOPES.agent];
185
186/** The operation each scope gates, by the API's operation names. */
187export const OPERATION_SCOPES = [
188 ["list_emails", "account:read"],
189 ["add_email", "account:write"],
190 ["remove_email", "account:write"],
191 ["update_email_settings", "account:write"],
192 ["list_invites", "account:read"],
193 ["create_invite", "account:write"],
194 ["revoke_invite", "account:write"],
195 ["list_my_repo_invitations", "account:read"],
196 ["accept_repo_invitation", "account:write"],
197 ["decline_repo_invitation", "account:write"],
API: pinned projects over REST and MCP198 // Your pinned projects: a preference of your account.
199 ["list_pinned_projects", "account:read"],
200 ["pin_project", "account:write"],
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97201 // Your stars: a preference of your account.
202 ["list_starred", "account:read"],
203 ["check_starred", "account:read"],
204 ["star_repo", "account:write"],
205 ["unstar_repo", "account:write"],
API: pinned projects over REST and MCP206 ["unpin_project", "account:write"],
207 ["reorder_pinned_projects", "account:write"],
API: notifications over REST and MCP, with notifications scopes208 // Your inbox: notifications, subscriptions and watching.
209 ["list_notifications", "notifications:read"],
210 ["get_notification_thread", "notifications:read"],
211 ["get_thread_subscription", "notifications:read"],
212 ["get_repo_subscription", "notifications:read"],
213 ["list_watched_repos", "notifications:read"],
214 ["mark_notifications_read", "notifications:write"],
215 ["mark_thread_read", "notifications:write"],
216 ["mark_thread_done", "notifications:write"],
217 ["save_thread", "notifications:write"],
218 ["snooze_thread", "notifications:write"],
219 ["set_thread_subscription", "notifications:write"],
220 ["delete_thread_subscription", "notifications:write"],
221 ["set_repo_subscription", "notifications:write"],
222 ["delete_repo_subscription", "notifications:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step223 ["create_workspace", "workspace:admin"],
224 ["delete_workspace", "workspace:admin"],
Merge branch 'worktree-agent-ad7c6d88d93adc817'225 ["get_workspace", "workspace:read"],
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily226 ["update_workspace", "workspace:admin"],
Merge membership: owners, org roles, GitHub's repo roles, privileges, 2FA227 ["list_members", "workspace:read"],
228 ["update_member", "workspace:admin"],
229 ["remove_member", "workspace:admin"],
230 ["transfer_ownership", "workspace:admin"],
231 ["leave_workspace", "account:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step232 ["list_workspace_invites", "workspace:read"],
233 ["invite_member", "workspace:admin"],
234 ["revoke_workspace_invite", "workspace:admin"],
235 ["list_integrations", "workspace:read"],
236 ["connect_integration", "workspace:admin"],
AI Gateway: OpenAI's format, open models, and your own providers237 ["update_integration", "workspace:admin"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step238 ["disconnect_integration", "workspace:admin"],
239 ["test_integration", "workspace:admin"],
240 ["get_model_routes", "workspace:read"],
241 ["set_model_routes", "workspace:admin"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar242 ["list_teams", "workspace:read"],
243 ["get_team", "workspace:read"],
244 ["list_team_members", "workspace:read"],
245 ["list_child_teams", "workspace:read"],
246 ["list_team_repos", "workspace:read"],
247 ["list_user_teams", "workspace:read"],
248 ["create_team", "workspace:admin"],
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge249 ["list_workspace_rulesets", "workspace:read"],
250 ["get_workspace_ruleset", "workspace:read"],
251 ["list_workspace_rule_evaluations", "workspace:read"],
252 ["create_workspace_ruleset", "workspace:admin"],
253 ["update_workspace_ruleset", "workspace:admin"],
254 ["delete_workspace_ruleset", "workspace:admin"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar255 ["update_team", "workspace:admin"],
256 ["delete_team", "workspace:admin"],
257 ["set_team_member", "workspace:admin"],
258 ["remove_team_member", "workspace:admin"],
259 ["set_team_review_assignment", "workspace:admin"],
Usage, Billing settings and prepaid AI credit; fixes from the UX audit260 // A workspace's billing: usage, budget, AI credit and invoices.
261 ["get_usage", "billing:read"],
262 ["get_budget", "billing:read"],
263 ["get_ai_credit", "billing:read"],
264 ["list_invoices", "billing:read"],
265 ["get_billing_details", "billing:read"],
266 ["set_budget", "billing:write"],
267 ["buy_ai_credit", "billing:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step268 ["list_repos", "repo:read"],
269 ["get_repo", "repo:read"],
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97270 // Projects follow their repositories.
271 ["list_projects", "repo:read"],
272 ["get_project", "repo:read"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step273 ["search", "repo:read"],
274 ["list_events", "repo:read"],
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97275 // What the default branch says about a repository, who starred it, and
276 // its releases.
277 ["get_languages", "repo:read"],
278 ["list_contributors", "repo:read"],
279 ["get_license", "repo:read"],
280 ["list_stargazers", "repo:read"],
281 ["list_releases", "repo:read"],
282 ["get_latest_release", "repo:read"],
283 ["get_release_by_tag", "repo:read"],
284 ["get_release", "repo:read"],
285 ["create_release", "repo:write"],
286 ["update_release", "repo:write"],
287 ["delete_release", "repo:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step288 ["list_labels", "repo:read"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar289 ["list_milestones", "repo:read"],
290 ["get_milestone", "repo:read"],
291 ["create_label", "issues:write"],
292 ["update_label", "issues:write"],
293 ["delete_label", "issues:write"],
294 ["add_default_labels", "issues:write"],
295 ["create_milestone", "issues:write"],
296 ["update_milestone", "issues:write"],
297 ["delete_milestone", "issues:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step298 ["get_repo_settings", "repo:read"],
Fast pages, required checks on the branch, self-hosted runners, honest incidents299 ["list_check_names", "repo:read"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step300 ["list_deleted_repos", "repo:read"],
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily301 ["list_security_alerts", "repo:read"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar302 ["get_codeowners_errors", "repo:read"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step303 ["create_repo", "repo:write"],
304 ["update_repo", "repo:write"],
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97305 ["update_project", "repo:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step306 ["update_repo_settings", "repo:write"],
Merge rulesets: branch and tag rules, agent-first, enforced on push and merge307 ["list_repo_rulesets", "repo:read"],
308 ["get_repo_ruleset", "repo:read"],
309 ["get_branch_rules", "repo:read"],
310 ["list_rule_evaluations", "repo:read"],
311 ["create_repo_ruleset", "repo:admin"],
312 ["update_repo_ruleset", "repo:admin"],
313 ["delete_repo_ruleset", "repo:admin"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step314 ["rename_branch", "repo:write"],
315 ["rename_repo", "repo:admin"],
316 ["transfer_repo", "repo:admin"],
317 ["archive_repo", "repo:admin"],
318 ["unarchive_repo", "repo:admin"],
319 ["set_repo_visibility", "repo:admin"],
320 ["delete_repo", "repo:admin"],
321 ["restore_repo", "repo:admin"],
322 ["purge_repo", "repo:admin"],
Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily323 ["dismiss_security_alert", "repo:admin"],
324 ["reopen_security_alert", "repo:admin"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar325 // The security suite.
326 ["list_secret_scanning_alerts", "security:read"],
327 ["get_secret_scanning_alert", "security:read"],
328 ["list_secret_scanning_locations", "security:read"],
329 ["list_bypass_requests", "security:read"],
330 ["list_custom_patterns", "security:read"],
331 ["list_code_scanning_alerts", "security:read"],
332 ["get_code_scanning_alert", "security:read"],
333 ["list_code_scanning_analyses", "security:read"],
334 ["get_sarif_upload", "security:read"],
335 ["list_vulnerability_alerts", "security:read"],
336 ["get_vulnerability_alert", "security:read"],
337 ["get_dependency_graph", "security:read"],
338 ["get_sbom", "security:read"],
339 ["compare_dependencies", "security:read"],
340 ["get_security_settings", "security:read"],
341 ["get_workspace_security_settings", "security:read"],
342 ["get_security_overview", "security:read"],
343 ["update_secret_scanning_alert", "security:write"],
344 ["bypass_push_protection", "security:write"],
345 ["check_secret_validity", "security:write"],
346 ["review_bypass_request", "security:write"],
347 ["create_custom_pattern", "security:write"],
348 ["update_custom_pattern", "security:write"],
349 ["delete_custom_pattern", "security:write"],
350 ["dry_run_custom_pattern", "security:write"],
351 ["update_code_scanning_alert", "security:write"],
352 ["upload_sarif", "security:write"],
353 ["update_vulnerability_alert", "security:write"],
354 ["fix_security_alert", "security:write"],
355 ["update_security_settings", "security:write"],
356 ["update_workspace_security_settings", "security:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step357 ["list_issues", "issues:read"],
358 ["get_issue", "issues:read"],
359 ["get_plan", "issues:read"],
360 ["create_issue", "issues:write"],
361 ["update_issue", "issues:write"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar362 ["list_issue_labels", "issues:read"],
363 ["add_issue_labels", "issues:write"],
364 ["set_issue_labels", "issues:write"],
365 ["remove_issue_labels", "issues:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step366 ["close_issue", "issues:write"],
367 ["reopen_issue", "issues:write"],
368 ["add_comment", "issues:write"],
369 ["import_issue", "issues:write"],
370 ["apply_plan", "issues:write"],
371 ["list_pull_requests", "pull_requests:read"],
372 ["get_pull_request", "pull_requests:read"],
373 ["get_pull_request_changes", "pull_requests:read"],
374 ["read_session", "pull_requests:read"],
375 ["get_merge_queue", "pull_requests:read"],
376 ["create_pull_request", "pull_requests:write"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar377 ["update_pull_request", "pull_requests:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step378 ["record_session", "pull_requests:write"],
379 ["mark_pull_request_ready", "pull_requests:write"],
380 ["close_pull_request", "pull_requests:write"],
381 ["review_pull_request", "pull_requests:write"],
382 ["merge_pull_request", "pull_requests:write"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar383 ["request_reviewers", "pull_requests:write"],
384 ["remove_requested_reviewers", "pull_requests:write"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step385 ["assign_issue", "agents:run"],
386 ["delegate", "agents:run"],
387 ["plan_work", "agents:run"],
388 ["message_agent", "agents:run"],
389 ["answer_message", "agents:run"],
390 ["take_messages", "agents:run"],
391 ["list_workflows", "workflows:read"],
392 ["list_workflow_runs", "workflows:read"],
393 ["get_workflow_run", "workflows:read"],
394 ["get_job_logs", "workflows:read"],
395 ["dispatch_workflow", "workflows:write"],
396 ["cancel_workflow_run", "workflows:write"],
397 ["rerun_workflow_run", "workflows:write"],
398 ["update_workflow", "workflows:write"],
Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2399 ["list_artifacts", "workflows:read"],
400 ["list_workflow_run_artifacts", "workflows:read"],
401 ["get_artifact", "workflows:read"],
402 ["download_artifact", "workflows:read"],
403 ["get_artifact_retention", "workflows:read"],
404 ["delete_artifact", "workflows:write"],
405 ["set_artifact_retention", "workflows:write"],
Merge checks: statuses and check runs on every commit406 ["list_commit_statuses", "checks:read"],
407 ["get_combined_status", "checks:read"],
408 ["list_check_runs_for_ref", "checks:read"],
409 ["get_check_run", "checks:read"],
410 ["list_check_run_annotations", "checks:read"],
411 ["list_check_suites_for_ref", "checks:read"],
412 ["get_check_suite", "checks:read"],
413 ["create_commit_status", "checks:write"],
414 ["create_check_run", "checks:write"],
415 ["update_check_run", "checks:write"],
416 ["rerequest_check_run", "checks:write"],
417 ["rerequest_check_suite", "checks:write"],
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97418 // Deployments, wherever they run: reading them, and reporting them.
419 ["list_deployments", "deployments:read"],
420 ["get_deployment", "deployments:read"],
421 ["list_deployment_statuses", "deployments:read"],
422 ["list_environments", "deployments:read"],
423 ["get_environment", "deployments:read"],
424 ["create_deployment", "deployments:write"],
425 ["create_deployment_status", "deployments:write"],
Merge branch 'worktree-agent-a3abfcce648e87dca'426 // What keeps runs safe: the runs environments hold and reviewing them,
427 // approving a pull request's run, and a repository's own rules for its
428 // environments and tokens, which are an admin's.
429 ["get_pending_deployments", "workflows:read"],
430 ["review_pending_deployments", "workflows:write"],
431 ["approve_workflow_run", "workflows:write"],
432 ["get_workflow_permissions", "repo:read"],
433 ["get_fork_pr_approval", "repo:read"],
434 ["update_environment", "repo:admin"],
435 ["delete_environment", "repo:admin"],
436 ["set_workflow_permissions", "repo:admin"],
437 ["set_fork_pr_approval", "repo:admin"],
438 // Starting workflows from outside, as a push would.
439 ["create_repository_dispatch", "code:write"],
440 // A workspace's policy for its repositories' tokens.
441 ["get_workspace_workflow_permissions", "workspace:read"],
442 ["set_workspace_workflow_permissions", "workspace:admin"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step443 ["recall", "memory:read"],
444 ["search_context", "memory:read"],
445 ["get_entity", "memory:read"],
446 ["get_context", "memory:read"],
447 ["remember", "memory:write"],
448 ["list_collaborators", "access:read"],
449 ["get_collaborator_permission", "access:read"],
450 ["list_repo_invitations", "access:read"],
451 ["list_outside_collaborators", "access:read"],
452 ["add_collaborator", "access:admin"],
453 ["update_collaborator", "access:admin"],
454 ["remove_collaborator", "access:admin"],
455 ["revoke_repo_invitation", "access:admin"],
456 ["set_base_permission", "access:admin"],
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar457 ["set_team_repo", "access:admin"],
458 ["remove_team_repo", "access:admin"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step459 ["list_webhooks", "webhooks:read"],
460 ["list_webhook_deliveries", "webhooks:read"],
461 ["create_webhook", "webhooks:admin"],
462 ["update_webhook", "webhooks:admin"],
463 ["delete_webhook", "webhooks:admin"],
464 ["ping_webhook", "webhooks:admin"],
465 ["redeliver_webhook", "webhooks:admin"],
466 ["list_actions_secrets", "secrets:read"],
467 ["list_actions_variables", "secrets:read"],
468 ["set_actions_secret", "secrets:admin"],
469 ["delete_actions_secret", "secrets:admin"],
470 ["set_actions_variable", "secrets:admin"],
471 ["delete_actions_variable", "secrets:admin"],
Fast pages, required checks on the branch, self-hosted runners, honest incidents472 // Self-hosted runners.
473 ["list_runners", "runners:read"],
474 ["list_runner_groups", "runners:read"],
475 ["get_runner_settings", "runners:read"],
476 ["create_runner_registration_token", "runners:admin"],
477 ["remove_runner", "runners:admin"],
478 ["create_runner_group", "runners:admin"],
479 ["update_runner_group", "runners:admin"],
480 ["delete_runner_group", "runners:admin"],
481 ["update_runner_settings", "runners:admin"],
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens482 // The AI Gateway. Sending a request to a model needs `models:write`,
483 // checked by the model proxy at models.g1t.sh.
484 ["list_gateway_requests", "models:read"],
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step485] as const;
486
487/**
488 * The scopes a token or grant holds, as stored: null for full access, or
489 * the list. `legacy` marks a token made before scopes, which has full
490 * access until someone narrows it.
491 */
492export type TokenScopes = {
493 scopes: Scope[] | null;
494 legacy: boolean;
495};
496
497/**
498 * How settings group scopes into a checklist: each group's scopes, least
499 * first. Admin scopes are not here; they are under "Dangerous" on their
500 * own (see `DANGEROUS_SCOPES`). Every other scope is in exactly one group.
501 */
502export const SCOPE_GROUPS: { id: string; label: string; scopes: Scope[] }[] = [
503 { id: "code", label: "Repositories & code", scopes: ["repo:read", "repo:write", "code:read", "code:write"] },
Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar504 { id: "security", label: "Security", scopes: ["security:read", "security:write"] },
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member505 { id: "packages", label: "Packages", scopes: ["packages:read", "packages:write"] },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step506 { id: "work", label: "Issues & pull requests", scopes: ["issues:read", "issues:write", "pull_requests:read", "pull_requests:write"] },
507 { id: "agents", label: "Agents", scopes: ["agents:run"] },
508 { id: "workflows", label: "Workflows", scopes: ["workflows:read", "workflows:write"] },
Merge checks: statuses and check runs on every commit509 { id: "checks", label: "Checks", scopes: ["checks:read", "checks:write"] },
Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97510 { id: "deployments", label: "Deployments", scopes: ["deployments:read", "deployments:write"] },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step511 { id: "memory", label: "Memory & search", scopes: ["memory:read", "memory:write"] },
512 { id: "account", label: "Account", scopes: ["account:read", "account:write"] },
API: notifications over REST and MCP, with notifications scopes513 { id: "notifications", label: "Notifications", scopes: ["notifications:read", "notifications:write"] },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step514 { id: "workspace", label: "Workspace", scopes: ["workspace:read", "access:read", "webhooks:read", "secrets:read"] },
Usage, Billing settings and prepaid AI credit; fixes from the UX audit515 { id: "billing", label: "Billing", scopes: ["billing:read", "billing:write"] },
Fast pages, required checks on the branch, self-hosted runners, honest incidents516 { id: "runners", label: "Runners", scopes: ["runners:read"] },
Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens517 { id: "models", label: "AI Gateway", scopes: ["models:read", "models:write"] },
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step518];
519
Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member520/** The admin and delete scopes, shown under "Dangerous" behind a warning. */
Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step521export const DANGEROUS_SCOPES: Scope[] = SCOPES.map((row) => row.scope).filter(isDangerous);

This file's history is long; its oldest lines are credited to the oldest commit read.