Skip to content
658 linesCodeBlameRaw
1/**
2 * Scopes: what an access token may do on its owner's behalf. Mirrors
3 * `crates/contracts/src/scopes.rs`, which is the source of truth; a Rust
4 * test keeps the tables here the same.
5 *
6 * A token's permissions are its scopes read per resource: each resource
7 * at none or one level, such as issues: write. What a request may do is
8 * the intersection of the owner's role, the token's reach (the workspace
9 * it is made for, and its repositories) and its permissions.
10 */
11
12export type ScopeResource =
13 | "repo"
14 | "code"
15 | "security"
16 | "packages"
17 | "issues"
18 | "pull_requests"
19 | "agents"
20 | "workflows"
21 | "workflow_files"
22 | "checks"
23 | "deployments"
24 | "memory"
25 | "account"
26 | "notifications"
27 | "workspace"
28 | "billing"
29 | "access"
30 | "webhooks"
31 | "secrets"
32 | "runners"
33 | "models"
34 | "artifacts";
35
36export type ScopeLevel = "read" | "write" | "run" | "delete" | "admin";
37
38/** Every scope, grouped by resource, least first. */
39export const SCOPES = [
40 { scope: "repo:read", description: "See repositories, their settings, labels, timelines, releases, languages, contributors and security alerts, and search" },
41 { scope: "repo:write", description: "Create repositories, rename branches, change how pull requests merge and publish releases" },
42 { scope: "repo:admin", description: "Rename, archive, transfer, delete or change who can see a repository, change its rulesets, and dismiss security alerts" },
43 { scope: "code:read", description: "Clone and fetch private repositories with git" },
44 { scope: "code:write", description: "Push commits with git" },
45 { scope: "security:read", description: "See secret scanning, code scanning and vulnerability alerts, custom patterns, the dependency graph and SBOM, and security settings" },
46 { scope: "security:write", description: "Dismiss and reopen alerts, bypass push protection, review bypass requests, manage custom patterns, upload SARIF and change security settings" },
47 { scope: "packages:read", description: "Pull container images and install private packages" },
48 { scope: "packages:write", description: "Push container images and publish packages" },
49 { scope: "packages:delete", description: "Delete and restore packages and their versions" },
50 { scope: "issues:read", description: "Read issues, comments and plans" },
51 { scope: "issues:write", description: "Open, edit, close and comment on issues" },
52 { scope: "pull_requests:read", description: "Read pull requests, their changes, sessions and merge queues" },
53 { scope: "pull_requests:write", description: "Open, review, close and merge pull requests" },
54 { scope: "agents:run", description: "Put g1t agents to work and message them, which uses the workspace's money" },
55 { scope: "workflows:read", description: "Read workflows, runs and logs" },
56 { scope: "workflows:write", description: "Run, cancel, rerun and turn workflows on or off" },
57 { scope: "workflow_files:write", description: "Add, change and delete workflow files under .g1t/workflows and .github/workflows, with git or the API" },
58 { scope: "checks:read", description: "Read commits' statuses, check runs, check suites and annotations" },
59 { scope: "checks:write", description: "Report statuses and check runs on commits, and ask for checks to run again" },
60 { scope: "deployments:read", description: "See deployments, their statuses and environments" },
61 { scope: "deployments:write", description: "Report deployments and their statuses, from any CI" },
62 { scope: "memory:read", description: "Recall memory and search the workspace's context" },
63 { scope: "memory:write", description: "Save memory for the next agent" },
64 { scope: "account:read", description: "Read your email addresses, invites, invitations, pinned projects and stars" },
65 { scope: "account:write", description: "Change your email addresses, make invites, answer invitations, pin projects and star repositories" },
66 { scope: "notifications:read", description: "See your inbox, its threads, and what you subscribe to and watch" },
67 { scope: "notifications:write", description: "Mark notifications read, done, saved or snoozed, subscribe to threads and watch repositories" },
68 { scope: "workspace:read", description: "Read workspace settings, invites, integrations, model routes, teams and rulesets" },
69 { scope: "workspace:admin", description: "Create and delete workspaces, invite members, connect integrations, create, change and delete teams, and change the workspace's rulesets" },
70 { scope: "billing:read", description: "See a workspace's usage, budget, AI credit and invoices" },
71 { scope: "billing:write", description: "Change a workspace's budget and buy AI credit" },
72 { scope: "access:read", description: "See who has access to repositories" },
73 { scope: "access:admin", description: "Give and take away access to repositories, a team's included" },
74 { scope: "webhooks:read", description: "See webhooks and their deliveries" },
75 { scope: "webhooks:admin", description: "Create, change and delete webhooks" },
76 { scope: "secrets:read", description: "List secrets (never their values) and read variables" },
77 { scope: "secrets:admin", description: "Set and delete secrets and variables" },
78 { scope: "runners:read", description: "See self-hosted runners, their groups and where agents run" },
79 { scope: "runners:admin", description: "Register and remove self-hosted runners, change their groups and settings" },
80 { scope: "models:read", description: "See the workspace's AI Gateway requests: their models, tokens, cost and status" },
81 { scope: "models:write", description: "Send model requests through the AI Gateway, which uses the workspace's AI credit" },
82 { scope: "artifacts:read", description: "List, read and search artifacts you can see, their versions, and the numbers their dashboards show" },
83 { scope: "artifacts:write", description: "Create, rename, move, edit, trash and restore artifacts, and propose changes to them" },
84 { scope: "artifacts:admin", description: "Share artifacts, change who can open them, and delete them for good" },
85] as const;
86
87/**
88 * Scopes of resources being built that tokens are not offered yet (Rust:
89 * `Resource::offered`). They parse in Rust and are typed here, but no
90 * preset, full access, OAuth request or token form hands them out, and no
91 * operation needs them. When one ships, its rows move to the end of
92 * `SCOPES` and `SCOPE_RESOURCES`. Empty now: Artifacts shipped last.
93 */
94export const UPCOMING_SCOPES: readonly { scope: Scope; description: string }[] = [
95] as const;
96
97export type Scope = (typeof SCOPES)[number]["scope"];
98
99/** Where a resource sits on the token form; only a person's token may hold account ones. */
100export type ResourceGroup = "repository" | "workspace" | "account";
101
102/** Resources in the order settings show them, with their names for people and their group. */
103export const SCOPE_RESOURCES: { resource: ScopeResource; label: string; group: ResourceGroup }[] = [
104 { resource: "repo", label: "Repositories", group: "repository" },
105 { resource: "code", label: "Code", group: "repository" },
106 { resource: "security", label: "Security", group: "repository" },
107 { resource: "packages", label: "Packages", group: "repository" },
108 { resource: "issues", label: "Issues", group: "repository" },
109 { resource: "pull_requests", label: "Pull requests", group: "repository" },
110 { resource: "agents", label: "g1t agents", group: "repository" },
111 { resource: "workflows", label: "Workflows", group: "repository" },
112 { resource: "workflow_files", label: "Workflow files", group: "repository" },
113 { resource: "checks", label: "Checks and statuses", group: "repository" },
114 { resource: "deployments", label: "Deployments", group: "repository" },
115 { resource: "memory", label: "Memory and context", group: "repository" },
116 { resource: "account", label: "Your account", group: "account" },
117 { resource: "notifications", label: "Notifications", group: "account" },
118 { resource: "workspace", label: "Workspaces", group: "workspace" },
119 { resource: "billing", label: "Billing", group: "workspace" },
120 { resource: "access", label: "Who has access", group: "repository" },
121 { resource: "webhooks", label: "Webhooks", group: "repository" },
122 { resource: "secrets", label: "Secrets and variables", group: "repository" },
123 { resource: "runners", label: "Self-hosted runners", group: "workspace" },
124 { resource: "models", label: "AI Gateway", group: "workspace" },
125 { resource: "artifacts", label: "Artifacts", group: "workspace" },
126];
127
128/** Resources not offered yet, as `UPCOMING_SCOPES`: settings never show them. */
129export const UPCOMING_RESOURCES: { resource: ScopeResource; label: string; group: ResourceGroup }[] = [
130];
131
132const LEVEL_ORDER: Record<ScopeLevel, number> = { read: 0, write: 1, run: 2, delete: 3, admin: 4 };
133
134export function scopeResource(scope: Scope): ScopeResource {
135 return scope.split(":")[0] as ScopeResource;
136}
137
138export function scopeLevel(scope: Scope): ScopeLevel {
139 return scope.split(":")[1] as ScopeLevel;
140}
141
142export function isScope(text: string): text is Scope {
143 return SCOPES.some((row) => row.scope === text);
144}
145
146/** Changes that are hard to undo, or decide who can reach what. */
147export function isDangerous(scope: Scope): boolean {
148 const level = scopeLevel(scope);
149 return level === "admin" || level === "delete";
150}
151
152export function describeScope(scope: Scope): string {
153 return [...SCOPES, ...UPCOMING_SCOPES].find((row) => row.scope === scope)?.description ?? scope;
154}
155
156/** Whether holding `held` gives `needed`: the same resource, at its level or lower. */
157export function scopeIncludes(held: Scope, needed: Scope): boolean {
158 return (
159 scopeResource(held) === scopeResource(needed) &&
160 LEVEL_ORDER[scopeLevel(held)] >= LEVEL_ORDER[scopeLevel(needed)]
161 );
162}
163
164/** The levels a resource has, least first. */
165export function levelsOf(resource: ScopeResource): ScopeLevel[] {
166 return SCOPES.filter((row) => scopeResource(row.scope) === resource).map((row) => scopeLevel(row.scope));
167}
168
169/** The token form's groups, in order. */
170export const RESOURCE_GROUPS: { group: ResourceGroup; label: string; about: string }[] = [
171 { group: "repository", label: "Repository permissions", about: "What it may do in the repositories it reaches." },
172 { group: "workspace", label: "Workspace permissions", about: "What it may do with the workspaces it reaches themselves." },
173 { group: "account", label: "Account permissions", about: "What it may do with your own account. Personal tokens only." },
174];
175
176/** A token's permissions: each resource held, at its highest level; left out is none. */
177export type Permissions = Partial<Record<ScopeResource, ScopeLevel>>;
178
179/** Scopes as permissions. Null scopes (full access) are every resource at its highest. */
180export function permissionsOf(scopes: readonly string[] | null): Permissions {
181 const permissions: Permissions = {};
182 const held = scopes === null ? SCOPES.map((row) => row.scope) : parseScopes(scopes.join(" "));
183 for (const scope of held) {
184 const resource = scopeResource(scope);
185 const now = permissions[resource];
186 if (!now || LEVEL_ORDER[scopeLevel(scope)] > LEVEL_ORDER[now]) permissions[resource] = scopeLevel(scope);
187 }
188 return permissions;
189}
190
191/** Permissions as the scopes a token stores: the highest of each resource, in table order. */
192export function scopesOfPermissions(permissions: Permissions): Scope[] {
193 const wanted = new Set(
194 Object.entries(permissions)
195 .filter(([, level]) => level)
196 .map(([resource, level]) => `${resource}:${level}`),
197 );
198 return SCOPES.map((row) => row.scope).filter((scope) => wanted.has(scope));
199}
200
201/** The longest a token with an expiry may last, in days. */
202export const MAX_TOKEN_LIFETIME_DAYS = 366;
203
204/** The most repositories a token may select. */
205export const MAX_SELECTED_REPOSITORIES = 50;
206
207/** Scopes from text separated by spaces or commas, in table order; unknown ones are left out. */
208export function parseScopes(text: string): Scope[] {
209 const given = new Set(text.split(/[\s,]+/).map((part) => part.trim().toLowerCase()));
210 return SCOPES.map((row) => row.scope).filter((scope) => given.has(scope));
211}
212
213/** What a token stores for full access. */
214export const FULL_ACCESS = "*";
215
216export type PresetId = "read_only" | "agent" | "ci" | "full";
217
218/** Starting points for choosing scopes. `*` is full access. */
219export const PRESET_SCOPES = {
220 read_only: [
221 "repo:read", "code:read", "security:read", "packages:read", "issues:read", "pull_requests:read", "workflows:read", "checks:read", "deployments:read", "memory:read", "account:read", "notifications:read", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "runners:read", "models:read", "artifacts:read",
222 ] as const,
223 agent: [
224 "repo:read", "code:read", "code:write", "security:read", "packages:read", "issues:read", "issues:write", "pull_requests:read", "pull_requests:write", "agents:run", "workflows:read", "checks:read", "deployments:read", "memory:read", "memory:write", "account:read", "notifications:read", "notifications:write", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "models:read", "artifacts:read",
225 ] as const,
226 ci: [
227 "repo:read", "code:read", "code:write", "packages:read", "packages:write", "workflows:read", "workflows:write", "checks:read", "checks:write", "deployments:read", "deployments:write",
228 ] as const,
229 full: [
230 "*",
231 ] as const,
232};
233
234export const PRESETS: { id: PresetId; label: string; description: string }[] = [
235 { id: "read_only", label: "Read only", description: "Read everything you can read; change nothing." },
236 { id: "agent", label: "Agent", description: "Read everything, work on issues and pull requests, push code and run g1t agents." },
237 { id: "ci", label: "CI", description: "Clone and push code, push and pull packages, run workflows, and report checks and deployments." },
238 { id: "full", label: "Full access", description: "Everything you can do, including deleting repositories and changing who has access." },
239];
240
241/** The scopes of a preset, or null for full access. */
242export function presetScopes(id: PresetId): Scope[] | null {
243 if (id === "full") return null;
244 return [...PRESET_SCOPES[id]] as Scope[];
245}
246
247/** What an OAuth client gets when it asks for nothing in particular. */
248export const OAUTH_DEFAULT_SCOPES: Scope[] = [...PRESET_SCOPES.agent];
249
250/** The operation each scope gates, by the API's operation names. */
251export const OPERATION_SCOPES = [
252 ["list_emails", "account:read"],
253 ["add_email", "account:write"],
254 ["confirm_email", "account:write"],
255 ["remove_email", "account:write"],
256 ["update_email_settings", "account:write"],
257 ["list_invites", "account:read"],
258 ["create_invite", "account:write"],
259 ["revoke_invite", "account:write"],
260 ["list_invitations", "account:read"],
261 ["accept_invitation", "account:write"],
262 ["decline_invitation", "account:write"],
263 ["list_my_repo_invitations", "account:read"],
264 ["accept_repo_invitation", "account:write"],
265 ["decline_repo_invitation", "account:write"],
266 // Your pinned projects: a preference of your account.
267 ["list_pinned_projects", "account:read"],
268 ["pin_project", "account:write"],
269 // Your stars: a preference of your account.
270 ["list_starred", "account:read"],
271 ["check_starred", "account:read"],
272 ["star_repo", "account:write"],
273 ["unstar_repo", "account:write"],
274 ["unpin_project", "account:write"],
275 ["reorder_pinned_projects", "account:write"],
276 // Your inbox: notifications, subscriptions and watching.
277 ["list_notifications", "notifications:read"],
278 ["get_notification_thread", "notifications:read"],
279 ["get_thread_subscription", "notifications:read"],
280 ["get_repo_subscription", "notifications:read"],
281 ["list_watched_repos", "notifications:read"],
282 ["mark_notifications_read", "notifications:write"],
283 ["mark_thread_read", "notifications:write"],
284 ["mark_thread_done", "notifications:write"],
285 ["save_thread", "notifications:write"],
286 ["snooze_thread", "notifications:write"],
287 ["set_thread_subscription", "notifications:write"],
288 ["delete_thread_subscription", "notifications:write"],
289 ["set_repo_subscription", "notifications:write"],
290 ["delete_repo_subscription", "notifications:write"],
291 ["create_workspace", "workspace:admin"],
292 ["delete_workspace", "workspace:admin"],
293 ["get_workspace", "workspace:read"],
294 ["update_workspace", "workspace:admin"],
295 ["list_members", "workspace:read"],
296 ["update_member", "workspace:admin"],
297 ["remove_member", "workspace:admin"],
298 ["transfer_ownership", "workspace:admin"],
299 ["leave_workspace", "account:write"],
300 ["list_workspace_invites", "workspace:read"],
301 ["invite_member", "workspace:admin"],
302 ["revoke_workspace_invite", "workspace:admin"],
303 ["list_integrations", "workspace:read"],
304 ["connect_integration", "workspace:admin"],
305 ["update_integration", "workspace:admin"],
306 ["disconnect_integration", "workspace:admin"],
307 ["test_integration", "workspace:admin"],
308 ["get_model_routes", "workspace:read"],
309 ["set_model_routes", "workspace:admin"],
310 ["list_teams", "workspace:read"],
311 ["get_team", "workspace:read"],
312 ["list_team_members", "workspace:read"],
313 ["list_child_teams", "workspace:read"],
314 ["list_team_repos", "workspace:read"],
315 ["list_user_teams", "workspace:read"],
316 ["create_team", "workspace:admin"],
317 ["list_workspace_rulesets", "workspace:read"],
318 ["get_workspace_ruleset", "workspace:read"],
319 ["list_workspace_rule_evaluations", "workspace:read"],
320 ["create_workspace_ruleset", "workspace:admin"],
321 ["update_workspace_ruleset", "workspace:admin"],
322 ["delete_workspace_ruleset", "workspace:admin"],
323 ["update_team", "workspace:admin"],
324 ["delete_team", "workspace:admin"],
325 ["set_team_member", "workspace:admin"],
326 ["remove_team_member", "workspace:admin"],
327 ["set_team_review_assignment", "workspace:admin"],
328 // A workspace's billing: usage, budget, AI credit and invoices.
329 ["get_usage", "billing:read"],
330 ["get_budget", "billing:read"],
331 ["get_ai_credit", "billing:read"],
332 ["list_invoices", "billing:read"],
333 ["get_billing_details", "billing:read"],
334 ["set_budget", "billing:write"],
335 ["buy_ai_credit", "billing:write"],
336 ["list_repos", "repo:read"],
337 ["get_repo", "repo:read"],
338 // Projects follow their repositories.
339 ["list_projects", "repo:read"],
340 ["get_project", "repo:read"],
341 ["search", "repo:read"],
342 ["list_events", "repo:read"],
343 // What the default branch says about a repository, who starred it, and
344 // its releases.
345 ["get_languages", "repo:read"],
346 ["list_contributors", "repo:read"],
347 ["get_license", "repo:read"],
348 ["list_stargazers", "repo:read"],
349 ["list_releases", "repo:read"],
350 ["get_latest_release", "repo:read"],
351 ["get_release_by_tag", "repo:read"],
352 ["get_release", "repo:read"],
353 ["create_release", "repo:write"],
354 ["update_release", "repo:write"],
355 ["delete_release", "repo:write"],
356 ["list_labels", "repo:read"],
357 ["list_milestones", "repo:read"],
358 ["get_milestone", "repo:read"],
359 ["create_label", "issues:write"],
360 ["update_label", "issues:write"],
361 ["delete_label", "issues:write"],
362 ["add_default_labels", "issues:write"],
363 ["create_milestone", "issues:write"],
364 ["update_milestone", "issues:write"],
365 ["delete_milestone", "issues:write"],
366 ["get_repo_settings", "repo:read"],
367 ["list_check_names", "repo:read"],
368 ["list_deleted_repos", "repo:read"],
369 ["list_security_alerts", "repo:read"],
370 ["get_codeowners_errors", "repo:read"],
371 ["create_repo", "repo:write"],
372 ["update_repo", "repo:write"],
373 ["update_project", "repo:write"],
374 ["update_repo_settings", "repo:write"],
375 ["list_repo_rulesets", "repo:read"],
376 ["get_repo_ruleset", "repo:read"],
377 ["get_branch_rules", "repo:read"],
378 ["list_rule_evaluations", "repo:read"],
379 ["create_repo_ruleset", "repo:admin"],
380 ["update_repo_ruleset", "repo:admin"],
381 ["delete_repo_ruleset", "repo:admin"],
382 ["rename_branch", "repo:write"],
383 ["rename_repo", "repo:admin"],
384 ["transfer_repo", "repo:admin"],
385 ["archive_repo", "repo:admin"],
386 ["unarchive_repo", "repo:admin"],
387 ["set_repo_visibility", "repo:admin"],
388 ["delete_repo", "repo:admin"],
389 ["restore_repo", "repo:admin"],
390 ["purge_repo", "repo:admin"],
391 ["dismiss_security_alert", "repo:admin"],
392 ["reopen_security_alert", "repo:admin"],
393 // The security suite.
394 ["list_secret_scanning_alerts", "security:read"],
395 ["get_secret_scanning_alert", "security:read"],
396 ["list_secret_scanning_locations", "security:read"],
397 ["list_bypass_requests", "security:read"],
398 ["list_custom_patterns", "security:read"],
399 ["list_code_scanning_alerts", "security:read"],
400 ["get_code_scanning_alert", "security:read"],
401 ["list_code_scanning_analyses", "security:read"],
402 ["get_sarif_upload", "security:read"],
403 ["list_vulnerability_alerts", "security:read"],
404 ["get_vulnerability_alert", "security:read"],
405 ["get_dependency_graph", "security:read"],
406 ["get_sbom", "security:read"],
407 ["compare_dependencies", "security:read"],
408 ["get_security_settings", "security:read"],
409 ["get_workspace_security_settings", "security:read"],
410 ["get_security_overview", "security:read"],
411 ["update_secret_scanning_alert", "security:write"],
412 ["bypass_push_protection", "security:write"],
413 ["check_secret_validity", "security:write"],
414 ["review_bypass_request", "security:write"],
415 ["create_custom_pattern", "security:write"],
416 ["update_custom_pattern", "security:write"],
417 ["delete_custom_pattern", "security:write"],
418 ["dry_run_custom_pattern", "security:write"],
419 ["update_code_scanning_alert", "security:write"],
420 ["upload_sarif", "security:write"],
421 ["update_vulnerability_alert", "security:write"],
422 ["fix_security_alert", "security:write"],
423 ["update_security_settings", "security:write"],
424 ["update_workspace_security_settings", "security:write"],
425 ["list_issues", "issues:read"],
426 ["get_issue", "issues:read"],
427 ["get_plan", "issues:read"],
428 ["create_issue", "issues:write"],
429 ["update_issue", "issues:write"],
430 ["list_issue_labels", "issues:read"],
431 ["add_issue_labels", "issues:write"],
432 ["set_issue_labels", "issues:write"],
433 ["remove_issue_labels", "issues:write"],
434 ["close_issue", "issues:write"],
435 ["reopen_issue", "issues:write"],
436 ["add_comment", "issues:write"],
437 ["edit_comment", "issues:write"],
438 ["delete_comment", "issues:write"],
439 ["import_issue", "issues:write"],
440 ["apply_plan", "issues:write"],
441 ["list_pull_requests", "pull_requests:read"],
442 ["get_pull_request", "pull_requests:read"],
443 ["get_pull_request_changes", "pull_requests:read"],
444 ["read_session", "pull_requests:read"],
445 ["get_merge_queue", "pull_requests:read"],
446 ["create_pull_request", "pull_requests:write"],
447 ["update_pull_request", "pull_requests:write"],
448 ["record_session", "pull_requests:write"],
449 ["mark_pull_request_ready", "pull_requests:write"],
450 ["close_pull_request", "pull_requests:write"],
451 ["reopen_pull_request", "pull_requests:write"],
452 ["convert_pull_request_to_draft", "pull_requests:write"],
453 ["review_pull_request", "pull_requests:write"],
454 ["merge_pull_request", "pull_requests:write"],
455 ["request_reviewers", "pull_requests:write"],
456 ["remove_requested_reviewers", "pull_requests:write"],
457 ["assign_issue", "agents:run"],
458 ["delegate", "agents:run"],
459 ["plan_work", "agents:run"],
460 ["message_agent", "agents:run"],
461 ["answer_message", "agents:run"],
462 ["take_messages", "agents:run"],
463 ["list_workflows", "workflows:read"],
464 ["list_workflow_runs", "workflows:read"],
465 ["get_workflow_run", "workflows:read"],
466 ["get_job_logs", "workflows:read"],
467 ["dispatch_workflow", "workflows:write"],
468 ["cancel_workflow_run", "workflows:write"],
469 ["rerun_workflow_run", "workflows:write"],
470 ["update_workflow", "workflows:write"],
471 ["list_artifacts", "workflows:read"],
472 ["list_workflow_run_artifacts", "workflows:read"],
473 ["get_artifact", "workflows:read"],
474 ["download_artifact", "workflows:read"],
475 ["get_artifact_retention", "workflows:read"],
476 ["delete_artifact", "workflows:write"],
477 ["set_artifact_retention", "workflows:write"],
478 ["list_commit_statuses", "checks:read"],
479 ["get_combined_status", "checks:read"],
480 ["list_check_runs_for_ref", "checks:read"],
481 ["get_check_run", "checks:read"],
482 ["list_check_run_annotations", "checks:read"],
483 ["list_check_suites_for_ref", "checks:read"],
484 ["get_check_suite", "checks:read"],
485 ["create_commit_status", "checks:write"],
486 ["create_check_run", "checks:write"],
487 ["update_check_run", "checks:write"],
488 ["rerequest_check_run", "checks:write"],
489 ["rerequest_check_suite", "checks:write"],
490 // Deployments, wherever they run: reading them, and reporting them.
491 ["list_deployments", "deployments:read"],
492 ["get_deployment", "deployments:read"],
493 ["list_deployment_statuses", "deployments:read"],
494 ["list_environments", "deployments:read"],
495 ["get_environment", "deployments:read"],
496 ["create_deployment", "deployments:write"],
497 ["create_deployment_status", "deployments:write"],
498 // What keeps runs safe: the runs environments hold and reviewing them,
499 // approving a pull request's run, and a repository's own rules for its
500 // environments and tokens, which are an admin's.
501 ["get_pending_deployments", "workflows:read"],
502 ["review_pending_deployments", "workflows:write"],
503 ["approve_workflow_run", "workflows:write"],
504 ["get_workflow_permissions", "repo:read"],
505 ["get_fork_pr_approval", "repo:read"],
506 ["get_actions_access", "repo:read"],
507 ["update_environment", "repo:admin"],
508 ["delete_environment", "repo:admin"],
509 ["set_workflow_permissions", "repo:admin"],
510 ["set_fork_pr_approval", "repo:admin"],
511 ["set_actions_access", "repo:admin"],
512 // Starting workflows from outside, as a push would.
513 ["create_repository_dispatch", "code:write"],
514 // A workspace's policy for its repositories' tokens.
515 ["get_workspace_workflow_permissions", "workspace:read"],
516 ["set_workspace_workflow_permissions", "workspace:admin"],
517 // A workspace's rules for personal access tokens, and its members' tokens.
518 ["get_token_policy", "workspace:read"],
519 ["set_token_policy", "workspace:admin"],
520 ["list_member_tokens", "access:read"],
521 ["list_token_requests", "access:read"],
522 ["review_token_request", "access:admin"],
523 ["revoke_member_token", "access:admin"],
524 ["recall", "memory:read"],
525 ["search_context", "memory:read"],
526 ["get_entity", "memory:read"],
527 ["get_context", "memory:read"],
528 ["remember", "memory:write"],
529 ["list_collaborators", "access:read"],
530 ["get_collaborator_permission", "access:read"],
531 ["list_repo_invitations", "access:read"],
532 ["list_outside_collaborators", "access:read"],
533 ["add_collaborator", "access:admin"],
534 ["update_collaborator", "access:admin"],
535 ["remove_collaborator", "access:admin"],
536 ["revoke_repo_invitation", "access:admin"],
537 ["set_base_permission", "access:admin"],
538 ["set_team_repo", "access:admin"],
539 ["remove_team_repo", "access:admin"],
540 ["list_deploy_keys", "access:read"],
541 ["get_deploy_key", "access:read"],
542 ["create_deploy_key", "access:admin"],
543 ["delete_deploy_key", "access:admin"],
544 ["get_mirror", "repo:read"],
545 ["sync_mirror", "code:write"],
546 ["get_hand_back_plan", "repo:admin"],
547 ["take_over_mirror", "repo:admin"],
548 ["set_ci_failover", "repo:admin"],
549 ["hand_back_mirror", "repo:admin"],
550 ["move_mirror_to_g1t", "repo:admin"],
551 ["add_mirror_remote", "repo:admin"],
552 ["update_mirror_remote", "repo:admin"],
553 ["remove_mirror_remote", "repo:admin"],
554 ["list_webhooks", "webhooks:read"],
555 ["list_webhook_deliveries", "webhooks:read"],
556 ["create_webhook", "webhooks:admin"],
557 ["update_webhook", "webhooks:admin"],
558 ["delete_webhook", "webhooks:admin"],
559 ["ping_webhook", "webhooks:admin"],
560 ["redeliver_webhook", "webhooks:admin"],
561 ["list_actions_secrets", "secrets:read"],
562 ["list_actions_variables", "secrets:read"],
563 ["set_actions_secret", "secrets:admin"],
564 ["delete_actions_secret", "secrets:admin"],
565 ["set_actions_variable", "secrets:admin"],
566 ["delete_actions_variable", "secrets:admin"],
567 // Self-hosted runners.
568 ["list_runners", "runners:read"],
569 ["list_runner_groups", "runners:read"],
570 ["get_runner_settings", "runners:read"],
571 ["create_runner_registration_token", "runners:admin"],
572 ["remove_runner", "runners:admin"],
573 ["create_runner_group", "runners:admin"],
574 ["update_runner_group", "runners:admin"],
575 ["delete_runner_group", "runners:admin"],
576 ["update_runner_settings", "runners:admin"],
577 // Packages: reading them, their versions and who may use them needs
578 // `packages:read`; changing their settings, access and Manage Actions
579 // access `packages:write` (and the Admin role on the package, which the
580 // packages service checks); deleting and restoring packages and
581 // versions `packages:delete`, as the registries' own deletes do.
582 ["list_packages", "packages:read"],
583 ["get_package", "packages:read"],
584 ["list_package_versions", "packages:read"],
585 ["get_package_version", "packages:read"],
586 ["list_package_access", "packages:read"],
587 ["list_package_actions_access", "packages:read"],
588 ["update_package", "packages:write"],
589 ["link_package", "packages:write"],
590 ["unlink_package", "packages:write"],
591 ["set_package_access", "packages:write"],
592 ["remove_package_access", "packages:write"],
593 ["set_package_actions_access", "packages:write"],
594 ["remove_package_actions_access", "packages:write"],
595 ["delete_package", "packages:delete"],
596 ["restore_package", "packages:delete"],
597 ["delete_package_version", "packages:delete"],
598 ["restore_package_version", "packages:delete"],
599 // The AI Gateway. Sending a request to a model needs `models:write`,
600 // checked by the model proxy at models.g1t.sh.
601 ["list_gateway_requests", "models:read"],
602 // Artifacts mode's docs, slides, designs and dashboards (the `artifact`
603 // MCP tool). The docs service then checks the person's role on each.
604 ["list_workspace_artifacts", "artifacts:read"],
605 ["search_workspace_artifacts", "artifacts:read"],
606 ["get_workspace_artifact", "artifacts:read"],
607 ["get_workspace_artifact_content", "artifacts:read"],
608 ["list_workspace_artifact_versions", "artifacts:read"],
609 ["get_workspace_artifact_access", "artifacts:read"],
610 ["list_workspace_artifact_templates", "artifacts:read"],
611 ["list_workspace_artifact_spaces", "artifacts:read"],
612 ["query_workspace_dataset", "artifacts:read"],
613 ["create_workspace_artifact", "artifacts:write"],
614 ["update_workspace_artifact", "artifacts:write"],
615 ["edit_workspace_artifact", "artifacts:write"],
616 ["trash_workspace_artifact", "artifacts:write"],
617 ["restore_workspace_artifact", "artifacts:write"],
618 ["restore_workspace_artifact_version", "artifacts:write"],
619 ["set_workspace_artifact_access", "artifacts:admin"],
620 ["purge_workspace_artifact", "artifacts:admin"],
621] as const;
622
623/**
624 * The scopes a token or grant holds, as stored: null for full access, or
625 * the list. `legacy` marks a token made before scopes, which has full
626 * access until someone narrows it.
627 */
628export type TokenScopes = {
629 scopes: Scope[] | null;
630 legacy: boolean;
631};
632
633/**
634 * How settings group scopes into a checklist: each group's scopes, least
635 * first. Admin scopes are not here; they are under "Dangerous" on their
636 * own (see `DANGEROUS_SCOPES`). Every other scope is in exactly one group.
637 */
638export const SCOPE_GROUPS: { id: string; label: string; scopes: Scope[] }[] = [
639 { id: "code", label: "Repositories & code", scopes: ["repo:read", "repo:write", "code:read", "code:write"] },
640 { id: "security", label: "Security", scopes: ["security:read", "security:write"] },
641 { id: "packages", label: "Packages", scopes: ["packages:read", "packages:write"] },
642 { id: "work", label: "Issues & pull requests", scopes: ["issues:read", "issues:write", "pull_requests:read", "pull_requests:write"] },
643 { id: "agents", label: "Agents", scopes: ["agents:run"] },
644 { id: "workflows", label: "Workflows", scopes: ["workflows:read", "workflows:write", "workflow_files:write"] },
645 { id: "checks", label: "Checks", scopes: ["checks:read", "checks:write"] },
646 { id: "deployments", label: "Deployments", scopes: ["deployments:read", "deployments:write"] },
647 { id: "memory", label: "Memory & search", scopes: ["memory:read", "memory:write"] },
648 { id: "account", label: "Account", scopes: ["account:read", "account:write"] },
649 { id: "notifications", label: "Notifications", scopes: ["notifications:read", "notifications:write"] },
650 { id: "workspace", label: "Workspace", scopes: ["workspace:read", "access:read", "webhooks:read", "secrets:read"] },
651 { id: "billing", label: "Billing", scopes: ["billing:read", "billing:write"] },
652 { id: "runners", label: "Runners", scopes: ["runners:read"] },
653 { id: "models", label: "AI Gateway", scopes: ["models:read", "models:write"] },
654 { id: "artifacts", label: "Artifacts", scopes: ["artifacts:read", "artifacts:write"] },
655];
656
657/** The admin and delete scopes, shown under "Dangerous" behind a warning. */
658export const DANGEROUS_SCOPES: Scope[] = SCOPES.map((row) => row.scope).filter(isDangerous);