Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 1 | /** |
| 2 | * Scopes: what an access token may do on its owner's behalf. Mirrors | |
| 3 | * `crates/contracts/src/scopes.rs`, which is the source of truth; a Rust | |
| 4 | * test keeps the tables here the same. | |
| 5 | * | |
| One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers | 6 | * A token's permissions are its scopes read per resource: each resource |
| 7 | * at none or one level, such as issues: write. What a request may do is | |
| 8 | * the intersection of the owner's role, the token's reach (the workspace | |
| 9 | * it is made for, and its repositories) and its permissions. | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 10 | */ |
| 11 | ||
| 12 | export type ScopeResource = | |
| 13 | | "repo" | |
| 14 | | "code" | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 15 | | "security" |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 16 | | "packages" |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 17 | | "issues" |
| 18 | | "pull_requests" | |
| 19 | | "agents" | |
| 20 | | "workflows" | |
| Token reach: workflow_files scope, fine-grained reach, workspace token cap | 21 | | "workflow_files" |
| Merge checks: statuses and check runs on every commit | 22 | | "checks" |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 23 | | "deployments" |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 24 | | "memory" |
| 25 | | "account" | |
| API: notifications over REST and MCP, with notifications scopes | 26 | | "notifications" |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 27 | | "workspace" |
| Usage, Billing settings and prepaid AI credit; fixes from the UX audit | 28 | | "billing" |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 29 | | "access" |
| 30 | | "webhooks" | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 31 | | "secrets" |
| Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens | 32 | | "runners" |
| Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet | 33 | | "models" |
| 34 | | "artifacts"; | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 35 | |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 36 | export type ScopeLevel = "read" | "write" | "run" | "delete" | "admin"; |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 37 | |
| 38 | /** Every scope, grouped by resource, least first. */ | |
| 39 | export const SCOPES = [ | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 40 | { scope: "repo:read", description: "See repositories, their settings, labels, timelines, releases, languages, contributors and security alerts, and search" }, |
| 41 | { scope: "repo:write", description: "Create repositories, rename branches, change how pull requests merge and publish releases" }, | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 42 | { scope: "repo:admin", description: "Rename, archive, transfer, delete or change who can see a repository, change its rulesets, and dismiss security alerts" }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 43 | { scope: "code:read", description: "Clone and fetch private repositories with git" }, |
| 44 | { scope: "code:write", description: "Push commits with git" }, | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 45 | { scope: "security:read", description: "See secret scanning, code scanning and vulnerability alerts, custom patterns, the dependency graph and SBOM, and security settings" }, |
| 46 | { scope: "security:write", description: "Dismiss and reopen alerts, bypass push protection, review bypass requests, manage custom patterns, upload SARIF and change security settings" }, | |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 47 | { scope: "packages:read", description: "Pull container images and install private packages" }, |
| 48 | { scope: "packages:write", description: "Push container images and publish packages" }, | |
| Merge packages: roles, Actions access, source label, soft delete, API | 49 | { scope: "packages:delete", description: "Delete and restore packages and their versions" }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 50 | { scope: "issues:read", description: "Read issues, comments and plans" }, |
| 51 | { scope: "issues:write", description: "Open, edit, close and comment on issues" }, | |
| 52 | { scope: "pull_requests:read", description: "Read pull requests, their changes, sessions and merge queues" }, | |
| 53 | { scope: "pull_requests:write", description: "Open, review, close and merge pull requests" }, | |
| 54 | { scope: "agents:run", description: "Put g1t agents to work and message them, which uses the workspace's money" }, | |
| 55 | { scope: "workflows:read", description: "Read workflows, runs and logs" }, | |
| 56 | { scope: "workflows:write", description: "Run, cancel, rerun and turn workflows on or off" }, | |
| Token reach: workflow_files scope, fine-grained reach, workspace token cap | 57 | { scope: "workflow_files:write", description: "Add, change and delete workflow files under .g1t/workflows and .github/workflows, with git or the API" }, |
| Merge checks: statuses and check runs on every commit | 58 | { scope: "checks:read", description: "Read commits' statuses, check runs, check suites and annotations" }, |
| 59 | { scope: "checks:write", description: "Report statuses and check runs on commits, and ask for checks to run again" }, | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 60 | { scope: "deployments:read", description: "See deployments, their statuses and environments" }, |
| 61 | { scope: "deployments:write", description: "Report deployments and their statuses, from any CI" }, | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 62 | { scope: "memory:read", description: "Recall memory and search the workspace's context" }, |
| 63 | { scope: "memory:write", description: "Save memory for the next agent" }, | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 64 | { scope: "account:read", description: "Read your email addresses, invites, invitations, pinned projects and stars" }, |
| 65 | { scope: "account:write", description: "Change your email addresses, make invites, answer invitations, pin projects and star repositories" }, | |
| API: notifications over REST and MCP, with notifications scopes | 66 | { scope: "notifications:read", description: "See your inbox, its threads, and what you subscribe to and watch" }, |
| 67 | { scope: "notifications:write", description: "Mark notifications read, done, saved or snoozed, subscribe to threads and watch repositories" }, | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 68 | { scope: "workspace:read", description: "Read workspace settings, invites, integrations, model routes, teams and rulesets" }, |
| 69 | { scope: "workspace:admin", description: "Create and delete workspaces, invite members, connect integrations, create, change and delete teams, and change the workspace's rulesets" }, | |
| Usage, Billing settings and prepaid AI credit; fixes from the UX audit | 70 | { scope: "billing:read", description: "See a workspace's usage, budget, AI credit and invoices" }, |
| 71 | { scope: "billing:write", description: "Change a workspace's budget and buy AI credit" }, | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 72 | { scope: "access:read", description: "See who has access to repositories" }, |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 73 | { scope: "access:admin", description: "Give and take away access to repositories, a team's included" }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 74 | { scope: "webhooks:read", description: "See webhooks and their deliveries" }, |
| 75 | { scope: "webhooks:admin", description: "Create, change and delete webhooks" }, | |
| 76 | { scope: "secrets:read", description: "List secrets (never their values) and read variables" }, | |
| 77 | { scope: "secrets:admin", description: "Set and delete secrets and variables" }, | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 78 | { scope: "runners:read", description: "See self-hosted runners, their groups and where agents run" }, |
| 79 | { scope: "runners:admin", description: "Register and remove self-hosted runners, change their groups and settings" }, | |
| Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens | 80 | { scope: "models:read", description: "See the workspace's AI Gateway requests: their models, tokens, cost and status" }, |
| 81 | { scope: "models:write", description: "Send model requests through the AI Gateway, which uses the workspace's AI credit" }, | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 82 | ] as const; |
| 83 | ||
| Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet | 84 | /** |
| 85 | * Scopes of resources being built that tokens are not offered yet (Rust: | |
| 86 | * `Resource::offered`). They parse in Rust and are typed here, but no | |
| 87 | * preset, full access, OAuth request or token form hands them out, and no | |
| 88 | * operation needs them. When one ships, its rows move to the end of | |
| 89 | * `SCOPES` and `SCOPE_RESOURCES`. | |
| 90 | */ | |
| 91 | export const UPCOMING_SCOPES = [ | |
| 92 | { scope: "artifacts:read", description: "List, read and search artifacts you can see, their versions, and the numbers their dashboards show" }, | |
| 93 | { scope: "artifacts:write", description: "Create, rename, move, edit, trash and restore artifacts, and propose changes to them" }, | |
| 94 | { scope: "artifacts:admin", description: "Share artifacts, change who can open them, and delete them for good" }, | |
| 95 | ] as const; | |
| 96 | ||
| 97 | export type Scope = (typeof SCOPES)[number]["scope"] | (typeof UPCOMING_SCOPES)[number]["scope"]; | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 98 | |
| One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers | 99 | /** Where a resource sits on the token form; only a person's token may hold account ones. */ |
| 100 | export type ResourceGroup = "repository" | "workspace" | "account"; | |
| 101 | ||
| 102 | /** Resources in the order settings show them, with their names for people and their group. */ | |
| 103 | export const SCOPE_RESOURCES: { resource: ScopeResource; label: string; group: ResourceGroup }[] = [ | |
| 104 | { resource: "repo", label: "Repositories", group: "repository" }, | |
| 105 | { resource: "code", label: "Code", group: "repository" }, | |
| 106 | { resource: "security", label: "Security", group: "repository" }, | |
| 107 | { resource: "packages", label: "Packages", group: "repository" }, | |
| 108 | { resource: "issues", label: "Issues", group: "repository" }, | |
| 109 | { resource: "pull_requests", label: "Pull requests", group: "repository" }, | |
| 110 | { resource: "agents", label: "g1t agents", group: "repository" }, | |
| 111 | { resource: "workflows", label: "Workflows", group: "repository" }, | |
| 112 | { resource: "workflow_files", label: "Workflow files", group: "repository" }, | |
| 113 | { resource: "checks", label: "Checks and statuses", group: "repository" }, | |
| 114 | { resource: "deployments", label: "Deployments", group: "repository" }, | |
| 115 | { resource: "memory", label: "Memory and context", group: "repository" }, | |
| 116 | { resource: "account", label: "Your account", group: "account" }, | |
| 117 | { resource: "notifications", label: "Notifications", group: "account" }, | |
| 118 | { resource: "workspace", label: "Workspaces", group: "workspace" }, | |
| 119 | { resource: "billing", label: "Billing", group: "workspace" }, | |
| 120 | { resource: "access", label: "Who has access", group: "repository" }, | |
| 121 | { resource: "webhooks", label: "Webhooks", group: "repository" }, | |
| 122 | { resource: "secrets", label: "Secrets and variables", group: "repository" }, | |
| 123 | { resource: "runners", label: "Self-hosted runners", group: "workspace" }, | |
| 124 | { resource: "models", label: "AI Gateway", group: "workspace" }, | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 125 | ]; |
| 126 | ||
| Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet | 127 | /** Resources not offered yet, as `UPCOMING_SCOPES`: settings never show them. */ |
| 128 | export const UPCOMING_RESOURCES: { resource: ScopeResource; label: string; group: ResourceGroup }[] = [ | |
| 129 | { resource: "artifacts", label: "Artifacts", group: "workspace" }, | |
| 130 | ]; | |
| 131 | ||
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 132 | const LEVEL_ORDER: Record<ScopeLevel, number> = { read: 0, write: 1, run: 2, delete: 3, admin: 4 }; |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 133 | |
| 134 | export function scopeResource(scope: Scope): ScopeResource { | |
| 135 | return scope.split(":")[0] as ScopeResource; | |
| 136 | } | |
| 137 | ||
| 138 | export function scopeLevel(scope: Scope): ScopeLevel { | |
| 139 | return scope.split(":")[1] as ScopeLevel; | |
| 140 | } | |
| 141 | ||
| 142 | export function isScope(text: string): text is Scope { | |
| 143 | return SCOPES.some((row) => row.scope === text); | |
| 144 | } | |
| 145 | ||
| 146 | /** Changes that are hard to undo, or decide who can reach what. */ | |
| 147 | export function isDangerous(scope: Scope): boolean { | |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 148 | const level = scopeLevel(scope); |
| 149 | return level === "admin" || level === "delete"; | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 150 | } |
| 151 | ||
| 152 | export function describeScope(scope: Scope): string { | |
| Artifacts contracts: folios, their four kinds, dashboard datasets, folio events and the artifacts scopes are typed and validated the same in TypeScript and Rust, with nothing using them yet | 153 | return [...SCOPES, ...UPCOMING_SCOPES].find((row) => row.scope === scope)?.description ?? scope; |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 154 | } |
| 155 | ||
| 156 | /** Whether holding `held` gives `needed`: the same resource, at its level or lower. */ | |
| 157 | export function scopeIncludes(held: Scope, needed: Scope): boolean { | |
| 158 | return ( | |
| 159 | scopeResource(held) === scopeResource(needed) && | |
| 160 | LEVEL_ORDER[scopeLevel(held)] >= LEVEL_ORDER[scopeLevel(needed)] | |
| 161 | ); | |
| 162 | } | |
| 163 | ||
| 164 | /** The levels a resource has, least first. */ | |
| 165 | export function levelsOf(resource: ScopeResource): ScopeLevel[] { | |
| 166 | return SCOPES.filter((row) => scopeResource(row.scope) === resource).map((row) => scopeLevel(row.scope)); | |
| 167 | } | |
| 168 | ||
| One kind of access token; presence and status; usernames keep their case; the tour is a miniature of the real app; icons for password managers | 169 | /** The token form's groups, in order. */ |
| 170 | export const RESOURCE_GROUPS: { group: ResourceGroup; label: string; about: string }[] = [ | |
| 171 | { group: "repository", label: "Repository permissions", about: "What it may do in the repositories it reaches." }, | |
| 172 | { group: "workspace", label: "Workspace permissions", about: "What it may do with the workspaces it reaches themselves." }, | |
| 173 | { group: "account", label: "Account permissions", about: "What it may do with your own account. Personal tokens only." }, | |
| 174 | ]; | |
| 175 | ||
| 176 | /** A token's permissions: each resource held, at its highest level; left out is none. */ | |
| 177 | export type Permissions = Partial<Record<ScopeResource, ScopeLevel>>; | |
| 178 | ||
| 179 | /** Scopes as permissions. Null scopes (full access) are every resource at its highest. */ | |
| 180 | export function permissionsOf(scopes: readonly string[] | null): Permissions { | |
| 181 | const permissions: Permissions = {}; | |
| 182 | const held = scopes === null ? SCOPES.map((row) => row.scope) : parseScopes(scopes.join(" ")); | |
| 183 | for (const scope of held) { | |
| 184 | const resource = scopeResource(scope); | |
| 185 | const now = permissions[resource]; | |
| 186 | if (!now || LEVEL_ORDER[scopeLevel(scope)] > LEVEL_ORDER[now]) permissions[resource] = scopeLevel(scope); | |
| 187 | } | |
| 188 | return permissions; | |
| 189 | } | |
| 190 | ||
| 191 | /** Permissions as the scopes a token stores: the highest of each resource, in table order. */ | |
| 192 | export function scopesOfPermissions(permissions: Permissions): Scope[] { | |
| 193 | const wanted = new Set( | |
| 194 | Object.entries(permissions) | |
| 195 | .filter(([, level]) => level) | |
| 196 | .map(([resource, level]) => `${resource}:${level}`), | |
| 197 | ); | |
| 198 | return SCOPES.map((row) => row.scope).filter((scope) => wanted.has(scope)); | |
| 199 | } | |
| 200 | ||
| 201 | /** The longest a token with an expiry may last, in days. */ | |
| 202 | export const MAX_TOKEN_LIFETIME_DAYS = 366; | |
| 203 | ||
| 204 | /** The most repositories a token may select. */ | |
| 205 | export const MAX_SELECTED_REPOSITORIES = 50; | |
| 206 | ||
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 207 | /** Scopes from text separated by spaces or commas, in table order; unknown ones are left out. */ |
| 208 | export function parseScopes(text: string): Scope[] { | |
| 209 | const given = new Set(text.split(/[\s,]+/).map((part) => part.trim().toLowerCase())); | |
| 210 | return SCOPES.map((row) => row.scope).filter((scope) => given.has(scope)); | |
| 211 | } | |
| 212 | ||
| 213 | /** What a token stores for full access. */ | |
| 214 | export const FULL_ACCESS = "*"; | |
| 215 | ||
| 216 | export type PresetId = "read_only" | "agent" | "ci" | "full"; | |
| 217 | ||
| 218 | /** Starting points for choosing scopes. `*` is full access. */ | |
| 219 | export const PRESET_SCOPES = { | |
| 220 | read_only: [ | |
| Merge checks: statuses and check runs on every commit | 221 | "repo:read", "code:read", "security:read", "packages:read", "issues:read", "pull_requests:read", "workflows:read", "checks:read", "deployments:read", "memory:read", "account:read", "notifications:read", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "runners:read", "models:read", |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 222 | ] as const, |
| 223 | agent: [ | |
| Merge checks: statuses and check runs on every commit | 224 | "repo:read", "code:read", "code:write", "security:read", "packages:read", "issues:read", "issues:write", "pull_requests:read", "pull_requests:write", "agents:run", "workflows:read", "checks:read", "deployments:read", "memory:read", "memory:write", "account:read", "notifications:read", "notifications:write", "workspace:read", "billing:read", "access:read", "webhooks:read", "secrets:read", "models:read", |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 225 | ] as const, |
| 226 | ci: [ | |
| Merge checks: statuses and check runs on every commit | 227 | "repo:read", "code:read", "code:write", "packages:read", "packages:write", "workflows:read", "workflows:write", "checks:read", "checks:write", "deployments:read", "deployments:write", |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 228 | ] as const, |
| 229 | full: [ | |
| 230 | "*", | |
| 231 | ] as const, | |
| 232 | }; | |
| 233 | ||
| 234 | export const PRESETS: { id: PresetId; label: string; description: string }[] = [ | |
| 235 | { id: "read_only", label: "Read only", description: "Read everything you can read; change nothing." }, | |
| 236 | { id: "agent", label: "Agent", description: "Read everything, work on issues and pull requests, push code and run g1t agents." }, | |
| Merge checks: statuses and check runs on every commit | 237 | { id: "ci", label: "CI", description: "Clone and push code, push and pull packages, run workflows, and report checks and deployments." }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 238 | { id: "full", label: "Full access", description: "Everything you can do, including deleting repositories and changing who has access." }, |
| 239 | ]; | |
| 240 | ||
| 241 | /** The scopes of a preset, or null for full access. */ | |
| 242 | export function presetScopes(id: PresetId): Scope[] | null { | |
| 243 | if (id === "full") return null; | |
| 244 | return [...PRESET_SCOPES[id]] as Scope[]; | |
| 245 | } | |
| 246 | ||
| 247 | /** What an OAuth client gets when it asks for nothing in particular. */ | |
| 248 | export const OAUTH_DEFAULT_SCOPES: Scope[] = [...PRESET_SCOPES.agent]; | |
| 249 | ||
| 250 | /** The operation each scope gates, by the API's operation names. */ | |
| 251 | export const OPERATION_SCOPES = [ | |
| 252 | ["list_emails", "account:read"], | |
| 253 | ["add_email", "account:write"], | |
| Merge email confirmation gate: a code and a link, nothing until confirmed (identity 0036) | 254 | ["confirm_email", "account:write"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 255 | ["remove_email", "account:write"], |
| 256 | ["update_email_settings", "account:write"], | |
| 257 | ["list_invites", "account:read"], | |
| 258 | ["create_invite", "account:write"], | |
| 259 | ["revoke_invite", "account:write"], | |
| Merge workspace invitations: nobody joins a workspace without saying yes, people are found by username, your own invites can bring someone in, and nobody is left without a workspace (identity 0040) | 260 | ["list_invitations", "account:read"], |
| 261 | ["accept_invitation", "account:write"], | |
| 262 | ["decline_invitation", "account:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 263 | ["list_my_repo_invitations", "account:read"], |
| 264 | ["accept_repo_invitation", "account:write"], | |
| 265 | ["decline_repo_invitation", "account:write"], | |
| API: pinned projects over REST and MCP | 266 | // Your pinned projects: a preference of your account. |
| 267 | ["list_pinned_projects", "account:read"], | |
| 268 | ["pin_project", "account:write"], | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 269 | // Your stars: a preference of your account. |
| 270 | ["list_starred", "account:read"], | |
| 271 | ["check_starred", "account:read"], | |
| 272 | ["star_repo", "account:write"], | |
| 273 | ["unstar_repo", "account:write"], | |
| API: pinned projects over REST and MCP | 274 | ["unpin_project", "account:write"], |
| 275 | ["reorder_pinned_projects", "account:write"], | |
| API: notifications over REST and MCP, with notifications scopes | 276 | // Your inbox: notifications, subscriptions and watching. |
| 277 | ["list_notifications", "notifications:read"], | |
| 278 | ["get_notification_thread", "notifications:read"], | |
| 279 | ["get_thread_subscription", "notifications:read"], | |
| 280 | ["get_repo_subscription", "notifications:read"], | |
| 281 | ["list_watched_repos", "notifications:read"], | |
| 282 | ["mark_notifications_read", "notifications:write"], | |
| 283 | ["mark_thread_read", "notifications:write"], | |
| 284 | ["mark_thread_done", "notifications:write"], | |
| 285 | ["save_thread", "notifications:write"], | |
| 286 | ["snooze_thread", "notifications:write"], | |
| 287 | ["set_thread_subscription", "notifications:write"], | |
| 288 | ["delete_thread_subscription", "notifications:write"], | |
| 289 | ["set_repo_subscription", "notifications:write"], | |
| 290 | ["delete_repo_subscription", "notifications:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 291 | ["create_workspace", "workspace:admin"], |
| 292 | ["delete_workspace", "workspace:admin"], | |
| Merge branch 'worktree-agent-ad7c6d88d93adc817' | 293 | ["get_workspace", "workspace:read"], |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 294 | ["update_workspace", "workspace:admin"], |
| Merge main (membership, two-factor, GitHub repo roles) into tokens | 295 | ["list_members", "workspace:read"], |
| 296 | ["update_member", "workspace:admin"], | |
| 297 | ["remove_member", "workspace:admin"], | |
| 298 | ["transfer_ownership", "workspace:admin"], | |
| 299 | ["leave_workspace", "account:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 300 | ["list_workspace_invites", "workspace:read"], |
| 301 | ["invite_member", "workspace:admin"], | |
| 302 | ["revoke_workspace_invite", "workspace:admin"], | |
| 303 | ["list_integrations", "workspace:read"], | |
| 304 | ["connect_integration", "workspace:admin"], | |
| AI Gateway: OpenAI's format, open models, and your own providers | 305 | ["update_integration", "workspace:admin"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 306 | ["disconnect_integration", "workspace:admin"], |
| 307 | ["test_integration", "workspace:admin"], | |
| 308 | ["get_model_routes", "workspace:read"], | |
| 309 | ["set_model_routes", "workspace:admin"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 310 | ["list_teams", "workspace:read"], |
| 311 | ["get_team", "workspace:read"], | |
| 312 | ["list_team_members", "workspace:read"], | |
| 313 | ["list_child_teams", "workspace:read"], | |
| 314 | ["list_team_repos", "workspace:read"], | |
| 315 | ["list_user_teams", "workspace:read"], | |
| 316 | ["create_team", "workspace:admin"], | |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 317 | ["list_workspace_rulesets", "workspace:read"], |
| 318 | ["get_workspace_ruleset", "workspace:read"], | |
| 319 | ["list_workspace_rule_evaluations", "workspace:read"], | |
| 320 | ["create_workspace_ruleset", "workspace:admin"], | |
| 321 | ["update_workspace_ruleset", "workspace:admin"], | |
| 322 | ["delete_workspace_ruleset", "workspace:admin"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 323 | ["update_team", "workspace:admin"], |
| 324 | ["delete_team", "workspace:admin"], | |
| 325 | ["set_team_member", "workspace:admin"], | |
| 326 | ["remove_team_member", "workspace:admin"], | |
| 327 | ["set_team_review_assignment", "workspace:admin"], | |
| Usage, Billing settings and prepaid AI credit; fixes from the UX audit | 328 | // A workspace's billing: usage, budget, AI credit and invoices. |
| 329 | ["get_usage", "billing:read"], | |
| 330 | ["get_budget", "billing:read"], | |
| 331 | ["get_ai_credit", "billing:read"], | |
| 332 | ["list_invoices", "billing:read"], | |
| 333 | ["get_billing_details", "billing:read"], | |
| 334 | ["set_budget", "billing:write"], | |
| 335 | ["buy_ai_credit", "billing:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 336 | ["list_repos", "repo:read"], |
| 337 | ["get_repo", "repo:read"], | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 338 | // Projects follow their repositories. |
| 339 | ["list_projects", "repo:read"], | |
| 340 | ["get_project", "repo:read"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 341 | ["search", "repo:read"], |
| 342 | ["list_events", "repo:read"], | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 343 | // What the default branch says about a repository, who starred it, and |
| 344 | // its releases. | |
| 345 | ["get_languages", "repo:read"], | |
| 346 | ["list_contributors", "repo:read"], | |
| 347 | ["get_license", "repo:read"], | |
| 348 | ["list_stargazers", "repo:read"], | |
| 349 | ["list_releases", "repo:read"], | |
| 350 | ["get_latest_release", "repo:read"], | |
| 351 | ["get_release_by_tag", "repo:read"], | |
| 352 | ["get_release", "repo:read"], | |
| 353 | ["create_release", "repo:write"], | |
| 354 | ["update_release", "repo:write"], | |
| 355 | ["delete_release", "repo:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 356 | ["list_labels", "repo:read"], |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 357 | ["list_milestones", "repo:read"], |
| 358 | ["get_milestone", "repo:read"], | |
| 359 | ["create_label", "issues:write"], | |
| 360 | ["update_label", "issues:write"], | |
| 361 | ["delete_label", "issues:write"], | |
| 362 | ["add_default_labels", "issues:write"], | |
| 363 | ["create_milestone", "issues:write"], | |
| 364 | ["update_milestone", "issues:write"], | |
| 365 | ["delete_milestone", "issues:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 366 | ["get_repo_settings", "repo:read"], |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 367 | ["list_check_names", "repo:read"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 368 | ["list_deleted_repos", "repo:read"], |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 369 | ["list_security_alerts", "repo:read"], |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 370 | ["get_codeowners_errors", "repo:read"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 371 | ["create_repo", "repo:write"], |
| 372 | ["update_repo", "repo:write"], | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 373 | ["update_project", "repo:write"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 374 | ["update_repo_settings", "repo:write"], |
| Merge rulesets: branch and tag rules, agent-first, enforced on push and merge | 375 | ["list_repo_rulesets", "repo:read"], |
| 376 | ["get_repo_ruleset", "repo:read"], | |
| 377 | ["get_branch_rules", "repo:read"], | |
| 378 | ["list_rule_evaluations", "repo:read"], | |
| 379 | ["create_repo_ruleset", "repo:admin"], | |
| 380 | ["update_repo_ruleset", "repo:admin"], | |
| 381 | ["delete_repo_ruleset", "repo:admin"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 382 | ["rename_branch", "repo:write"], |
| 383 | ["rename_repo", "repo:admin"], | |
| 384 | ["transfer_repo", "repo:admin"], | |
| 385 | ["archive_repo", "repo:admin"], | |
| 386 | ["unarchive_repo", "repo:admin"], | |
| 387 | ["set_repo_visibility", "repo:admin"], | |
| 388 | ["delete_repo", "repo:admin"], | |
| 389 | ["restore_repo", "repo:admin"], | |
| 390 | ["purge_repo", "repo:admin"], | |
| Git storage hardened, pages in tens of milliseconds, honest security alerts, and costs reconciled daily | 391 | ["dismiss_security_alert", "repo:admin"], |
| 392 | ["reopen_security_alert", "repo:admin"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 393 | // The security suite. |
| 394 | ["list_secret_scanning_alerts", "security:read"], | |
| 395 | ["get_secret_scanning_alert", "security:read"], | |
| 396 | ["list_secret_scanning_locations", "security:read"], | |
| 397 | ["list_bypass_requests", "security:read"], | |
| 398 | ["list_custom_patterns", "security:read"], | |
| 399 | ["list_code_scanning_alerts", "security:read"], | |
| 400 | ["get_code_scanning_alert", "security:read"], | |
| 401 | ["list_code_scanning_analyses", "security:read"], | |
| 402 | ["get_sarif_upload", "security:read"], | |
| 403 | ["list_vulnerability_alerts", "security:read"], | |
| 404 | ["get_vulnerability_alert", "security:read"], | |
| 405 | ["get_dependency_graph", "security:read"], | |
| 406 | ["get_sbom", "security:read"], | |
| 407 | ["compare_dependencies", "security:read"], | |
| 408 | ["get_security_settings", "security:read"], | |
| 409 | ["get_workspace_security_settings", "security:read"], | |
| 410 | ["get_security_overview", "security:read"], | |
| 411 | ["update_secret_scanning_alert", "security:write"], | |
| 412 | ["bypass_push_protection", "security:write"], | |
| 413 | ["check_secret_validity", "security:write"], | |
| 414 | ["review_bypass_request", "security:write"], | |
| 415 | ["create_custom_pattern", "security:write"], | |
| 416 | ["update_custom_pattern", "security:write"], | |
| 417 | ["delete_custom_pattern", "security:write"], | |
| 418 | ["dry_run_custom_pattern", "security:write"], | |
| 419 | ["update_code_scanning_alert", "security:write"], | |
| 420 | ["upload_sarif", "security:write"], | |
| 421 | ["update_vulnerability_alert", "security:write"], | |
| 422 | ["fix_security_alert", "security:write"], | |
| 423 | ["update_security_settings", "security:write"], | |
| 424 | ["update_workspace_security_settings", "security:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 425 | ["list_issues", "issues:read"], |
| 426 | ["get_issue", "issues:read"], | |
| 427 | ["get_plan", "issues:read"], | |
| 428 | ["create_issue", "issues:write"], | |
| 429 | ["update_issue", "issues:write"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 430 | ["list_issue_labels", "issues:read"], |
| 431 | ["add_issue_labels", "issues:write"], | |
| 432 | ["set_issue_labels", "issues:write"], | |
| 433 | ["remove_issue_labels", "issues:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 434 | ["close_issue", "issues:write"], |
| 435 | ["reopen_issue", "issues:write"], | |
| 436 | ["add_comment", "issues:write"], | |
| Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts | 437 | ["edit_comment", "issues:write"], |
| 438 | ["delete_comment", "issues:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 439 | ["import_issue", "issues:write"], |
| 440 | ["apply_plan", "issues:write"], | |
| 441 | ["list_pull_requests", "pull_requests:read"], | |
| 442 | ["get_pull_request", "pull_requests:read"], | |
| 443 | ["get_pull_request_changes", "pull_requests:read"], | |
| 444 | ["read_session", "pull_requests:read"], | |
| 445 | ["get_merge_queue", "pull_requests:read"], | |
| 446 | ["create_pull_request", "pull_requests:write"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 447 | ["update_pull_request", "pull_requests:write"], |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 448 | ["record_session", "pull_requests:write"], |
| 449 | ["mark_pull_request_ready", "pull_requests:write"], | |
| 450 | ["close_pull_request", "pull_requests:write"], | |
| Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts | 451 | ["reopen_pull_request", "pull_requests:write"], |
| 452 | ["convert_pull_request_to_draft", "pull_requests:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 453 | ["review_pull_request", "pull_requests:write"], |
| 454 | ["merge_pull_request", "pull_requests:write"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 455 | ["request_reviewers", "pull_requests:write"], |
| 456 | ["remove_requested_reviewers", "pull_requests:write"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 457 | ["assign_issue", "agents:run"], |
| 458 | ["delegate", "agents:run"], | |
| 459 | ["plan_work", "agents:run"], | |
| 460 | ["message_agent", "agents:run"], | |
| 461 | ["answer_message", "agents:run"], | |
| 462 | ["take_messages", "agents:run"], | |
| 463 | ["list_workflows", "workflows:read"], | |
| 464 | ["list_workflow_runs", "workflows:read"], | |
| 465 | ["get_workflow_run", "workflows:read"], | |
| 466 | ["get_job_logs", "workflows:read"], | |
| 467 | ["dispatch_workflow", "workflows:write"], | |
| 468 | ["cancel_workflow_run", "workflows:write"], | |
| 469 | ["rerun_workflow_run", "workflows:write"], | |
| 470 | ["update_workflow", "workflows:write"], | |
| Actions: OIDC tokens, the toolkit's cache and artifact services, and artifacts in R2 | 471 | ["list_artifacts", "workflows:read"], |
| 472 | ["list_workflow_run_artifacts", "workflows:read"], | |
| 473 | ["get_artifact", "workflows:read"], | |
| 474 | ["download_artifact", "workflows:read"], | |
| 475 | ["get_artifact_retention", "workflows:read"], | |
| 476 | ["delete_artifact", "workflows:write"], | |
| 477 | ["set_artifact_retention", "workflows:write"], | |
| Merge checks: statuses and check runs on every commit | 478 | ["list_commit_statuses", "checks:read"], |
| 479 | ["get_combined_status", "checks:read"], | |
| 480 | ["list_check_runs_for_ref", "checks:read"], | |
| 481 | ["get_check_run", "checks:read"], | |
| 482 | ["list_check_run_annotations", "checks:read"], | |
| 483 | ["list_check_suites_for_ref", "checks:read"], | |
| 484 | ["get_check_suite", "checks:read"], | |
| 485 | ["create_commit_status", "checks:write"], | |
| 486 | ["create_check_run", "checks:write"], | |
| 487 | ["update_check_run", "checks:write"], | |
| 488 | ["rerequest_check_run", "checks:write"], | |
| 489 | ["rerequest_check_suite", "checks:write"], | |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 490 | // Deployments, wherever they run: reading them, and reporting them. |
| 491 | ["list_deployments", "deployments:read"], | |
| 492 | ["get_deployment", "deployments:read"], | |
| 493 | ["list_deployment_statuses", "deployments:read"], | |
| 494 | ["list_environments", "deployments:read"], | |
| 495 | ["get_environment", "deployments:read"], | |
| 496 | ["create_deployment", "deployments:write"], | |
| 497 | ["create_deployment_status", "deployments:write"], | |
| Merge branch 'worktree-agent-a3abfcce648e87dca' | 498 | // What keeps runs safe: the runs environments hold and reviewing them, |
| 499 | // approving a pull request's run, and a repository's own rules for its | |
| 500 | // environments and tokens, which are an admin's. | |
| 501 | ["get_pending_deployments", "workflows:read"], | |
| 502 | ["review_pending_deployments", "workflows:write"], | |
| 503 | ["approve_workflow_run", "workflows:write"], | |
| 504 | ["get_workflow_permissions", "repo:read"], | |
| 505 | ["get_fork_pr_approval", "repo:read"], | |
| Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts | 506 | ["get_actions_access", "repo:read"], |
| Merge branch 'worktree-agent-a3abfcce648e87dca' | 507 | ["update_environment", "repo:admin"], |
| 508 | ["delete_environment", "repo:admin"], | |
| 509 | ["set_workflow_permissions", "repo:admin"], | |
| 510 | ["set_fork_pr_approval", "repo:admin"], | |
| Merge Actions: cross-repo workflows and actions, release and deployment triggers, step timeouts | 511 | ["set_actions_access", "repo:admin"], |
| Merge branch 'worktree-agent-a3abfcce648e87dca' | 512 | // Starting workflows from outside, as a push would. |
| 513 | ["create_repository_dispatch", "code:write"], | |
| 514 | // A workspace's policy for its repositories' tokens. | |
| 515 | ["get_workspace_workflow_permissions", "workspace:read"], | |
| 516 | ["set_workspace_workflow_permissions", "workspace:admin"], | |
| API and MCP for a workspace's personal access token rules, members' tokens and approvals | 517 | // A workspace's rules for personal access tokens, and its members' tokens. |
| 518 | ["get_token_policy", "workspace:read"], | |
| 519 | ["set_token_policy", "workspace:admin"], | |
| 520 | ["list_member_tokens", "access:read"], | |
| 521 | ["list_token_requests", "access:read"], | |
| 522 | ["review_token_request", "access:admin"], | |
| 523 | ["revoke_member_token", "access:admin"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 524 | ["recall", "memory:read"], |
| 525 | ["search_context", "memory:read"], | |
| 526 | ["get_entity", "memory:read"], | |
| 527 | ["get_context", "memory:read"], | |
| 528 | ["remember", "memory:write"], | |
| 529 | ["list_collaborators", "access:read"], | |
| 530 | ["get_collaborator_permission", "access:read"], | |
| 531 | ["list_repo_invitations", "access:read"], | |
| 532 | ["list_outside_collaborators", "access:read"], | |
| 533 | ["add_collaborator", "access:admin"], | |
| 534 | ["update_collaborator", "access:admin"], | |
| 535 | ["remove_collaborator", "access:admin"], | |
| 536 | ["revoke_repo_invitation", "access:admin"], | |
| 537 | ["set_base_permission", "access:admin"], | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 538 | ["set_team_repo", "access:admin"], |
| 539 | ["remove_team_repo", "access:admin"], | |
| Merge branch 'worktree-agent-a5a5de74d8863d554' into worktree-agent-a16631325aecf58ca | 540 | ["list_deploy_keys", "access:read"], |
| 541 | ["get_deploy_key", "access:read"], | |
| 542 | ["create_deploy_key", "access:admin"], | |
| 543 | ["delete_deploy_key", "access:admin"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 544 | ["list_webhooks", "webhooks:read"], |
| 545 | ["list_webhook_deliveries", "webhooks:read"], | |
| 546 | ["create_webhook", "webhooks:admin"], | |
| 547 | ["update_webhook", "webhooks:admin"], | |
| 548 | ["delete_webhook", "webhooks:admin"], | |
| 549 | ["ping_webhook", "webhooks:admin"], | |
| 550 | ["redeliver_webhook", "webhooks:admin"], | |
| 551 | ["list_actions_secrets", "secrets:read"], | |
| 552 | ["list_actions_variables", "secrets:read"], | |
| 553 | ["set_actions_secret", "secrets:admin"], | |
| 554 | ["delete_actions_secret", "secrets:admin"], | |
| 555 | ["set_actions_variable", "secrets:admin"], | |
| 556 | ["delete_actions_variable", "secrets:admin"], | |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 557 | // Self-hosted runners. |
| 558 | ["list_runners", "runners:read"], | |
| 559 | ["list_runner_groups", "runners:read"], | |
| 560 | ["get_runner_settings", "runners:read"], | |
| 561 | ["create_runner_registration_token", "runners:admin"], | |
| 562 | ["remove_runner", "runners:admin"], | |
| 563 | ["create_runner_group", "runners:admin"], | |
| 564 | ["update_runner_group", "runners:admin"], | |
| 565 | ["delete_runner_group", "runners:admin"], | |
| 566 | ["update_runner_settings", "runners:admin"], | |
| Merge packages: roles, Actions access, source label, soft delete, API | 567 | // Packages: reading them, their versions and who may use them needs |
| 568 | // `packages:read`; changing their settings, access and Manage Actions | |
| 569 | // access `packages:write` (and the Admin role on the package, which the | |
| 570 | // packages service checks); deleting and restoring packages and | |
| 571 | // versions `packages:delete`, as the registries' own deletes do. | |
| 572 | ["list_packages", "packages:read"], | |
| 573 | ["get_package", "packages:read"], | |
| 574 | ["list_package_versions", "packages:read"], | |
| 575 | ["get_package_version", "packages:read"], | |
| 576 | ["list_package_access", "packages:read"], | |
| 577 | ["list_package_actions_access", "packages:read"], | |
| 578 | ["update_package", "packages:write"], | |
| 579 | ["link_package", "packages:write"], | |
| 580 | ["unlink_package", "packages:write"], | |
| 581 | ["set_package_access", "packages:write"], | |
| 582 | ["remove_package_access", "packages:write"], | |
| 583 | ["set_package_actions_access", "packages:write"], | |
| 584 | ["remove_package_actions_access", "packages:write"], | |
| 585 | ["delete_package", "packages:delete"], | |
| 586 | ["restore_package", "packages:delete"], | |
| 587 | ["delete_package_version", "packages:delete"], | |
| 588 | ["restore_package_version", "packages:delete"], | |
| Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens | 589 | // The AI Gateway. Sending a request to a model needs `models:write`, |
| 590 | // checked by the model proxy at models.g1t.sh. | |
| 591 | ["list_gateway_requests", "models:read"], | |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 592 | ] as const; |
| 593 | ||
| 594 | /** | |
| 595 | * The scopes a token or grant holds, as stored: null for full access, or | |
| 596 | * the list. `legacy` marks a token made before scopes, which has full | |
| 597 | * access until someone narrows it. | |
| 598 | */ | |
| 599 | export type TokenScopes = { | |
| 600 | scopes: Scope[] | null; | |
| 601 | legacy: boolean; | |
| 602 | }; | |
| 603 | ||
| 604 | /** | |
| 605 | * How settings group scopes into a checklist: each group's scopes, least | |
| 606 | * first. Admin scopes are not here; they are under "Dangerous" on their | |
| 607 | * own (see `DANGEROUS_SCOPES`). Every other scope is in exactly one group. | |
| 608 | */ | |
| 609 | export const SCOPE_GROUPS: { id: string; label: string; scopes: Scope[] }[] = [ | |
| 610 | { id: "code", label: "Repositories & code", scopes: ["repo:read", "repo:write", "code:read", "code:write"] }, | |
| Teams and CODEOWNERS, labels and milestones, dependency updates, the security suite, and a clearer top bar | 611 | { id: "security", label: "Security", scopes: ["security:read", "security:write"] }, |
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 612 | { id: "packages", label: "Packages", scopes: ["packages:read", "packages:write"] }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 613 | { id: "work", label: "Issues & pull requests", scopes: ["issues:read", "issues:write", "pull_requests:read", "pull_requests:write"] }, |
| 614 | { id: "agents", label: "Agents", scopes: ["agents:run"] }, | |
| Token reach: workflow_files scope, fine-grained reach, workspace token cap | 615 | { id: "workflows", label: "Workflows", scopes: ["workflows:read", "workflows:write", "workflow_files:write"] }, |
| Merge checks: statuses and check runs on every commit | 616 | { id: "checks", label: "Checks", scopes: ["checks:read", "checks:write"] }, |
| Merge branch 'main' into worktree-agent-a69aeabc4b0deeb97 | 617 | { id: "deployments", label: "Deployments", scopes: ["deployments:read", "deployments:write"] }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 618 | { id: "memory", label: "Memory & search", scopes: ["memory:read", "memory:write"] }, |
| 619 | { id: "account", label: "Account", scopes: ["account:read", "account:write"] }, | |
| API: notifications over REST and MCP, with notifications scopes | 620 | { id: "notifications", label: "Notifications", scopes: ["notifications:read", "notifications:write"] }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 621 | { id: "workspace", label: "Workspace", scopes: ["workspace:read", "access:read", "webhooks:read", "secrets:read"] }, |
| Usage, Billing settings and prepaid AI credit; fixes from the UX audit | 622 | { id: "billing", label: "Billing", scopes: ["billing:read", "billing:write"] }, |
| Fast pages, required checks on the branch, self-hosted runners, honest incidents | 623 | { id: "runners", label: "Runners", scopes: ["runners:read"] }, |
| Merge the AI Gateway: Anthropic's Messages API on a workspace's tokens | 624 | { id: "models", label: "AI Gateway", scopes: ["models:read", "models:write"] }, |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 625 | ]; |
| 626 | ||
| Packages, with a container registry on g1t.sh; workspaces deleted whole and kept 30 days; Members for every member | 627 | /** The admin and delete scopes, shown under "Dangerous" behind a warning. */ |
| Thirteen MCP tools and classic token scopes; agents rate their confidence and can be put on an issue in one step | 628 | export const DANGEROUS_SCOPES: Scope[] = SCOPES.map((row) => row.scope).filter(isDangerous); |
This file's history is long; its oldest lines are credited to the oldest commit read.