llms.txt: workflow files and fine-grained tokens
1 file+7−10/1 viewed
| 325 | 325 | what a call may do is the owner's role and the token's scopes together. | |
| 326 | 326 | A token sees only the MCP tools and actions its scopes allow. A missing scope answers `403` with | |
| 327 | 327 | `{"error": {"code": "forbidden", "message": "This access token needs the issues:write scope to use create_issue.", "needed_scope": "issues:write"}}`. | |
| 328 | − | Pushing needs `code:write`; cloning a private repository `code:read`. For | |
| 328 | + | Pushing needs `code:write`; cloning a private repository `code:read`. | |
| 329 | + | Pushing commits that add, change or delete files under `.g1t/workflows/` | |
| 330 | + | or `.github/workflows/` also needs `workflow_files:write` (in no preset | |
| 331 | + | but full access); a workflow job's token never has it. A fine-grained | |
| 332 | + | token reaches one workspace (or only its owner's account), all, chosen or | |
| 333 | + | only public repositories of it, with permissions (`contents`, `issues`, | |
| 334 | + | `workflows`, …) mapped to these scopes; a workspace may require an owner to approve one first. For | |
| 329 | 335 | an agent, use the Agent preset (every read scope but `runners:read`, plus `code:write`, | |
| 330 | 336 | `issues:write`, `pull_requests:write`, `agents:run`, `memory:write`, | |
| 331 | 337 | `notifications:write`). For CI, the CI preset (`repo:read`, `code:read`, |