Skip to content

Commit

llms.txt: workflow files and fine-grained tokens

syntaqxcommitted Parentbbe0d4aBrowse files
1 file+7−10/1 viewed
+7−1
325325 what a call may do is the owner's role and the token's scopes together.
326326 A token sees only the MCP tools and actions its scopes allow. A missing scope answers `403` with
327327 `{"error": {"code": "forbidden", "message": "This access token needs the issues:write scope to use create_issue.", "needed_scope": "issues:write"}}`.
328−Pushing needs `code:write`; cloning a private repository `code:read`. For
328+Pushing needs `code:write`; cloning a private repository `code:read`.
329+Pushing commits that add, change or delete files under `.g1t/workflows/`
330+or `.github/workflows/` also needs `workflow_files:write` (in no preset
331+but full access); a workflow job's token never has it. A fine-grained
332+token reaches one workspace (or only its owner's account), all, chosen or
333+only public repositories of it, with permissions (`contents`, `issues`,
334+`workflows`, …) mapped to these scopes; a workspace may require an owner to approve one first. For
329335 an agent, use the Agent preset (every read scope but `runners:read`, plus `code:write`,
330336 `issues:write`, `pull_requests:write`, `agents:run`, `memory:write`,
331337 `notifications:write`). For CI, the CI preset (`repo:read`, `code:read`,