---
title: "App Permissions"
url: "https://kiwi.arashsheyda.me/apis/git-hub-v3-rest-api-1/versions/4cb06d26-20a0-409c-8492-8406889b7eb4/schemas/app-permissions"
---

> Full API specification: https://kiwi.arashsheyda.me/apis/git-hub-v3-rest-api-1/versions/4cb06d26-20a0-409c-8492-8406889b7eb4.md

# App Permissions

The permissions granted to the user-to-server access token.

## OpenAPI definition

```yaml
openapi: 3.0.3
info:
  title: GitHub v3 REST API
  version: 1.1.4
servers:
  - url: "{protocol}://{hostname}/api/v3"
    variables:
      hostname:
        description: Self-hosted Enterprise Server or Enterprise Cloud hostname
        default: HOSTNAME
      protocol:
        description: Self-hosted Enterprise Server or Enterprise Cloud protocol
        default: http
components:
  schemas:
    app-permissions:
      title: App Permissions
      type: object
      description: The permissions granted to the user-to-server access token.
      properties:
        actions:
          type: string
          description: "The level of permission to grant the access token for GitHub
            Actions workflows, workflow runs, and artifacts. Can be one of:
            `read` or `write`."
          enum:
            - read
            - write
        administration:
          type: string
          description: "The level of permission to grant the access token for repository
            creation, deletion, settings, teams, and collaborators creation. Can
            be one of: `read` or `write`."
          enum:
            - read
            - write
        checks:
          type: string
          description: "The level of permission to grant the access token for checks on
            code. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        contents:
          type: string
          description: "The level of permission to grant the access token for repository
            contents, commits, branches, downloads, releases, and merges. Can be
            one of: `read` or `write`."
          enum:
            - read
            - write
        deployments:
          type: string
          description: "The level of permission to grant the access token for deployments
            and deployment statuses. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        environments:
          type: string
          description: "The level of permission to grant the access token for managing
            repository environments. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        issues:
          type: string
          description: "The level of permission to grant the access token for issues and
            related comments, assignees, labels, and milestones. Can be one of:
            `read` or `write`."
          enum:
            - read
            - write
        metadata:
          type: string
          description: "The level of permission to grant the access token to search
            repositories, list collaborators, and access repository metadata.
            Can be one of: `read` or `write`."
          enum:
            - read
            - write
        packages:
          type: string
          description: "The level of permission to grant the access token for packages
            published to GitHub Packages. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        pages:
          type: string
          description: "The level of permission to grant the access token to retrieve
            Pages statuses, configuration, and builds, as well as create new
            builds. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        pull_requests:
          type: string
          description: "The level of permission to grant the access token for pull
            requests and related comments, assignees, labels, milestones, and
            merges. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        repository_hooks:
          type: string
          description: "The level of permission to grant the access token to manage the
            post-receive hooks for a repository. Can be one of: `read` or
            `write`."
          enum:
            - read
            - write
        repository_projects:
          type: string
          description: "The level of permission to grant the access token to manage
            repository projects, columns, and cards. Can be one of: `read`,
            `write`, or `admin`."
          enum:
            - read
            - write
            - admin
        secret_scanning_alerts:
          type: string
          description: "The level of permission to grant the access token to view and
            manage secret scanning alerts. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        secrets:
          type: string
          description: "The level of permission to grant the access token to manage
            repository secrets. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        security_events:
          type: string
          description: "The level of permission to grant the access token to view and
            manage security events like code scanning alerts. Can be one of:
            `read` or `write`."
          enum:
            - read
            - write
        single_file:
          type: string
          description: "The level of permission to grant the access token to manage just a
            single file. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        statuses:
          type: string
          description: "The level of permission to grant the access token for commit
            statuses. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        vulnerability_alerts:
          type: string
          description: "The level of permission to grant the access token to manage
            Dependabot alerts. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        workflows:
          type: string
          description: "The level of permission to grant the access token to update GitHub
            Actions workflow files. Can be one of: `write`."
          enum:
            - write
        members:
          type: string
          description: "The level of permission to grant the access token for organization
            teams and members. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        organization_administration:
          type: string
          description: "The level of permission to grant the access token to manage access
            to an organization. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        organization_hooks:
          type: string
          description: "The level of permission to grant the access token to manage the
            post-receive hooks for an organization. Can be one of: `read` or
            `write`."
          enum:
            - read
            - write
        organization_plan:
          type: string
          description: "The level of permission to grant the access token for viewing an
            organization's plan. Can be one of: `read`."
          enum:
            - read
        organization_projects:
          type: string
          description: "The level of permission to grant the access token to manage
            organization projects and projects beta (where available). Can be
            one of: `read`, `write`, or `admin`."
          enum:
            - read
            - write
            - admin
        organization_packages:
          type: string
          description: "The level of permission to grant the access token for organization
            packages published to GitHub Packages. Can be one of: `read` or
            `write`."
          enum:
            - read
            - write
        organization_secrets:
          type: string
          description: "The level of permission to grant the access token to manage
            organization secrets. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        organization_self_hosted_runners:
          type: string
          description: "The level of permission to grant the access token to view and
            manage GitHub Actions self-hosted runners available to an
            organization. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        organization_user_blocking:
          type: string
          description: "The level of permission to grant the access token to view and
            manage users blocked by the organization. Can be one of: `read` or
            `write`."
          enum:
            - read
            - write
        team_discussions:
          type: string
          description: "The level of permission to grant the access token to manage team
            discussions and related comments. Can be one of: `read` or `write`."
          enum:
            - read
            - write
        content_references:
          type: string
          description: "The level of permission to grant the access token for notification
            of content references and creation content attachments. Can be one
            of: `read` or `write`."
          enum:
            - read
            - write
      example:
        contents: read
        issues: read
        deployments: write
        single_file: read
```
