You can now limit the scopes a key can grant in Code Storage. Give each agent or service a restricted key with only the permissions it needs. Code Storage rejects tokens that request a scope outside the key's allowlist, even when the signature is valid.
To create a key that can list repositories and read their contents:
- Open Keys in your organization dashboard and select Create key.
- Enter a name for the key.
- Enable Limit scope for this key.
- Leave Git read (
git:read) and Organization read (org:read) selected. Deselect the write scopes. - Select Create key and copy the private key to your secret manager.
This key allows tokens to request git:read, org:read, or both. If a token requests git:write
or repo:write, Code Storage rejects it.
Code Storage stores only the public key. Your browser creates the key pair, and we cannot show the private key again.
New keys are unrestricted by default. If you leave every scope selected, the dashboard also saves an unrestricted key.
Tokens from restricted keys must include iat and exp, with a lifetime of at most one hour.
See the authentication docs for how to use restricted and unrestricted keys, sign tokens, and choose scopes.