Repository claims
Set the JWTrepo claim to the target repository name. A {repo_name} path value must equal the
claim, and POST /api/repos takes the new repository name from it.
Authentication lists the rules and the errors for the
claim.
For example, this token allows a client to read and write team/project-alpha:
Permission scopes
Storage operations use thegit:read, git:write, repo:write, and org:read scopes.
Authentication lists every scope and the operations that need it.
git:write does not grant read access. Add git:read when a client must clone or fetch before it
pushes.
Limit ref writes
Thegit:write scope permits updates to all refs by default. Add a ref policy when a JWT needs
narrower write access.
A ref policy can limit branches, tags, notes, and refs in a namespace. It can also reject force
pushes or require commit signatures.
See Ref Policies for the JWT claim and SDK options. See
Commit Signing for key setup and signature checks.