Skip to main content
Use a signed JWT for repository HTTP requests and Git over HTTPS. Authentication explains private keys and token signing.

Repository claims

Set the JWT repo claim to the target repository name. A {repo_name} path value must equal the claim, and POST /api/repos takes the new repository name from it. Authentication lists the rules and the errors for the claim. For example, this token allows a client to read and write team/project-alpha:
Use these claims with the shared signing examples. Git clients put the token in a Git remote URL.

Permission scopes

Storage operations use the git:read, git:write, repo:write, and org:read scopes. Authentication lists every scope and the operations that need it. git:write does not grant read access. Add git:read when a client must clone or fetch before it pushes.

Limit ref writes

The git:write scope permits updates to all refs by default. Add a ref policy when a JWT needs narrower write access. A ref policy can limit branches, tags, notes, and refs in a namespace. It can also reject force pushes or require commit signatures. See Ref Policies for the JWT claim and SDK options. See Commit Signing for key setup and signature checks.