> ## Documentation Index
> Fetch the complete documentation index at: https://code.storage/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Access & Permissions

> Choose Storage scopes, repository claims, and ref policies for each client.

Use a signed JWT for repository HTTP requests and Git over HTTPS.
[Authentication](/docs/platform/authentication) explains private keys and token signing.

## Repository claims

Set the JWT `repo` claim to the target repository name. A `{repo_name}` path value must equal the
claim, and `POST /api/repos` takes the new repository name from it.
[Authentication](/docs/platform/authentication#repository-claim) lists the rules and the errors for the
claim.

For example, this token allows a client to read and write `team/project-alpha`:

```jsonc theme={"theme":{"light":"github-light","dark":"min-dark"}}
{
  "iss": "your-org",
  "sub": "ci-pipeline-prod",
  "repo": "team/project-alpha",
  "scopes": ["git:read", "git:write"],
  "iat": 1723453189, // Replace with the current Unix timestamp.
  "exp": 1723456789, // Set an expiration after iat.
}
```

Use these claims with the [shared signing examples](/docs/platform/authentication#how-to-sign-a-jwt). Git
clients put the token in a [Git remote URL](/docs/repos/git-operations#authentication-format).

## Permission scopes

Storage operations use the `git:read`, `git:write`, `repo:write`, and `org:read` scopes.
[Authentication](/docs/platform/authentication#scopes) lists every scope and the operations that need it.

`git:write` does not grant read access. Add `git:read` when a client must clone or fetch before it
pushes.

## Limit ref writes

The `git:write` scope permits updates to all refs by default. Add a ref policy when a JWT needs
narrower write access.

A ref policy can limit branches, tags, notes, and refs in a namespace. It can also reject force
pushes or require commit signatures.

See [Ref Policies](/docs/repos/ref-policies) for the JWT claim and SDK options. See
[Commit Signing](/docs/repos/commit-signing) for key setup and signature checks.
