neosourceDocs
Search docs

Grant a team or account a role on a repository

POST/api/repos/{owner}/{repo}/grants

addRepoGrant

Adds (or upserts) a per-repo grant. Required role: `repo:admin`. Re-adding an existing grantee with a new role updates the role.

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X POST 'https://neosource.dev/api/repos/OWNER/REPO/grants' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{"grantee_kind":"string","grantee_id":"string","role":"string"}'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/grants", {
  method: "POST",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({"grantee_kind":"string","grantee_id":"string","role":"string"}),
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

Request bodyrequired

application/json

AddRepoGrantRequest

object

grantee_idrequired

string

Team key for `team`, or account handle for `account`.

grantee_kindrequired

GranteeKind

string

Discriminator for the two grantee shapes of a [`RepoGrantee`], as it appears on the wire (`"account"` / `"team"`).

"account""team"

rolerequired

RepoRole

string

Repo-level role (read/write/maintain/admin). Ordered low → high so `if role >= RepoRole::Write` reads naturally.

"read""write""maintain""admin"

Responses

201Grant set

application/json

RepoGrantResponse

object

grantee_idrequired

string

grantee_kindrequired

GranteeKind

string

Discriminator for the two grantee shapes of a [`RepoGrantee`], as it appears on the wire (`"account"` / `"team"`).

"account""team"

grantee_labelrequired

string

Human-friendly label — team name for team grants, account handle for account grants. Lets the SPA render the row without a second round-trip per row.

rolerequired

RepoRole

string

Repo-level role (read/write/maintain/admin). Ordered low → high so `if role >= RepoRole::Write` reads naturally.

"read""write""maintain""admin"

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 409Conflict — one of: already_exists, conflict, non_fast_forward
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget