neosourceDocs
Search docs

List branch-protection rules

GET/api/repos/{owner}/{repo}/branches/protection

listBranchProtection

Every protection rule configured on the repo, stable order. Requires admin access on the repository — this doubles as the settings UI's admin-permission probe, so a non-admin (or anonymous) caller sees 404 rather than an empty list.

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X GET 'https://neosource.dev/api/repos/OWNER/REPO/branches/protection' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/branches/protection", {
  method: "GET",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
  },
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

ownerrequired

string

reporequired

string

Responses

200Protection rules

application/json

BranchProtectionListResponse

object

`GET /api/repos/{owner}/{repo}/branches/protection` — every rule on the repo, stable order (see `PgBranchProtectionStore::list_for_repo`).

rulesrequired

array

items

BranchProtectionResponse

object

allow_deletionsrequired

boolean

Permit deleting a branch this rule covers. `false` blocks.

allow_force_pushesrequired

boolean

Permit a non-fast-forward update to a branch this rule covers. `false` blocks — see `BranchProtectionRequest::allow_force_pushes`.

branch_patternrequired

string

The pattern the rule is keyed on (exact branch name or glob).

created_atrequired

integerint64

enforce_adminsrequired

boolean

repo_idrequired

string

require_any_checkrequired

boolean

Require *some* check to have run and passed on the head, without naming it. See `BranchProtectionRequest::require_any_check`.

require_conversation_resolutionrequired

boolean

require_pull_requestrequired

boolean

Refuse every direct update (fast-forward included); changes must arrive via a PR. `true` blocks — see `BranchProtectionRequest::require_pull_request`.

required_approving_reviewsrequired

integerint32

required_status_checksrequired

array

items

string

strict_up_to_daterequired

boolean

updated_atrequired

integerint64

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 409Conflict — one of: already_exists, conflict, non_fast_forward
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget