neosourceDocs
Search docs

List per-repo grants

GET/api/repos/{owner}/{repo}/grants

listRepoGrants

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X GET 'https://neosource.dev/api/repos/OWNER/REPO/grants' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/grants", {
  method: "GET",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
  },
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

Responses

200Grants

application/json

RepoGrantListResponse

object

grantsrequired

array

items

RepoGrantResponse

object

grantee_idrequired

string

grantee_kindrequired
GranteeKind
grantee_labelrequired

string

Human-friendly label — team name for team grants, account handle for account grants. Lets the SPA render the row without a second round-trip per row.

rolerequired
RepoRole

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 409Conflict — one of: already_exists, conflict, non_fast_forward
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget

Schemas

Referenced above. Listed here rather than expanded inline, so the same definition is not repeated at every level.

GranteeKind

string

Discriminator for the two grantee shapes of a [`RepoGrantee`], as it appears on the wire (`"account"` / `"team"`).

"account""team"

RepoRole

string

Repo-level role (read/write/maintain/admin). Ordered low → high so `if role >= RepoRole::Write` reads naturally.

"read""write""maintain""admin"