neosourceDocs
Search docs

Create or replace a branch-protection rule

PUT/api/repos/{owner}/{repo}/branches/{branch}/protection

setBranchProtection

Full-replace (PUT) of the rule keyed on this branch pattern. Requires admin access on the repository. Clearing the rule (DELETE) removes the merge gate entirely — no rule means no gate.

Requires authentication using a bearer token or a session cookie — see tokens and scopes.

curl

curl -X PUT 'https://neosource.dev/api/repos/OWNER/REPO/branches/BRANCH/protection' \
  -H 'Authorization: Bearer $NEOSOURCE_TOKEN' \
  -H 'Content-Type: application/json' \
  -d '{}'

fetch

fetch("https://neosource.dev/api/repos/OWNER/REPO/branches/BRANCH/protection", {
  method: "PUT",
  headers: {
    Authorization: "Bearer $NEOSOURCE_TOKEN",
    "Content-Type": "application/json",
  },
  body: JSON.stringify({}),
});

Path parameters

ownerrequired

Repository owner or organization slug.

string

reporequired

Repository name.

string

branchrequired

Exact branch name or glob pattern the rule is keyed on (`*` matches within one `/`-segment, `**` crosses segments). Names containing `/` must be percent-encoded (`release%2Fv1`).

string

ownerrequired

string

reporequired

string

branchrequired

string

Request bodyrequired

application/json

BranchProtectionRequest

object

Body of `PUT .../branches/{branch}/protection` — full-replace semantics; omitted fields fall back to their defaults (off / zero).

allow_deletions

boolean

Permit deleting a branch this rule covers (`git push origin :main`). Omitted means `false`, which BLOCKS.

allow_force_pushes

boolean

Permit a non-fast-forward update (`git push --force`) to a branch this rule covers. Omitted means `false`, which BLOCKS — the `allow_*` polarity is what makes `#[serde(default)]` fail closed here.

enforce_admins

boolean

Apply this rule to repo admins too — on the PR merge gate **and** on the push gate.

require_any_check

boolean

Require *some* check to have run and passed on the head, without naming it. Composes with `required_status_checks`: when on, nothing reported / any red / any pending / everything skipped all block.

require_conversation_resolution

boolean

require_pull_request

boolean

Refuse every direct update to a branch this rule covers — a plain fast-forward `git push` included — so changes must arrive through a pull request. Creating a branch that matches the rule stays permitted. Omitted means `false`, which PERMITS. That is the opposite of the `allow_*` fields below and is deliberate: those were a defect fix that had to start blocking on deploy, this is a new opt-in that must not change any existing rule's behaviour.

required_approving_reviews

integerint32

required_status_checks

array

Check contexts (commit-status `context` values or CI-derived `"<workflow> / <job_key>"` names) that must all be green to merge.

items

string

strict_up_to_date

boolean

Require the PR head to be up to date with the target branch.

Responses

200Protection rule saved

application/json

BranchProtectionResponse

object

allow_deletionsrequired

boolean

Permit deleting a branch this rule covers. `false` blocks.

allow_force_pushesrequired

boolean

Permit a non-fast-forward update to a branch this rule covers. `false` blocks — see `BranchProtectionRequest::allow_force_pushes`.

branch_patternrequired

string

The pattern the rule is keyed on (exact branch name or glob).

created_atrequired

integerint64

enforce_adminsrequired

boolean

repo_idrequired

string

require_any_checkrequired

boolean

Require *some* check to have run and passed on the head, without naming it. See `BranchProtectionRequest::require_any_check`.

require_conversation_resolutionrequired

boolean

require_pull_requestrequired

boolean

Refuse every direct update (fast-forward included); changes must arrive via a PR. `true` blocks — see `BranchProtectionRequest::require_pull_request`.

required_approving_reviewsrequired

integerint32

required_status_checksrequired

array

items

string

strict_up_to_daterequired

boolean

updated_atrequired

integerint64

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 401Authentication required
  • 403Forbidden — one of: forbidden
  • 404Not Found — one of: not_found
  • 409Conflict — one of: already_exists, conflict, non_fast_forward
  • 423Locked — one of: busy
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget