neosourceDocs
Search docs

List a user's repositories

GET/api/users/{handle}/repos

listUserProfileRepos

Returns repos in the user's personal workspace that the caller can read — the same decision the repo routes make, so nothing listed here 404s on click-through.

Authentication is not described for this operation in the spec — that does not mean it is public. Check tokens and scopes.

curl

curl -X GET 'https://neosource.dev/api/users/HANDLE/repos'

fetch

fetch("https://neosource.dev/api/users/HANDLE/repos", {
  method: "GET",
});

Path parameters

handlerequired

Username slug.

string

Responses

200Repository list

application/json

RepoListResponse

object

reposrequired

array

items

RepoResponse

object

allowed_merge_methodsrequired

array

Which merge methods this repo permits at all. Never empty, and always in a canonical order (`merge` before `squash`) — it is a set, so the server normalises the order on write rather than echoing the order it was sent.

created_atrequired

integerint64

created_byrequired

string

default_branchrequired

string

default_merge_methodrequired
MergeMethod
delete_branch_on_mergerequired

boolean

Whether merging a PR against this repo also deletes its source branch. `true` on a repo nobody has configured — see the settings route for why this one defaults on where the merge-method fields default to today's behaviour.

descriptionrequired

string

ownerrequired

string

parent
one of
repo_idrequired

string

slugrequired

string

statusrequired
RepoStatusOutput
updated_atrequired

integerint64

versionrequired

integerint32

visibilityrequired
RepoVisibilityInput
workspace_idrequired

string

403Forbidden — one of: forbidden, needs_scope

application/json

one of
  • ErrorForbidden
  • NeedsScopeError

    object

    `403` body returned when listing private repos but the linked identity lacks the required provider scope. The SPA turns this into an incremental-authorization prompt (Tier 2) that calls the `/elevate` OAuth endpoint with this `scope`.

    errorrequired

    string

    Always `needs_scope` — this body exists to carry the extra fields that kind needs.

    "needs_scope"

    scoperequired

    string

    The provider scope to request via elevation (e.g. `"repo"`).

Standard errors

Bodies documented once for the whole API — see standard errors.

  • 400Bad Request — one of: invalid_input
  • 404Not Found — one of: not_found
  • 429Rate limited — retry after the `Retry-After` header
  • 500Internal server error
  • 503Service temporarily unavailable / at capacity — retry after the `Retry-After` header
  • 504Gateway timeout — the request exceeded the server's handling budget

Schemas

Referenced above. Listed here rather than expanded inline, so the same definition is not repeated at every level.

MergeMethod

string

How a pull request's commits land on its target branch. A repo carries two settings over this enum (`migrations/20260820120000_repo_merge_methods.sql`): the set it *permits* (`RepoRecord::allowed_merge_methods`, never empty) and the one the merge path reaches for when the request names none (`RepoRecord::default_merge_method`, always a member of that set — enforced by the settings route, which is the only place both columns are visible at once). `Default` is [`MergeMethod::Merge`] to match the column default, which is itself the pre-existing behaviour of every repo: before this setting existed, a merge always minted a two-parent commit. `Rebase` is deliberately absent rather than merely unimplemented — it replays N commits, can conflict per commit, and rewrites the SHAs the stacked-PR re-parent invariant leans on (`plans/archive/pr-merge-methods-2026-08.md` §"Not doing"). Adding it later is one `ALTER TYPE merge_method ADD VALUE` plus an arm here, which is why the stored shape is an enum array and not a pair of booleans.

"merge""squash"

RepoParentInfo

object

Summary of a fork's parent repository.

repo_idrequired

string

RepoStatusOutput

string

Repo lifecycle state surfaced by the API. Mirrors `RepoStatus`. See ADR 0012 §2.

"creating""ready""importing""import_failed"

RepoVisibilityInput

string

"public""internal""private"