OAuth scope with only read-only access but to private repos #174347
Select Topic AreaQuestion BodyI want to have an OAuth scope with only read-only access but to private repos. I understand this is not possible right now, there is no such scope. I think this is a pretty common use case? I want to use an app (https://anonymous.4open.science/), but I am hesitating to give it full write access to all my repos, because I know that it only needs read access. See also: tdurieux/anonymous_github#56 |
Replies: 2 comments
|
You’re correct — GitHub does not currently provide an OAuth scope that allows read-only access to private repositories. The available scopes for repositories are: repo → full read/write access to private repos repo:status, repo_deployment, etc. → more granular, but still not strictly “read-only” for private repos For public repositories, the public_repo scope exists, but there isn’t an equivalent “read-only private repo” scope today. If your use case requires strictly read-only access, the best options are: Use a fine-grained personal access token (PAT) where you can limit to read-only on specific repositories. Or request this feature by opening a ticket/feedback with GitHub Support So at the moment, giving an OAuth app access to private repos unfortunately implies write permissions, which is a known limitation. |
|
You’re correct — GitHub does not currently provide an OAuth scope that allows read-only access to private repositories. The available scopes for repositories are:
repo → full read/write access to private repos
repo:status, repo_deployment, etc. → more granular, but still not strictly “read-only” for private repos
For public repositories, the public_repo scope exists, but there isn’t an equivalent “read-only private repo” scope today.
If your use case requires strictly read-only access, the best options are:
Use a fine-grained personal access token (PAT) where you can limit to read-only on specific repositories.
Or request this feature by opening a ticket/feedback with GitHub Support
or on…