Use this API to interact with CI/CD job token scopes.

All requests to the CI/CD job token scope API endpoint must be authenticated. The authenticated user must have the Maintainer or Owner role for the project.

Retrieve the CI/CD job token access settings for a project

GET /api/v4/projects/{id}/job_token_scope

Retrieves the CI/CD job token access settings (job token scope) of a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Responses

CodeDescriptionSchema
200OKAPIEntitiesProjectJobTokenScope
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

Update the CI/CD job token access settings for a project

PATCH /api/v4/projects/{id}/job_token_scope

Updates the Authorized groups and projects setting (job token scope) of a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project

Request body (application/json)

PropertyTypeDescription
enabled
Required
BooleanIndicates CI/CD job tokens generated in other projects have restricted access to this project

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

List all projects in a CI/CD job token allowlist

GET /api/v4/projects/{id}/job_token_scope/allowlist

Lists all projects in the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesBasicProjectDetails
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

Add a project to a CI/CD job token allowlist

POST /api/v4/projects/{id}/job_token_scope/allowlist

Adds a project to the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
IntegerID of user project
Example: 1

Request body (application/json)

PropertyTypeDescription
target_project_id
Required
IntegerID of target project
Example: 2

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesProjectScopeLink
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—
422Unprocessable entity—

Delete a project from a CI/CD job token allowlist

DELETE /api/v4/projects/{id}/job_token_scope/allowlist/{target_project_id}

Deletes a project from the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
IntegerID of user project
Example: 1
target_project_id
Path, required
IntegerID of the project to be removed from the allowlist
Example: 2

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

List all groups in a CI/CD job token allowlist

GET /api/v4/projects/{id}/job_token_scope/groups_allowlist

Lists all groups in the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
String or integerThe ID or URL-encoded path of the project
page
Query
IntegerCurrent page number
Default: 1
Example: 1
per_page
Query
IntegerNumber of items per page
Default: 20
Example: 20

Responses

CodeDescriptionSchema
200OKAPIEntitiesBasicGroupDetails
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

Add a group to a CI/CD job token allowlist

POST /api/v4/projects/{id}/job_token_scope/groups_allowlist

Adds a group to the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
IntegerID of user project
Example: 1

Request body (application/json)

PropertyTypeDescription
target_group_id
Required
IntegerID of target group
Example: 2

Responses

CodeDescriptionSchema
201CreatedAPIEntitiesGroupScopeLink
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—
422Unprocessable entity—

Delete a group from a CI/CD job token allowlist

DELETE /api/v4/projects/{id}/job_token_scope/groups_allowlist/{target_group_id}

Deletes a group from the CI/CD job token allowlist of a specified project.

Parameters

NameTypeDescription
id
Path, required
IntegerID of user project
Example: 1
target_group_id
Path, required
IntegerID of the group to be removed from the allowlist
Example: 2

Responses

CodeDescriptionSchema
204No Content—
400Bad Request—
401Unauthorized—
403Forbidden—
404Not found—

Schemas

Objects returned by the operations above and objects nested in their request bodies.

APIEntitiesBasicGroupDetails

PropertyTypeDescription
idInteger (int64)—
nameStringExample: Diaspora
web_urlStringExample: http://gitlab.example.com/groups/diaspora

APIEntitiesBasicProjectDetails

PropertyTypeDescription
avatar_urlStringExample: http://example.com/uploads/project/avatar/3/uploads/avatar.png
created_atString (date-time)Example: 2020-05-07T04:27:17.016Z
custom_attributesAPIEntitiesCustomAttribute—
default_branchStringExample: main
descriptionStringExample: desc
forks_countIntegerExample: 1
http_url_to_repoStringExample: https://gitlab.example.com/gitlab/gitlab.git
idInteger (int64)Example: 1
last_activity_atString (date-time)Example: 2013-09-30T13:46:02Z
licenseAPIEntitiesLicenseBasic—
license_urlStringExample: https://gitlab.example.com/gitlab/gitlab/blob/master/LICENCE
nameStringExample: project1
name_with_namespaceStringExample: John Doe / project1
namespaceAPIEntitiesNamespaceBasic—
pathStringExample: project1
path_with_namespaceStringExample: namespace1/project1
readme_urlStringExample: https://gitlab.example.com/gitlab/gitlab/blob/master/README.md
repository_storageStringExample: default
ssh_url_to_repoStringExample: git@gitlab.example.com:gitlab/gitlab.git
star_countIntegerExample: 1
tag_listArray of stringsExample: ["tag"]
topicsArray of stringsExample: ["topic"]
visibilityStringExample: public
web_urlStringExample: https://gitlab.example.com/gitlab/gitlab

APIEntitiesCustomAttribute

PropertyTypeDescription
keyStringExample: foo
valueStringExample: bar
PropertyTypeDescription
source_project_idInteger (int64)—
target_group_idInteger (int64)—

APIEntitiesLicenseBasic

PropertyTypeDescription
html_urlStringExample: http://choosealicense.com/licenses/gpl-3.0
keyStringExample: gpl-3.0
nameStringExample: GNU General Public License v3.0
nicknameStringExample: GNU GPLv3
source_urlString—

APIEntitiesNamespaceBasic

PropertyTypeDescription
avatar_urlStringExample: https://example.com/avatar/12345
full_pathStringExample: group/my_project
idInteger (int64)Example: 2
kindStringExample: project
nameStringExample: project
parent_idInteger (int64)Example: 1
pathStringExample: my_project
web_urlStringExample: https://example.com/group/my_project

APIEntitiesProjectJobTokenScope

PropertyTypeDescription
inbound_enabledBoolean—
outbound_enabledBoolean—
PropertyTypeDescription
source_project_idInteger (int64)—
target_project_idInteger (int64)—