Use this API to manage protected branches for a project, and the protected branch settings that all projects in a group inherit.
GitLab Premium and GitLab Ultimate support more granular protections for pushing to branches. Administrators can grant permission to modify and push to protected branches only to deploy keys, instead of specific users.
Group protected branch settings are restricted to top-level groups. They support only valid access levels, and cannot name individual users or groups.
List all protected branches
GET /api/v4/projects/{id}/protected_branches
Lists all protected branches for a specified project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- Example: gitlab- |
pageQuery | Integer | Current page number Default: 1Example: 1 |
per_Query | Integer | Number of items per page Default: 20Example: 20 |
searchQuery | String | Search for a protected branch by name Example: mai |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
401 | 401 Unauthorized | — |
404 | 404 Project Not Found | — |
Protect repository branches
POST /api/v4/projects/{id}/protected_branches
Protects a specified repository branch or several project repository branches using a wildcard protected branch.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- Example: gitlab- |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
allow_ | Boolean | Allow force push for all users with push access Default: false |
allowed_ | Array of objects | Array of merge access levels,{user_,{group_,{access_ |
allowed_ | Array of objects | Array of push access levels,{user_,{group_,{deploy_,{access_ |
merge_ | Integer | Access levels allowed to merge (defaults:40,Allowed values: 30,40,60,0 |
nameRequired | String | The name of the protected branch Example: main |
push_ | Integer | Access levels allowed to push (defaults:40,Allowed values: 30,40,60,0 |
Responses
| Code | Description | Schema |
|---|---|---|
201 | Created | APIEntities |
400 | Bad Request | — |
401 | 401 Unauthorized | — |
404 | 404 Project Not Found | — |
409 | Protected branch ‘main’ already exists | — |
422 | name is missing | — |
Retrieve a protected branch or wildcard protected branch
GET /api/v4/projects/{id}/protected_branches/{name}
Retrieves a specified protected branch or wildcard protected branch.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- Example: gitlab- |
namePath, | String | The name of the branch or wildcard Example: main |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | Bad Request | — |
401 | 401 Unauthorized | — |
404 | 404 Project Not Found | — |
Update a protected branch
PATCH /api/v4/projects/{id}/protected_branches/{name}
Updates a protected branch for a specified project.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- Example: gitlab- |
namePath, | String | The name of the branch Example: main |
Request body (application/json)
| Property | Type | Description |
|---|---|---|
allow_ | Boolean | Allow force push for all users with push access |
allowed_ | Array of objects | Array of merge access levels,{user_,{group_,{access_ |
allowed_ | Array of objects | Array of push access levels,{user_,{group_,{deploy_,{access_ |
Responses
| Code | Description | Schema |
|---|---|---|
200 | OK | APIEntities |
400 | 400 Bad request | — |
401 | 401 Unauthorized | — |
404 | 404 Project Not Found | — |
422 | Push access levels access level has already been taken | — |
Unprotect repository branches
DELETE /api/v4/projects/{id}/protected_branches/{name}
Unprotects a specified protected branch or wildcard protected branch.
Parameters
| Name | Type | Description |
|---|---|---|
idPath, | String or integer | The ID or URL- Example: gitlab- |
namePath, | String | The name of the protected branch Example: main |
Responses
| Code | Description | Schema |
|---|---|---|
204 | No Content | — |
400 | Bad Request | — |
401 | 401 Unauthorized | — |
404 | 404 Project Not Found | — |
Schemas
Objects returned by the operations above and objects nested in their request bodies.
APIEntitiesProtectedBranch
| Property | Type | Description |
|---|---|---|
allow_ | Boolean | — |
id | Integer (int64) | Example:1 |
merge_ | Array of APIEntities | — |
name | String | Example:main |
push_ | Array of APIEntities | — |
APIEntitiesProtectedRefAccess
| Property | Type | Description |
|---|---|---|
access_ | Integer | Example:40 |
access_ | String | Example:Maintainers |
deploy_ | Integer (int64) | Example:1 |
group_ | Integer | Example:1 |
id | Integer (int64) | Example:1 |
user_ | Integer | Example:1 |