# Set allowed actions for a repository

From **GitHub v3 REST API**.

`PUT /repos/{owner}/{repo}/actions/permissions/selected-actions`

Sets the actions that are allowed in a repository. To use this endpoint, the repository permission policy for `allowed_actions` must be configured to `selected`. For more information, see "[Set GitHub Actions permissions for a repository](#set-github-actions-permissions-for-a-repository)."

If the repository belongs to an organization or enterprise that has `selected` actions set at the organization or enterprise levels, then you cannot override any of the allowed actions settings.

To use the `patterns_allowed` setting for private repositories, the repository must belong to an enterprise. If the repository does not belong to an enterprise, then the `patterns_allowed` setting only applies to public repositories.

You must authenticate using an access token with the `repo` scope to use this endpoint. GitHub Apps must have the `administration` repository permission to use this API.

## Parameters

### `owner`

- Location: path
- Required: true
- Type: `string`

### `repo`

- Location: path
- Required: true
- Type: `string`

## Request body

- Required: false
### `application/json`

- Type: `object`

```json
{
  "github_owned_allowed": true,
  "patterns_allowed": [
    "monalisa/octocat@*",
    "docker/*"
  ],
  "verified_allowed": false
}
```

```json
{"properties":{"github_owned_allowed":{"description":"Whether GitHub-owned actions are allowed. For example, this includes the actions in the `actions` organization.","type":"boolean"},"patterns_allowed":{"description":"Specifies a list of string-matching patterns to allow specific action(s). Wildcards, tags, and SHAs are allowed. For example, `monalisa/octocat@*`, `monalisa/octocat@v2`, `monalisa/*`.\"","items":{"type":"string"},"type":"array"}},"required":["github_owned_allowed","patterns_allowed"],"type":"object"}
```

## Responses

### `204`

Response

## Request examples

### cURL

```shell
curl --request PUT \
  --url {protocol}://{hostname}/api/v3/repos/{owner}/{repo}/actions/permissions/selected-actions \
  --header 'content-type: application/json' \
  --data '{
  "github_owned_allowed": true,
  "patterns_allowed": [
    "monalisa/octocat@*",
    "docker/*"
  ],
  "verified_allowed": false
}'
```
