# Set allowed actions for an organization

From **GitHub v3 REST API**.

`PUT /orgs/{org}/actions/permissions/selected-actions`

Sets the actions that are allowed in an organization. To use this endpoint, the organization permission policy for `allowed_actions` must be configured to `selected`. For more information, see "[Set GitHub Actions permissions for an organization](#set-github-actions-permissions-for-an-organization)."

If the organization belongs to an enterprise that has `selected` actions set at the enterprise level, then you cannot override any of the enterprise's allowed actions settings.

To use the `patterns_allowed` setting for private repositories, the organization must belong to an enterprise. If the organization does not belong to an enterprise, then the `patterns_allowed` setting only applies to public repositories in the organization.

You must authenticate using an access token with the `admin:org` scope to use this endpoint. GitHub Apps must have the `administration` organization permission to use this API.

## Parameters

### `org`

- Location: path
- Required: true
- Type: `string`

## Request body

- Required: false
### `application/json`

- Type: `object`

```json
{
  "github_owned_allowed": true,
  "patterns_allowed": [
    "monalisa/octocat@*",
    "docker/*"
  ],
  "verified_allowed": false
}
```

```json
{"properties":{"github_owned_allowed":{"description":"Whether GitHub-owned actions are allowed. For example, this includes the actions in the `actions` organization.","type":"boolean"},"patterns_allowed":{"description":"Specifies a list of string-matching patterns to allow specific action(s). Wildcards, tags, and SHAs are allowed. For example, `monalisa/octocat@*`, `monalisa/octocat@v2`, `monalisa/*`.\"","items":{"type":"string"},"type":"array"}},"required":["github_owned_allowed","patterns_allowed"],"type":"object"}
```

## Responses

### `204`

Response

## Request examples

### cURL

```shell
curl --request PUT \
  --url {protocol}://{hostname}/api/v3/orgs/{org}/actions/permissions/selected-actions \
  --header 'content-type: application/json' \
  --data '{
  "github_owned_allowed": true,
  "patterns_allowed": [
    "monalisa/octocat@*",
    "docker/*"
  ],
  "verified_allowed": false
}'
```
