v2

latestOpenAPI 3.0.02026-08-013312111.4 MB
Branch restrictions

Create a branch restriction rule

Creates a new branch restriction rule for a repository.

kind describes what will be restricted. Allowed values include: push, force, delete, restrict_merges, require_tasks_to_be_completed, require_approvals_to_merge, require_default_reviewer_approvals_to_merge, require_no_changes_requested, require_passing_builds_to_merge, require_commits_behind, reset_pullrequest_approvals_on_change, smart_reset_pullrequest_approvals, reset_pullrequest_changes_requested_on_change, require_all_dependencies_merged, enforce_merge_checks, and allow_auto_merge_when_builds_pass.

Different kinds of branch restrictions have different requirements:

  • push and restrict_merges require users and groups to be specified. Empty lists are allowed, in which case permission is denied for everybody.

The restriction applies to all branches that match. There are two ways to match a branch. It is configured in branch_match_kind:

  1. glob: Matches a branch against the pattern. A '*' in pattern will expand to match zero or more characters, and every other character matches itself. For example, 'foo*' will match 'foo' and 'foobar', but not 'barfoo'. '*' will match all branches.
  2. branching_model: Matches a branch against the repository's branching model. The branch_type controls the type of branch to match. Allowed values include: production, development, bugfix, release, feature and hotfix.

The combination of kind and match must be unique. This means that two glob restrictions in a repository cannot have the same kind and pattern. Additionally, two branching_model restrictions in a repository cannot have the same kind and branch_type.

users and groups are lists of users and groups that are except from the restriction. They can only be configured in push and restrict_merges restrictions. The push restriction stops a user pushing to matching branches unless that user is in users or is a member of a group in groups. The restrict_merges stops a user merging pull requests to matching branches unless that user is in users or is a member of a group in groups. Adding new users or groups to an existing restriction should be done via PUT.

Note that branch restrictions with overlapping matchers is allowed, but the resulting behavior may be surprising.

post/repositories/{workspace}/{repo_slug}/branch-restrictions

Request body

typestring required
idinteger

The branch restriction status' id.

kind'push' | 'delete' | 'force' | 'restrict_merges' | 'require_tasks_to_be_completed' | 'require_approvals_to_merge' | 'require_review_group_approvals_to_merge' | 'require_default_reviewer_approvals_to_merge' | 'require_no_changes_requested' | 'require_passing_builds_to_merge' | 'require_commits_behind' | 'reset_pullrequest_approvals_on_change' | 'smart_reset_pullrequest_approvals' | 'reset_pullrequest_changes_requested_on_change' | 'require_all_dependencies_merged' | 'enforce_merge_checks' | 'allow_auto_merge_when_builds_pass' | 'require_all_comments_resolved' required

The type of restriction that is being applied.

branch_match_kind'branching_model' | 'glob' required

Indicates how the restriction is matched against a branch. The default is glob.

branch_type'feature' | 'bugfix' | 'release' | 'hotfix' | 'development' | 'production'

Apply the restriction to branches of this type. Active when branch_match_kind is branching_model. The branch type will be calculated using the branching model configured for the repository.

patternstring required

Apply the restriction to branches that match this pattern. Active when branch_match_kind is glob. Will be empty when branch_match_kind is branching_model.

valueinteger

Value with kind-specific semantics:

  • require_approvals_to_merge uses it to require a minimum number of approvals on a PR.

  • require_default_reviewer_approvals_to_merge uses it to require a minimum number of approvals from default reviewers on a PR.

  • require_passing_builds_to_merge uses it to require a minimum number of passing builds.

  • require_commits_behind uses it to require the current branch is up to a maximum number of commits behind it destination.

Response

A paginated list of branch restrictions

typestring required
idinteger

The branch restriction status' id.

kind'push' | 'delete' | 'force' | 'restrict_merges' | 'require_tasks_to_be_completed' | 'require_approvals_to_merge' | 'require_review_group_approvals_to_merge' | 'require_default_reviewer_approvals_to_merge' | 'require_no_changes_requested' | 'require_passing_builds_to_merge' | 'require_commits_behind' | 'reset_pullrequest_approvals_on_change' | 'smart_reset_pullrequest_approvals' | 'reset_pullrequest_changes_requested_on_change' | 'require_all_dependencies_merged' | 'enforce_merge_checks' | 'allow_auto_merge_when_builds_pass' | 'require_all_comments_resolved' required

The type of restriction that is being applied.

branch_match_kind'branching_model' | 'glob' required

Indicates how the restriction is matched against a branch. The default is glob.

branch_type'feature' | 'bugfix' | 'release' | 'hotfix' | 'development' | 'production'

Apply the restriction to branches of this type. Active when branch_match_kind is branching_model. The branch type will be calculated using the branching model configured for the repository.

patternstring required

Apply the restriction to branches that match this pattern. Active when branch_match_kind is glob. Will be empty when branch_match_kind is branching_model.

valueinteger

Value with kind-specific semantics:

  • require_approvals_to_merge uses it to require a minimum number of approvals on a PR.

  • require_default_reviewer_approvals_to_merge uses it to require a minimum number of approvals from default reviewers on a PR.

  • require_passing_builds_to_merge uses it to require a minimum number of passing builds.

  • require_commits_behind uses it to require the current branch is up to a maximum number of commits behind it destination.