---
title: "Add a repository collaborator"
method: PUT
path: "/repos/{owner}/{repo}/collaborators/{username}"
tags: ["repos"]
---

# Add a repository collaborator

`PUT /repos/{owner}/{repo}/collaborators/{username}`

Add a user to a repository with a specified level of access. If the repository is owned by an organization, this API does not add the user to the organization - a user that has repository access without being an organization member is called an "outside collaborator" (if they are not an Enterprise Managed User) or a "repository collaborator" if they are an Enterprise Managed User. These users are exempt from some organization policies - see "[Adding outside collaborators to repositories](https://docs.github.com/enterprise-cloud@latest/organizations/managing-user-access-to-your-organizations-repositories/managing-outside-collaborators/adding-outside-collaborators-to-repositories-in-your-organization)" to learn more about these collaborator types.

This endpoint triggers [notifications](https://docs.github.com/enterprise-cloud@latest/github/managing-subscriptions-and-notifications-on-github/about-notifications).

Adding an outside collaborator may be restricted by enterprise and organization administrators. For more information, see "[Enforcing repository management policies in your enterprise](https://docs.github.com/enterprise-cloud@latest/admin/policies/enforcing-policies-for-your-enterprise/enforcing-repository-management-policies-in-your-enterprise#enforcing-a-policy-for-inviting-outside-collaborators-to-repositories)" and "[Setting permissions for adding outside collaborators](https://docs.github.com/enterprise-cloud@latest/organizations/managing-organization-settings/setting-permissions-for-adding-outside-collaborators)" for organization settings.

For more information on permission levels, see "[Repository permission levels for an organization](https://docs.github.com/enterprise-cloud@latest/github/setting-up-and-managing-organizations-and-teams/repository-permission-levels-for-an-organization#permission-levels-for-repositories-owned-by-an-organization)". There are restrictions on which permissions can be granted to organization members when an organization base role is in place. In this case, the role being given must be equal to or higher than the org base permission. Otherwise, the request will fail with:

```
Cannot assign {member} permission of {role name}
```

Note that, if you choose not to pass any parameters, you'll need to set `Content-Length` to zero when calling out to this endpoint. For more information, see "[HTTP method](https://docs.github.com/enterprise-cloud@latest/rest/guides/getting-started-with-the-rest-api#http-method)."

The invitee will receive a notification that they have been invited to the repository, which they must accept or decline. They may do this via the notifications page, the email they receive, or by using the [API](https://docs.github.com/enterprise-cloud@latest/rest/collaborators/invitations).

For Enterprise Managed Users, this endpoint does not send invitations - these users are automatically added to organizations and repositories. Enterprise Managed Users can only be added to organizations and repositories within their enterprise.

**Updating an existing collaborator's permission level**

The endpoint can also be used to change the permissions of an existing collaborator without first removing and re-adding the collaborator. To change the permissions, use the same endpoint and pass a different `permission` parameter. The response will be a `204`, with no other indication that the permission level changed.

**Rate limits**

You are limited to sending 50 invitations to a repository per 24 hour period. Note there is no limit if you are inviting organization members to an organization repository.

## Path parameters

- `owner` string, required
- `repo` string, required
- `username` string, required

## Request body

- object
  - `permission` string — The permission to grant the collaborator. **Only valid on organization-owned repositories.** We accept the following permissions to be set: `pull`, `triage`, `push`, `maintain`, `admin` and you can also specify a custom repository role name, if the owning organization has defined any.

## Response `201`

Response when a new invitation is created

- RepositoryInvitation — Repository invitations let you manage who you collaborate with.
  - `id` integer, required — Unique identifier of the repository invitation.
  - `repository` MinimalRepository, required — Minimal Repository
    - `id` integer, required
    - `node_id` string, required
    - `name` string, required
    - `full_name` string, required
    - `owner` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
      - `user_view_type` string
    - `private` boolean, required
    - `html_url` string, uri, required
    - `description` string, nullable, required
    - `fork` boolean, required
    - `url` string, uri, required
    - `archive_url` string, required
    - `assignees_url` string, required
    - `blobs_url` string, required
    - `branches_url` string, required
    - `collaborators_url` string, required
    - `comments_url` string, required
    - `commits_url` string, required
    - `compare_url` string, required
    - `contents_url` string, required
    - `contributors_url` string, uri, required
    - `deployments_url` string, uri, required
    - `downloads_url` string, uri, required
    - `events_url` string, uri, required
    - `forks_url` string, uri, required
    - `git_commits_url` string, required
    - `git_refs_url` string, required
    - `git_tags_url` string, required
    - `git_url` string
    - `issue_comment_url` string, required
    - `issue_events_url` string, required
    - `issues_url` string, required
    - `keys_url` string, required
    - `labels_url` string, required
    - `languages_url` string, uri, required
    - `merges_url` string, uri, required
    - `milestones_url` string, required
    - `notifications_url` string, required
    - `pulls_url` string, required
    - `releases_url` string, required
    - `ssh_url` string
    - `stargazers_url` string, uri, required
    - `statuses_url` string, required
    - `subscribers_url` string, uri, required
    - `subscription_url` string, uri, required
    - `tags_url` string, uri, required
    - `teams_url` string, uri, required
    - `trees_url` string, required
    - `clone_url` string
    - `mirror_url` string, nullable
    - `hooks_url` string, uri, required
    - `svn_url` string
    - `homepage` string, nullable
    - `language` string, nullable
    - `forks_count` integer
    - `stargazers_count` integer
    - `watchers_count` integer
    - `size` integer — The size of the repository, in kilobytes. Size is calculated hourly. When a repository is initially created, the size is 0.
    - `default_branch` string
    - `open_issues_count` integer
    - `is_template` boolean
    - `topics` string[]
    - `has_issues` boolean
    - `has_projects` boolean
    - `has_wiki` boolean
    - `has_pages` boolean
    - `has_downloads` boolean
    - `has_discussions` boolean
    - `has_pull_requests` boolean
    - `pull_request_creation_policy` 'all' | 'collaborators_only' — The policy controlling who can create pull requests: all or collaborators_only.
    - `archived` boolean
    - `disabled` boolean
    - `visibility` string
    - `pushed_at` string, date-time, nullable
    - `created_at` string, date-time, nullable
    - `updated_at` string, date-time, nullable
    - `permissions` object
      - `admin` boolean
      - `maintain` boolean
      - `push` boolean
      - `triage` boolean
      - `pull` boolean
    - `role_name` string
    - `temp_clone_token` string
    - `delete_branch_on_merge` boolean
    - `subscribers_count` integer
    - `network_count` integer
    - `code_of_conduct` CodeOfConduct — Code Of Conduct
      - `key` string, required
      - `name` string, required
      - `url` string, uri, required
      - `body` string
      - `html_url` string, uri, nullable, required
    - `license` object, nullable
      - `key` string
      - `name` string
      - `spdx_id` string
      - `url` string, nullable
      - `node_id` string
    - `forks` integer
    - `open_issues` integer
    - `watchers` integer
    - `allow_forking` boolean
    - `web_commit_signoff_required` boolean
    - `security_and_analysis` SecurityAndAnalysis, nullable
      - `advanced_security` object — Enable or disable GitHub Advanced Security for the repository. For standalone Code Scanning or Secret Protection products, this parameter cannot be used.
        - `status` 'enabled' | 'disabled'
      - `code_security` object
        - `status` 'enabled' | 'disabled'
      - `dependabot_security_updates` object — Enable or disable Dependabot security updates for the repository.
        - `status` 'enabled' | 'disabled' — The enablement status of Dependabot security updates for the repository.
      - `secret_scanning` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_push_protection` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_non_provider_patterns` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_ai_detection` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_validity_checks` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_delegated_alert_dismissal` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_delegated_bypass` object
        - `status` 'enabled' | 'disabled'
      - `secret_scanning_delegated_bypass_options` object
        - `reviewers` object[] — The bypass reviewers for secret scanning delegated bypass
          - `reviewer_id` integer, required — The ID of the team or role selected as a bypass reviewer
          - `reviewer_type` 'TEAM' | 'ROLE', required — The type of the bypass reviewer
          - `mode` 'ALWAYS' | 'EXEMPT' — The bypass mode for the reviewer
    - `custom_properties` object — The custom properties that were defined for the repository. The keys are the custom property names, and the values are the corresponding custom property values.
  - `invitee` NullableSimpleUser, nullable, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `inviter` NullableSimpleUser, nullable, required — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
    - `user_view_type` string
  - `permissions` 'read' | 'write' | 'admin' | 'triage' | 'maintain', required — The permission associated with the invitation.
  - `created_at` string, date-time, required
  - `expired` boolean — Whether or not the invitation has expired
  - `url` string, required — URL for the repository invitation
  - `html_url` string, required
  - `node_id` string, required

## Other responses

- `204` — Response when: - an existing collaborator is added as a collaborator - an organization member is added as an individual collaborator - an existing team member (whose team is also a repository collaborator) is added as an individual collaborator
- `403` — Forbidden
- `422` — Response when: - validation failed, or the endpoint has been spammed - an Enterprise Managed User (EMU) account was invited to a repository in an enterprise with personal user accounts

---

[API](https://skmtc.net/github/apis/github-v3-rest-api-2.md) · [All operations](https://skmtc.net/github/apis/github-v3-rest-api-2/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/github-v3-rest-api-2/versions/8ae6d0c8716e/schema)
