---
title: "List bypass requests for secret scanning for an org"
method: GET
path: "/orgs/{org}/bypass-requests/secret-scanning"
tags: ["secret-scanning"]
---

# List bypass requests for secret scanning for an org

`GET /orgs/{org}/bypass-requests/secret-scanning`

List requests to bypass secret scanning push protection in an org.

Delegated bypass must be enabled on repositories in the org and the user must be a bypass reviewer to access this endpoint.
Personal access tokens (classic) need the `security_events` scope to use this endpoint.

## Path parameters

- `org` string, required

## Query parameters

- `repository_name` string
- `reviewer` string
- `requester` string
- `time_period` 'hour' | 'day' | 'week' | 'month'
- `request_status` 'completed' | 'cancelled' | 'approved' | 'expired' | 'deleted' | 'denied' | 'open' | 'all'
- `per_page` integer
- `page` integer

## Response `200`

Response

- SecretScanningBypassRequest[]
  - `id` integer — The unique identifier of the bypass request.
  - `number` integer — The number uniquely identifying the bypass request within its repository.
  - `repository` object — The repository the bypass request is for.
    - `id` integer — The ID of the repository the bypass request is for.
    - `name` string — The name of the repository the bypass request is for.
    - `full_name` string — The full name of the repository the bypass request is for.
  - `organization` object — The organization associated with the repository the bypass request is for.
    - `id` integer — The ID of the organization.
    - `name` string — The name of the organization.
  - `requester` object — The user who requested the bypass.
    - `actor_id` integer — The ID of the GitHub user who requested the bypass.
    - `actor_name` string — The name of the GitHub user who requested the bypass.
  - `request_type` string — The type of request.
  - `data` object[], nullable — Data describing the push rules that are being requested to be bypassed.
    - `secret_type` string — The type of secret that secret scanning detected.
    - `bypass_reason` 'used_in_tests' | 'false_positive' | 'fix_later' — The reason the bypass was requested.
    - `path` string — The path in the repo where the secret was located during the request.
    - `branch` string — The branch in the repo where the secret was located during the request.
  - `resource_identifier` string — The unique identifier for the request type of the bypass request. For example, a commit SHA.
  - `status` 'pending' | 'denied' | 'approved' | 'cancelled' | 'completed' | 'expired' | 'open' — The status of the bypass request.
  - `requester_comment` string, nullable — The comment the requester provided when creating the bypass request.
  - `expires_at` string, date-time — The date and time the bypass request will expire.
  - `created_at` string, date-time — The date and time the bypass request was created.
  - `responses` BypassResponse[], nullable — The responses to the bypass request.
    - `id` integer — The ID of the response to the bypass request.
    - `reviewer` object — The user who reviewed the bypass request.
      - `actor_id` integer — The ID of the GitHub user who reviewed the bypass request.
      - `actor_name` string — The name of the GitHub user who reviewed the bypass request.
    - `status` 'approved' | 'denied' | 'dismissed' — The response status to the bypass request until dismissed.
    - `created_at` string, date-time — The date and time the response to the bypass request was created.
  - `url` string, uri
  - `html_url` string, uri — The URL to view the bypass request in a browser.

## Other responses

- `404` — Resource not found
- `500` — Internal Error

---

[API](https://skmtc.net/github/apis/github-v3-rest-api-3.md) · [All operations](https://skmtc.net/github/apis/github-v3-rest-api-3/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/github-v3-rest-api-3/versions/dc0584ac4e13/schema)
