---
title: "Create a commit"
method: POST
path: "/repos/{owner}/{repo}/git/commits"
tags: ["git"]
---

# Create a commit

`POST /repos/{owner}/{repo}/git/commits`

Creates a new Git [commit object](https://git-scm.com/book/en/v2/Git-Internals-Git-Objects).

**Signature verification object**

The response will include a `verification` object that describes the result of verifying the commit's signature. The following fields are included in the `verification` object:

| Name | Type | Description |
| ---- | ---- | ----------- |
| `verified` | `boolean` | Indicates whether GitHub considers the signature in this commit to be verified. |
| `reason` | `string` | The reason for verified value. Possible values and their meanings are enumerated in the table below. |
| `signature` | `string` | The signature that was extracted from the commit. |
| `payload` | `string` | The value that was signed. |
| `verified_at` | `string` | The date the signature was verified by GitHub. |

These are the possible values for `reason` in the `verification` object:

| Value | Description |
| ----- | ----------- |
| `expired_key` | The key that made the signature is expired. |
| `not_signing_key` | The "signing" flag is not among the usage flags in the GPG key that made the signature. |
| `gpgverify_error` | There was an error communicating with the signature verification service. |
| `gpgverify_unavailable` | The signature verification service is currently unavailable. |
| `unsigned` | The object does not include a signature. |
| `unknown_signature_type` | A non-PGP signature was found in the commit. |
| `no_user` | No user was associated with the `committer` email address in the commit. |
| `unverified_email` | The `committer` email address in the commit was associated with a user, but the email address is not verified on their account. |
| `bad_email` | The `committer` email address in the commit is not included in the identities of the PGP key that made the signature. |
| `unknown_key` | The key that made the signature has not been registered with any user's account. |
| `malformed_signature` | There was an error parsing the signature. |
| `invalid` | The signature could not be cryptographically verified using the key whose key-id was found in the signature. |
| `valid` | None of the above errors applied, so the signature is considered to be verified. |

## Path parameters

- `owner` string, required
- `repo` string, required

## Request body

- object
  - `message` string, required — The commit message
  - `tree` string, required — The SHA of the tree object this commit points to
  - `parents` string[] — The full SHAs of the commits that were the parents of this commit. If omitted or empty, the commit will be written as a root commit. For a single parent, an array of one SHA should be provided; for a merge commit, an array of more than one should be provided.
  - `author` object — Information about the author of the commit. By default, the `author` will be the authenticated user and the current date. See the `author` and `committer` object below for details.
    - `name` string, required — The name of the author (or committer) of the commit
    - `email` string, required — The email of the author (or committer) of the commit
    - `date` string, date-time — Indicates when this commit was authored (or committed). This is a timestamp in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `committer` object — Information about the person who is making the commit. By default, `committer` will use the information set in `author`. See the `author` and `committer` object below for details.
    - `name` string — The name of the author (or committer) of the commit
    - `email` string — The email of the author (or committer) of the commit
    - `date` string, date-time — Indicates when this commit was authored (or committed). This is a timestamp in [ISO 8601](https://en.wikipedia.org/wiki/ISO_8601) format: `YYYY-MM-DDTHH:MM:SSZ`.
  - `signature` string — The [PGP signature](https://en.wikipedia.org/wiki/Pretty_Good_Privacy) of the commit. GitHub adds the signature to the `gpgsig` header of the created commit. For a commit signature to be verifiable by Git or GitHub, it must be an ASCII-armored detached PGP signature over the string commit as it would be written to the object database. To pass a `signature` parameter, you need to first manually create a valid PGP signature, which can be complicated. You may find it easier to [use the command line](https://git-scm.com/book/id/v2/Git-Tools-Signing-Your-Work) to create signed commits.

## Response `201`

Response

- GitCommit — Low-level Git commit operations within a repository
  - `sha` string, required — SHA for the commit
  - `node_id` string, required
  - `url` string, uri, required
  - `author` object, required — Identifying information for the git-user
    - `date` string, date-time, required — Timestamp of the commit
    - `email` string, required — Git email address of the user
    - `name` string, required — Name of the git user
  - `committer` object, required — Identifying information for the git-user
    - `date` string, date-time, required — Timestamp of the commit
    - `email` string, required — Git email address of the user
    - `name` string, required — Name of the git user
  - `message` string, required — Message describing the purpose of the commit
  - `tree` object, required
    - `sha` string, required — SHA for the commit
    - `url` string, uri, required
  - `parents` object[], required
    - `sha` string, required — SHA for the commit
    - `url` string, uri, required
    - `html_url` string, uri, required
  - `verification` object, required
    - `verified` boolean, required
    - `reason` string, required
    - `signature` string, nullable, required
    - `payload` string, nullable, required
    - `verified_at` string, nullable, required
  - `html_url` string, uri, required

## Other responses

- `404` — Resource not found
- `409` — Conflict
- `422` — Validation failed, or the endpoint has been spammed.

---

[API](https://skmtc.net/github/apis/rest-api.md) · [All operations](https://skmtc.net/github/apis/rest-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/rest-api/versions/80850db290cd/schema)
