Skip to main content
PUT
Update repository guardrails

Authorizations

Authorization
string
header
required

Your Reason API key from Settings > API. New keys use reason_; legacy ara_ keys remain accepted. Keys are capability-scoped: run, mcp:read, mcp:write, secrets:read, secrets:write, sessions:read, sessions:debug, knowledge:read, memory:read, memory:write, skills:read, skills:write, repos:read, repos:write, reviews:read, reviews:write, deployment:read, analytics:read, org:read, org:write, attachments:read, attachments:write, guardrails:read, guardrails:write, automations:read, automations:write, agent_auth:read. mcp:write manages MCP server configuration only; it does not authorize remote MCP-tool execution. sessions:read reads sessions, including the assistant, reasoning and tool activity in their events. sessions:debug is privileged: only for organization owners/admins, it expands session events to the full diagnostic projection (diagnostic event kinds, status text and raw event metadata).

Path Parameters

orgId
string
required

Organization id or slug. Resolve it with GET /v3/self.

owner
string
required

Repository owner (user or organization).

repo
string
required

Repository name.

Query Parameters

provider
enum<string>
default:github

Source-control provider. GitHub is the only supported provider.

Available options:
github

Body

application/json

Per-repository automation guardrails. On update, every property is optional and only the supplied fields change.

auto_fix_new_issues
boolean
auto_audit_on_connect
boolean
pr_risk_assessment
boolean
auto_merge_prs
boolean
auto_merge_max_risk
enum<string>
Available options:
zero,
low,
medium,
high
auto_merge_require_no_blocking_findings
boolean
auto_merge_require_reason_authored
boolean

Require a Reason-authored pull request before an unattended merge.

auto_merge_require_ci_green
boolean
auto_merge_require_reason_verify
boolean

Require Reason's verification checkpoint to hold before an unattended merge.

auto_merge_require_migration_approval
boolean
auto_merge_require_ara_authored
boolean
deprecated

Deprecated: use auto_merge_require_reason_authored. Accepted on update (sending both with different values is rejected) and returned with the same value.

auto_merge_require_ara_verify
boolean
deprecated

Deprecated: use auto_merge_require_reason_verify. Accepted on update (sending both with different values is rejected) and returned with the same value.

auto_merge_review_context
enum<string>

Which automated review-bot comments PR Merge Bot reads. ara_review_bot_only is a deprecated spelling of reason_review_bot_only, still accepted on update; responses report reason_review_bot_only.

Available options:
all_review_bots,
reason_review_bot_only,
ara_review_bot_only
auto_merge_custom_prompt
string
auto_merge_protected_paths
string

Newline-separated glob patterns; changes touching a matching path require a standing human approval before an unattended merge. Lines starting with # are comments.

auto_merge_max_changed_lines
integer

Maximum total changed lines (additions plus deletions) an unattended merge may carry. 0 disables the limit.

Required range: x >= 0
auto_merge_delete_branch
boolean

Delete the source branch after an unattended merge. Fork branches and branches other open pull requests target are never deleted.

Response

The updated repository guardrails.

repo
string
guardrails
object

Per-repository automation guardrails. On update, every property is optional and only the supplied fields change.