Access tokens and credentials
The credentials that give someone or something access to a project or a group: project, group and personal access tokens (list, read, rotate and revoke, and create for projects and groups), deploy tokens, deploy keys, the access requests users file to join, and the invitations sent to them. Rotating a token issues a new value and revokes the old one in one call: the token keeps its name, scopes and role, but whatever holds the old value, a CI/CD variable for instance, has to be updated with the token the call returns. Revoking or deleting a credential is destructive.
Creating a personal access token is a user action rather than one of these (see Users), and so are SSH keys and impersonation tokens. Project and group members are managed on the Projects and Groups pages, and the CI/CD job token scope on Jobs.
Sample questions
Section titled “Sample questions”- “List the access tokens of project 42”
- “Rotate the deploy-bot project token before it expires”
- “Create a read-only deploy token for my-group/my-app”
- “Approve the pending access requests on group platform”
How to call it
Section titled “How to call it”- Dynamic, the default surface: call
gitlab_execute_actionwithactionset to the action’s ID, such asaccess.approve_group, and its parameters inparams.gitlab_find_actionfinds an ID from a description of the task. - Meta (
GITLAB_MCP_TOOL_SURFACE=meta): callgitlab_accesswithactionset to the action’s name, such asapprove_group, and its parameters inparams. - Individual (
GITLAB_MCP_TOOL_SURFACE=individual): call the action’s own tool, such asgitlab_access_request_approve_group, with its parameters as the arguments.
Availability
Section titled “Availability”Every tier serves the whole group, on self-managed instances and on GitLab.com alike.
Read-only actions: 19 of 48, the ones a deployment in read-only mode keeps.
Actions
Section titled “Actions”The description of each action, and of each of its parameters, is the text the server serves for it on the default surface, quoted as served. A destructive action runs only once confirmed, unless GITLAB_MCP_YOLO_MODE (or AUTOPILOT) skips that step: the dynamic surface needs confirm: true on gitlab_execute_action, and the other two take a confirm parameter or the client’s prompt (Destructive actions). A parameter followed by a tier in parentheses is served only from that tier on.
| Action | Individual |
|---|---|
access.approve_group | gitlab_access_request_approve_group |
access.approve_project | gitlab_access_request_approve_project |
access.deny_group | gitlab_access_request_deny_group |
access.deny_project | gitlab_access_request_deny_project |
access.deploy_key_add | gitlab_deploy_key_add |
access.deploy_key_add_instance | gitlab_deploy_key_add_instance |
access.deploy_key_delete | gitlab_deploy_key_delete |
access.deploy_key_enable | gitlab_deploy_key_enable |
access.deploy_key_get | gitlab_deploy_key_get |
access.deploy_key_list_all | gitlab_deploy_key_list_all |
access.deploy_key_list_project | gitlab_deploy_key_list_project |
access.deploy_key_list_user_project | gitlab_deploy_key_list_user_project |
access.deploy_key_update | gitlab_deploy_key_update |
access.deploy_token_create_group | gitlab_deploy_token_create_group |
access.deploy_token_create_project | gitlab_deploy_token_create_project |
access.deploy_token_delete_group | gitlab_deploy_token_delete_group |
access.deploy_token_delete_project | gitlab_deploy_token_delete_project |
access.deploy_token_get_group | gitlab_deploy_token_get_group |
access.deploy_token_get_project | gitlab_deploy_token_get_project |
access.deploy_token_list_all | gitlab_deploy_token_list_all |
access.deploy_token_list_group | gitlab_deploy_token_list_group |
access.deploy_token_list_project | gitlab_deploy_token_list_project |
access.invite_group | gitlab_group_invite |
access.invite_list_group | gitlab_group_invite_list_pending |
access.invite_list_project | gitlab_project_invite_list_pending |
access.invite_project | gitlab_project_invite |
access.request_group | gitlab_access_request_request_group |
access.request_list_group | gitlab_access_request_list_group |
access.request_list_project | gitlab_access_request_list_project |
access.request_project | gitlab_access_request_request_project |
access.token_group_create | gitlab_group_access_token_create |
access.token_group_get | gitlab_group_access_token_get |
access.token_group_list | gitlab_group_access_token_list |
access.token_group_revoke | gitlab_group_access_token_revoke |
access.token_group_rotate | gitlab_group_access_token_rotate |
access.token_group_rotate_self | gitlab_group_access_token_rotate_self |
access.token_personal_get | gitlab_personal_access_token_get |
access.token_personal_list | gitlab_personal_access_token_list |
access.token_personal_revoke | gitlab_personal_access_token_revoke |
access.token_personal_revoke_self | gitlab_personal_access_token_revoke_self |
access.token_personal_rotate | gitlab_personal_access_token_rotate |
access.token_personal_rotate_self | gitlab_personal_access_token_rotate_self |
access.token_project_create | gitlab_project_access_token_create |
access.token_project_get | gitlab_project_access_token_get |
access.token_project_list | gitlab_project_access_token_list |
access.token_project_revoke | gitlab_project_access_token_revoke |
access.token_project_rotate | gitlab_project_access_token_rotate |
access.token_project_rotate_self | gitlab_project_access_token_rotate_self |
access.approve_group
Section titled “access.approve_group”Approve a pending group access request, granting the user membership. Returns: the membership it became, with id, username, name, the granted access level, the state, and the membership fields GitLab sends with it. See also:
access.request_list_group,access.deny_group,group.members.
- Meta-tool:
gitlab_access, actionapprove_group - Individual tool:
gitlab_access_request_approve_group - Tier: Free
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or path |
user_id | integer | yes | User ID of the access requester |
access_level | integer | no | Access level to grant (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium), 20=Reporter, 25=Security Manager (Premium), 30=Developer, 40=Maintainer, 50=Owner). Default 30 |
access.approve_project
Section titled “access.approve_project”Approve a pending project access request, granting the user membership. Returns: the membership it became, with id, username, name, the granted access level, the state, and the membership fields GitLab sends with it. See also:
access.request_list_project,access.deny_project,project.members.
- Meta-tool:
gitlab_access, actionapprove_project - Individual tool:
gitlab_access_request_approve_project - Tier: Free
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or path |
user_id | integer | yes | User ID of the access requester |
access_level | integer | no | Access level to grant (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium), 20=Reporter, 25=Security Manager (Premium), 30=Developer, 40=Maintainer, 50=Owner). Default 30 |
access.deny_group
Section titled “access.deny_group”Deny a pending group access request, removing it without granting membership. Returns: a success status and confirmation message. See also:
access.request_list_group,access.approve_group,group.members.
- Meta-tool:
gitlab_access, actiondeny_group - Individual tool:
gitlab_access_request_deny_group - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or path |
user_id | integer | yes | User ID of the access requester |
access.deny_project
Section titled “access.deny_project”Deny a pending project access request, removing it without granting membership. Returns: a success status and confirmation message. See also:
access.request_list_project,access.approve_project,project.members.
- Meta-tool:
gitlab_access, actiondeny_project - Individual tool:
gitlab_access_request_deny_project - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or path |
user_id | integer | yes | User ID of the access requester |
access.deploy_key_add
Section titled “access.deploy_key_add”Add a new SSH deploy key to a project. Returns: the created deploy key with id, title, fingerprint, can_push, and expiry. See also:
access.deploy_key_get,access.deploy_key_list_project,access.deploy_key_enable.
- Meta-tool:
gitlab_access, actiondeploy_key_add - Individual tool:
gitlab_deploy_key_add - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
key | string | yes | Public SSH key content |
project_id | string/integer | yes | Project ID or path |
title | string | yes | Deploy key title |
can_push | boolean | no | Whether the key can push to the project |
expires_at | string | no | Expiry date (YYYY-MM-DD) |
access.deploy_key_add_instance
Section titled “access.deploy_key_add_instance”Create an instance-level deploy key (admin only). Returns: the created instance deploy key with id, title, fingerprint, expiry, and project access arrays. See also:
access.deploy_key_list_all,access.deploy_key_enable.
- Meta-tool:
gitlab_access, actiondeploy_key_add_instance - Individual tool:
gitlab_deploy_key_add_instance - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
key | string | yes | Public SSH key content |
title | string | yes | Deploy key title |
expires_at | string | no | Expiry date (YYYY-MM-DD) |
access.deploy_key_delete
Section titled “access.deploy_key_delete”Delete a deploy key from a project (removes it from all projects where it is enabled). Returns: a success confirmation. See also:
access.deploy_key_get,access.deploy_key_list_project.
- Meta-tool:
gitlab_access, actiondeploy_key_delete - Individual tool:
gitlab_deploy_key_delete - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_key_id | integer | yes | Deploy key ID returned by deploy key operations. Do not use deploy_token_id |
project_id | string/integer | yes | Project ID or path |
access.deploy_key_enable
Section titled “access.deploy_key_enable”Enable an existing deploy key for a project. Returns: the enabled deploy key with id, title, fingerprint, and can_push. See also:
access.deploy_key_list_all,access.deploy_key_list_project,access.deploy_key_get.
- Meta-tool:
gitlab_access, actiondeploy_key_enable - Individual tool:
gitlab_deploy_key_enable - Tier: Free
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_key_id | integer | yes | Deploy key ID to enable. Do not use deploy_token_id |
project_id | string/integer | yes | Project ID or path |
access.deploy_key_get
Section titled “access.deploy_key_get”Get a single project deploy key by id. Returns: the deploy key with title, key, fingerprint, fingerprint_sha256, can_push, created_at, and expires_at. See also:
access.deploy_key_list_project,access.deploy_key_update,access.deploy_key_delete.
- Meta-tool:
gitlab_access, actiondeploy_key_get - Individual tool:
gitlab_deploy_key_get - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_key_id | integer | yes | Deploy key ID returned by deploy key operations. Do not use deploy_token_id |
project_id | string/integer | yes | Project ID or path |
access.deploy_key_list_all
Section titled “access.deploy_key_list_all”List ALL instance-level SSH deploy keys in one call (admin only). Use this instead of access.deploy_key_list_project when you need every key on the instance. Returns: instance deploy keys with id, title, fingerprint, expiry, projects_with_write_access, projects_with_readonly_access, and pagination metadata. See also:
access.deploy_key_add_instance,access.deploy_key_enable,access.deploy_key_list_project.
- Meta-tool:
gitlab_access, actiondeploy_key_list_all - Individual tool:
gitlab_deploy_key_list_all - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
order_by | string | no | Column to order results by (e.g. id, title, created_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
public | boolean | no | Filter by public keys |
sort | string (asc, desc) | no | Sort direction (asc, desc) |
access.deploy_key_list_project
Section titled “access.deploy_key_list_project”List a project’s SSH deploy keys with ordering and pagination. Returns: deploy keys with id, title, fingerprint, can_push, expiry, and pagination metadata. See also:
access.deploy_key_get,access.deploy_key_add,access.deploy_key_enable.
- Meta-tool:
gitlab_access, actiondeploy_key_list_project - Individual tool:
gitlab_deploy_key_list_project - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or path |
order_by | string | no | Column to order results by (e.g. id, title, created_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort direction (asc, desc) |
access.deploy_key_list_user_project
Section titled “access.deploy_key_list_user_project”List the deploy keys across a user’s projects (admin only) with ordering and pagination. Returns: deploy keys with id, title, fingerprint, can_push, expiry, and pagination metadata. See also:
access.deploy_key_list_project,access.deploy_key_get,user.get.
- Meta-tool:
gitlab_access, actiondeploy_key_list_user_project - Individual tool:
gitlab_deploy_key_list_user_project - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
user_id | string/integer | yes | User ID or username |
order_by | string | no | Column to order results by (e.g. id, title, created_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort direction (asc, desc) |
access.deploy_key_update
Section titled “access.deploy_key_update”Update a project deploy key’s title or push permission. Returns: the updated deploy key. See also:
access.deploy_key_get,access.deploy_key_list_project,access.deploy_key_delete.
- Meta-tool:
gitlab_access, actiondeploy_key_update - Individual tool:
gitlab_deploy_key_update - Tier: Free
- Behavior: writes, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_key_id | integer | yes | Deploy key ID returned by deploy key operations. Do not use deploy_token_id |
project_id | string/integer | yes | Project ID or path |
can_push | boolean | no | Whether the key can push to the project |
title | string | no | New deploy key title |
access.deploy_token_create_group
Section titled “access.deploy_token_create_group”Create a deploy token for a group. Returns: the created deploy token including its one-time secret token value, plus id, name, username, scopes, and expiry. See also:
access.deploy_token_list_group,access.deploy_token_get_group,access.deploy_token_delete_group.
- Meta-tool:
gitlab_access, actiondeploy_token_create_group - Individual tool:
gitlab_deploy_token_create_group - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
name | string | yes | Deploy token name |
expires_at | string | no | Expiry date (YYYY-MM-DD) |
scopes | string[] | no | Array of scopes (read_repository, read_registry, write_registry, read_package_registry, write_package_registry) |
username | string | no | Username for the deploy token |
access.deploy_token_create_project
Section titled “access.deploy_token_create_project”Create a deploy token for a project. Returns: the created deploy token including its one-time secret token value, plus id, name, username, scopes, and expiry. See also:
access.deploy_token_list_project,access.deploy_token_get_project,access.deploy_token_delete_project.
- Meta-tool:
gitlab_access, actiondeploy_token_create_project - Individual tool:
gitlab_deploy_token_create_project - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
name | string | yes | Deploy token name |
project_id | string/integer | yes | Project ID or URL-encoded path |
expires_at | string | no | Expiry date (YYYY-MM-DD) |
scopes | string[] | no | Array of scopes (read_repository, read_registry, write_registry, read_package_registry, write_package_registry) |
username | string | no | Username for the deploy token |
access.deploy_token_delete_group
Section titled “access.deploy_token_delete_group”Permanently delete a group deploy token by ID. Returns: a success confirmation. Deletion is irreversible. See also:
access.deploy_token_list_group,access.deploy_token_get_group,access.deploy_token_create_group.
- Meta-tool:
gitlab_access, actiondeploy_token_delete_group - Individual tool:
gitlab_deploy_token_delete_group - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_token_id | integer | yes | Deploy token ID |
group_id | string/integer | yes | Group ID or URL-encoded path |
access.deploy_token_delete_project
Section titled “access.deploy_token_delete_project”Permanently delete a project deploy token by ID. Returns: a success confirmation. Deletion is irreversible. See also:
access.deploy_token_list_project,access.deploy_token_get_project,access.deploy_token_create_project.
- Meta-tool:
gitlab_access, actiondeploy_token_delete_project - Individual tool:
gitlab_deploy_token_delete_project - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_token_id | integer | yes | Deploy token ID |
project_id | string/integer | yes | Project ID or URL-encoded path |
access.deploy_token_get_group
Section titled “access.deploy_token_get_group”Get a single group deploy token by ID. Returns: the deploy token with id, name, username, scopes, revoked/expired state, and expiry. See also:
access.deploy_token_list_group,access.deploy_token_create_group,access.deploy_token_delete_group.
- Meta-tool:
gitlab_access, actiondeploy_token_get_group - Individual tool:
gitlab_deploy_token_get_group - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_token_id | integer | yes | Deploy token ID |
group_id | string/integer | yes | Group ID or URL-encoded path |
access.deploy_token_get_project
Section titled “access.deploy_token_get_project”Get a single project deploy token by ID. Returns: the deploy token with id, name, username, scopes, revoked/expired state, and expiry. See also:
access.deploy_token_list_project,access.deploy_token_create_project,access.deploy_token_delete_project.
- Meta-tool:
gitlab_access, actiondeploy_token_get_project - Individual tool:
gitlab_deploy_token_get_project - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
deploy_token_id | integer | yes | Deploy token ID |
project_id | string/integer | yes | Project ID or URL-encoded path |
access.deploy_token_list_all
Section titled “access.deploy_token_list_all”List ALL deploy tokens across the GitLab instance in one call (admin only). Use this instead of access.deploy_token_list_project or access.deploy_token_list_group when you need every instance-wide token. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, and pagination metadata. See also:
access.deploy_token_list_project,access.deploy_token_list_group,access.deploy_token_create_project.
- Meta-tool:
gitlab_access, actiondeploy_token_list_all - Individual tool:
gitlab_deploy_token_list_all - Tier: Free
- Behavior: read-only, idempotent
No parameters.
access.deploy_token_list_group
Section titled “access.deploy_token_list_group”List deploy tokens owned by a group. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, expiry, and pagination metadata. See also:
access.deploy_token_get_group,access.deploy_token_create_group,access.deploy_token_delete_group.
- Meta-tool:
gitlab_access, actiondeploy_token_list_group - Individual tool:
gitlab_deploy_token_list_group - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
order_by | string | no | For keyset pagination, the column to order results by |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort order for keyset pagination: ‘asc’ or ‘desc’ |
access.deploy_token_list_project
Section titled “access.deploy_token_list_project”List deploy tokens owned by a project. Returns: deploy tokens with id, name, username, scopes, revoked/expired state, expiry, and pagination metadata. See also:
access.deploy_token_get_project,access.deploy_token_create_project,access.deploy_token_delete_project.
- Meta-tool:
gitlab_access, actiondeploy_token_list_project - Individual tool:
gitlab_deploy_token_list_project - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string | no | For keyset pagination, the column to order results by |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort order for keyset pagination: ‘asc’ or ‘desc’ |
access.invite_group
Section titled “access.invite_group”Invite a user to a group by email or user ID with an access level. Returns: an invitation result with status, per-email messages, and any users queued for administrator approval. See also:
access.invite_list_group,group.group_member_add,access.request_group.
- Meta-tool:
gitlab_access, actioninvite_group - Individual tool:
gitlab_group_invite - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
access_level | integer | yes | Access level (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium/Ultimate), 20=Reporter, 25=Security Manager (Premium/Ultimate), 30=Developer, 40=Maintainer, 50=Owner) |
group_id | string/integer | yes | Group ID or URL-encoded path |
email | string | no | Email address to invite (either email or user_id required) |
expires_at | string | no | Expiration date for the invitation (YYYY-MM-DD) |
id | string/integer | no | Group ID or URL-encoded path sent in the request body (mirrors the GitLab id parameter. Usually equal to group_id) |
invite_source | string | no | Source of the invitation that starts the member creation process |
member_role_id (Ultimate) | integer | no | Custom role to assign the new member (Ultimate only) |
user_id | integer | no | User ID to invite (either email or user_id required) |
access.invite_list_group
Section titled “access.invite_list_group”List a group’s pending invitations. Returns: pending invitations with invite email, access level, creator, creation and expiry dates, plus pagination metadata. See also:
access.invite_group,group.members.
- Meta-tool:
gitlab_access, actioninvite_list_group - Individual tool:
gitlab_group_invite_list_pending - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
order_by | string | no | Column to order keyset-paginated results by |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
query | string | no | Filter invitations by email or name |
sort | string (asc, desc) | no | Sort order for keyset-paginated results: ‘asc’ or ‘desc’ |
access.invite_list_project
Section titled “access.invite_list_project”List a project’s pending invitations. Returns: pending invitations with invite email, access level, creator, creation and expiry dates, plus pagination metadata. See also:
access.invite_project,project.members.
- Meta-tool:
gitlab_access, actioninvite_list_project - Individual tool:
gitlab_project_invite_list_pending - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string | no | Column to order keyset-paginated results by |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
query | string | no | Filter invitations by email or name |
sort | string (asc, desc) | no | Sort order for keyset-paginated results: ‘asc’ or ‘desc’ |
access.invite_project
Section titled “access.invite_project”Invite a user to a project by email or user ID with an access level. Returns: an invitation result with status, per-email messages, and any users queued for administrator approval. See also:
access.invite_list_project,project.member_add,access.request_project.
- Meta-tool:
gitlab_access, actioninvite_project - Individual tool:
gitlab_project_invite - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
access_level | integer | yes | Access level (0=No access, 5=Minimal access, 10=Guest, 15=Planner (Premium/Ultimate), 20=Reporter, 25=Security Manager (Premium/Ultimate), 30=Developer, 40=Maintainer, 50=Owner) |
project_id | string/integer | yes | Project ID or URL-encoded path |
email | string | no | Email address to invite (either email or user_id required) |
expires_at | string | no | Expiration date for the invitation (YYYY-MM-DD) |
id | string/integer | no | Project ID or URL-encoded path sent in the request body (mirrors the GitLab id parameter. Usually equal to project_id) |
invite_source | string | no | Source of the invitation that starts the member creation process |
member_role_id (Ultimate) | integer | no | Custom role to assign the new member (Ultimate only) |
user_id | integer | no | User ID to invite (either email or user_id required) |
access.request_group
Section titled “access.request_group”Request access to a group as the authenticated user. Returns: the created access request with id, username, name, requested state, and requested_at timestamp. See also:
access.request_list_group,access.approve_group,access.deny_group.
- Meta-tool:
gitlab_access, actionrequest_group - Individual tool:
gitlab_access_request_request_group - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or path |
access.request_list_group
Section titled “access.request_list_group”List pending access requests for a group. Returns: access requests with id, username, name, state, whether the account is locked, the address the user publishes, the requested_at timestamp, and pagination metadata. A pending request carries no access level: GitLab grants one when it is approved. See also:
access.approve_group,access.deny_group,group.members.
- Meta-tool:
gitlab_access, actionrequest_list_group - Individual tool:
gitlab_access_request_list_group - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or path |
order_by | string | no | Column to order results by for keyset-paginated result sets (e.g. id) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort order: asc or desc |
access.request_list_project
Section titled “access.request_list_project”List pending access requests for a project. Returns: access requests with id, username, name, state, whether the account is locked, the address the user publishes, the requested_at timestamp, and pagination metadata. A pending request carries no access level: GitLab grants one when it is approved. See also:
access.approve_project,access.deny_project,project.members.
- Meta-tool:
gitlab_access, actionrequest_list_project - Individual tool:
gitlab_access_request_list_project - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or path |
order_by | string | no | Column to order results by for keyset-paginated result sets (e.g. id) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (asc, desc) | no | Sort order: asc or desc |
access.request_project
Section titled “access.request_project”Request access to a project as the authenticated user. Returns: the created access request with id, username, name, requested state, and requested_at timestamp. See also:
access.request_list_project,access.approve_project,access.deny_project.
- Meta-tool:
gitlab_access, actionrequest_project - Individual tool:
gitlab_access_request_request_project - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or path |
access.token_group_create
Section titled “access.token_group_create”Use for GitLab group access tokens: this action creates a group-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_group_create - Individual tool:
gitlab_group_access_token_create - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
name | string | yes | Token name |
scopes | string[] | yes | Token scopes: api, read_api, read_repository, write_repository, etc. |
access_level | integer | no | Access level: 5 (Minimal access), 10 (guest), 15 (Planner, Premium/Ultimate), 20 (reporter), 25 (Security Manager, Premium/Ultimate), 30 (developer), 40 (maintainer), 50 (owner). 60=Admin is not valid for group access tokens |
description | string | no | Token description |
expires_at | string | no | Expiry date in YYYY-MM-DD format |
access.token_group_get
Section titled “access.token_group_get”Use for GitLab group access tokens: this action gets a group-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_group_get - Individual tool:
gitlab_group_access_token_get - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
token_id | integer | yes | Access token ID |
access.token_group_list
Section titled “access.token_group_list”Use for GitLab group access tokens: this action lists group-scoped API tokens.
- Meta-tool:
gitlab_access, actiontoken_group_list - Individual tool:
gitlab_group_access_token_list - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
created_after | string | no | Return tokens created on or after this date (YYYY-MM-DD) |
created_before | string | no | Return tokens created on or before this date (YYYY-MM-DD) |
expires_after | string | no | Return tokens that expire on or after this date (YYYY-MM-DD) |
expires_before | string | no | Return tokens that expire on or before this date (YYYY-MM-DD) |
last_used_after | string | no | Return tokens last used on or after this date (YYYY-MM-DD) |
last_used_before | string | no | Return tokens last used on or before this date (YYYY-MM-DD) |
order_by | string | no | Column to order results by (e.g. created_at, expires_at, last_used_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
revoked | boolean | no | Filter by revoked status: true to return only revoked tokens, false for non-revoked |
search | string | no | Filter tokens by name (partial match) |
sort | string (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc) | no | Sort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc |
state | string (active, inactive) | no | Token state filter: active, inactive |
access.token_group_revoke
Section titled “access.token_group_revoke”Use for GitLab group access tokens: this action revokes a group-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_group_revoke - Individual tool:
gitlab_group_access_token_revoke - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
token_id | integer | yes | Access token ID to revoke |
access.token_group_rotate
Section titled “access.token_group_rotate”Use for GitLab group access tokens: this action rotates a group-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_group_rotate - Individual tool:
gitlab_group_access_token_rotate - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
token_id | integer | yes | Access token ID |
expires_at | string | no | New expiry date in YYYY-MM-DD format |
access.token_group_rotate_self
Section titled “access.token_group_rotate_self”Use for GitLab group access tokens: this action rotates the group-scoped token that authenticates this request itself, with no token_id parameter.
- Meta-tool:
gitlab_access, actiontoken_group_rotate_self - Individual tool:
gitlab_group_access_token_rotate_self - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
group_id | string/integer | yes | Group ID or URL-encoded path |
expires_at | string | no | New expiry date in YYYY-MM-DD format |
access.token_personal_get
Section titled “access.token_personal_get”Use for GitLab personal access tokens: this action gets a personal-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_personal_get - Individual tool:
gitlab_personal_access_token_get - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
token_id | integer | no | Access token ID (required, use 0 for current token) |
access.token_personal_list
Section titled “access.token_personal_list”Use for GitLab personal access tokens: this action lists personal-scoped API tokens.
- Meta-tool:
gitlab_access, actiontoken_personal_list - Individual tool:
gitlab_personal_access_token_list - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
created_after | string | no | Return tokens created on or after this date (YYYY-MM-DD) |
created_before | string | no | Return tokens created on or before this date (YYYY-MM-DD) |
expires_after | string | no | Return tokens that expire on or after this date (YYYY-MM-DD) |
expires_before | string | no | Return tokens that expire on or before this date (YYYY-MM-DD) |
last_used_after | string | no | Return tokens last used on or after this date (YYYY-MM-DD) |
last_used_before | string | no | Return tokens last used on or before this date (YYYY-MM-DD) |
order_by | string | no | Column to order results by (e.g. created_at, expires_at, last_used_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
revoked | boolean | no | Filter by revoked status: true to return only revoked tokens, false for non-revoked |
search | string | no | Search by token name |
sort | string (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc) | no | Sort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc |
state | string (active, inactive) | no | Token state filter: active, inactive |
user_id | integer | no | Filter by user ID (admin only) |
access.token_personal_revoke
Section titled “access.token_personal_revoke”Use for GitLab personal access tokens: this action revokes a personal-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_personal_revoke - Individual tool:
gitlab_personal_access_token_revoke - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
token_id | integer | yes | Access token ID to revoke |
access.token_personal_revoke_self
Section titled “access.token_personal_revoke_self”Use for GitLab personal access tokens: this action revokes the personal-scoped token that authenticates this request itself, with no token_id parameter.
- Meta-tool:
gitlab_access, actiontoken_personal_revoke_self - Individual tool:
gitlab_personal_access_token_revoke_self - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
No parameters.
access.token_personal_rotate
Section titled “access.token_personal_rotate”Use for GitLab personal access tokens: this action rotates a personal-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_personal_rotate - Individual tool:
gitlab_personal_access_token_rotate - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
token_id | integer | yes | Access token ID |
expires_at | string | no | New expiry date in YYYY-MM-DD format |
access.token_personal_rotate_self
Section titled “access.token_personal_rotate_self”Use for GitLab personal access tokens: this action rotates the personal-scoped token that authenticates this request itself, with no token_id parameter.
- Meta-tool:
gitlab_access, actiontoken_personal_rotate_self - Individual tool:
gitlab_personal_access_token_rotate_self - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
expires_at | string | no | New expiry date in YYYY-MM-DD format |
access.token_project_create
Section titled “access.token_project_create”Use for GitLab project access tokens: this action creates a project-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_project_create - Individual tool:
gitlab_project_access_token_create - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
name | string | yes | Token name |
project_id | string/integer | yes | Project ID or URL-encoded path |
scopes | string[] | yes | Token scopes: api, read_api, read_repository, write_repository, etc. |
access_level | integer | no | Access level: 5 (Minimal access), 10 (guest), 15 (Planner, Premium/Ultimate), 20 (reporter), 25 (Security Manager, Premium/Ultimate), 30 (developer), 40 (maintainer). 50=Owner and 60=Admin are not valid for project access tokens |
description | string | no | Token description |
expires_at | string | no | Expiry date in YYYY-MM-DD format |
access.token_project_get
Section titled “access.token_project_get”Use for GitLab project access tokens: this action gets a project-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_project_get - Individual tool:
gitlab_project_access_token_get - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
token_id | integer | yes | Access token ID |
access.token_project_list
Section titled “access.token_project_list”Use for GitLab project access tokens: this action lists project-scoped API tokens.
- Meta-tool:
gitlab_access, actiontoken_project_list - Individual tool:
gitlab_project_access_token_list - Tier: Free
- Behavior: read-only, idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
order_by | string | no | Column to order results by (e.g. created_at, expires_at, last_used_at) |
page | integer | no | Page number to fetch, 1-based. Defaults to 1. Use the next_page field from the previous response to paginate forward. |
page_token | string | no | Keyset pagination cursor: record id at which to fetch the next page, taken from the previous keyset response. Only used when pagination=‘keyset’. |
pagination | string | no | Pagination method: ‘keyset’ for keyset-based pagination on large ordered result sets, or ‘offset’ (the default). Keyset avoids deep-offset cost. |
per_page | integer | no | Items per page. Defaults to 20, minimum 1, maximum 100. Use 100 to minimize round trips when the result set is large. |
sort | string (created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc) | no | Sort order: created_asc, created_desc, expires_asc, expires_desc, last_used_asc, last_used_desc, name_asc, name_desc |
state | string (active, inactive) | no | Token state filter: active, inactive |
access.token_project_revoke
Section titled “access.token_project_revoke”Use for GitLab project access tokens: this action revokes a project-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_project_revoke - Individual tool:
gitlab_project_access_token_revoke - Tier: Free
- Behavior: writes, destructive (needs confirmation), idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
token_id | integer | yes | Access token ID to revoke |
access.token_project_rotate
Section titled “access.token_project_rotate”Use for GitLab project access tokens: this action rotates a project-scoped API token.
- Meta-tool:
gitlab_access, actiontoken_project_rotate - Individual tool:
gitlab_project_access_token_rotate - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
token_id | integer | yes | Access token ID |
expires_at | string | no | New expiry date in YYYY-MM-DD format |
access.token_project_rotate_self
Section titled “access.token_project_rotate_self”Use for GitLab project access tokens: this action rotates the project-scoped token that authenticates this request itself, with no token_id parameter.
- Meta-tool:
gitlab_access, actiontoken_project_rotate_self - Individual tool:
gitlab_project_access_token_rotate_self - Tier: Free
- Behavior: writes, not idempotent
| Parameter | Type | Mandatory | Description |
|---|---|---|---|
project_id | string/integer | yes | Project ID or URL-encoded path |
expires_at | string | no | New expiry date in YYYY-MM-DD format |