403 Resource not accessible by integration" error when posting a PR review
Fixes the 403 'Resource not accessible by integration' error when a bot posts a PR review. Use it when a GitHub App or fine-grained token fails to submit pull request reviews. Key trigger: review submission works with a classic PAT but fails with the app's installation token.
TL;DR
The credential posting the review lacks the Pull requests write permission. For a GitHub App, grant Pull requests "Read and write" in the app permissions and reinstall the app to accept them; for a fine-grained PAT, add the Pull requests write permission and update the secret. Then re-run the review step.
The error
"403 Resource not accessible by integration" error when posting a PR reviewSteps to fix
- Identify the credential: find which token the review step uses - an app installation token, a fine-grained PAT, or a classic PAT.
- Expected: you know exactly which credential is making the failing call.
- For a GitHub App: open the app settings, set Pull requests to Read and write, save, and accept the updated installation on the repo.
- Expected: the installation lists Pull requests read and write.
- For a fine-grained PAT: create or edit the token to include Pull requests read and write for the target repo, and update the secret the workflow reads.
- Expected: the workflow picks up the new token value.
- Re-run the review step.
- Expected: the review posts successfully.
Use this when
- A bot gets 403 "resource not accessible by integration" submitting a pull request review.
- The same review works with a classic PAT but fails with an app installation token.
- A review bot was just switched from PAT auth to GitHub App auth.
Not for this skill when
- The error is about annotations rather than reviews (that's the Checks permission).
- The PR is closed or merged (reviews can only be submitted on open PRs).
- The token is expired rather than under-permissioned (mint a fresh one).
Variant phrasings
- github app 403 posting pull request review
- resource not accessible by integration pull request review
- bot cannot submit PR review permissions
- 403 when review bot posts review github actions
Why it happens
Posting a review calls the pull-request reviews endpoint, which requires write access to pull requests. The phrase "by integration" in the message means the caller authenticated as a GitHub App installation, whose permissions are exactly the set on the app's settings page - nothing more. Classic PATs historically carried broad scopes, which is why the same call works with a PAT and fails with a fresh app token.
Edge cases
- Permission changes only take effect after the new installation is accepted; the old token keeps the old scopes until then.
- Posting a review on a PR from a fork works with the base-repo installation, but reading the fork's code may need more.
- Draft PRs accept reviews but some review APIs behave differently on drafts - confirm the PR is open, not just existing.
- If the bot also dismisses reviews or edits comments, it needs the same write permission, which this fix already grants.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstDUSLol5eWjgppHgPMee4w
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.