VectleSkillsPermission denied to github-actions[bot] pushing from a workflow

Permission denied to github-actions[bot] pushing from a workflow

Export

Fixes 'Permission denied to github-actions[bot]' when a workflow pushes commits. Use when git push with GITHUB_TOKEN gets a 403. Not for PAT scope issues or deploy-key problems.

TL;DR: Give the job write permission: add permissions: contents: write to the workflow or job that pushes. GITHUB_TOKEN defaults to read-only, so any git push it attempts is rejected as the github-actions bot with a 403.

Permission denied to github-actions[bot]

The fix

  1. Add a permissions block to the job (or workflow) that pushes:
   permissions:
     contents: write

Expected: YAML parses; no other change needed.

  1. Re-run the failed job.

Expected: The push step succeeds instead of Permission denied to github-actions[bot].

  1. If it still 403s, check branch protection rules: the bot must be allowed to bypass them, or push to an unprotected branch.

Expected: Push lands on the target branch.

When this applies

  • a workflow step runs git push with GITHUB_TOKEN and gets Permission denied to github-actions[bot]
  • deploying docs or built files back to the repo

When it does NOT apply

  • you push with your own PAT (then check that token's scopes instead)
  • the error names a different user (that is a deploy-key problem)

Compatibility

GitHub Actions on GitHub.com and GHES, actions/checkout v2 and later. Since 2023 the default token permission is read-only.

Variants of this error

fatal: unable to access 'https://github.com/...': The requested URL returned error: 403

What git prints alongside it. Same fix.

remote: Permission to [owner]/[repo].git denied to github-actions[bot].

The full git form of the same rejection. Same fix.

Why it happens

GitHub changed the default GITHUB_TOKEN to read-only to limit blast radius of compromised workflows. Pushes need an explicit contents: write grant, which many older tutorials predate.

Edge cases and pitfalls

  • actions/checkout with persist-credentials: false removes the token from the local git config; pushes then need an explicit token.
  • Tags need contents: write too.
  • If the workflow is triggered by a fork PR, write permissions are stripped for safety; use the pullrequesttarget event carefully instead.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Permission+denied+to+github-actions%5Bbot%5D+pushing+from+a+workflow&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.