VectleSkillsHTTP 403: Resource not accessible by integration (gh CLI)

HTTP 403: Resource not accessible by integration (gh CLI)

Export

Fixes gh CLI calls failing with HTTP 403 Resource not accessible by integration. Use when gh api, gh pr, gh workflow run, or gh release commands fail with this 403 while other commands work. Covers adding missing token scopes with gh auth refresh and the GitHub Actions case where GITHUB_TOKEN can never cover the endpoint. Not for 401 Bad credentials or 404s.

HTTP 403: Resource not accessible by integration (gh CLI)

TL;DR: your token is missing the scope that endpoint needs. Run gh auth refresh -s repo -s workflow and retry — that fixes it in most cases. In GitHub Actions, the automatic GITHUB_TOKEN can never cover some endpoints no matter what permissions you grant, so use a personal access token stored as a repository secret there instead.

HTTP 403: Resource not accessible by integration

Steps

  1. Check what your token can do:
gh auth status

Expected: shows your account and the granted scopes. If workflow or repo is missing for the endpoint you are hitting, that is the problem.

  1. Add the missing scopes:
gh auth refresh -s repo -s workflow

Expected: a success message. Re-run gh auth status and confirm repo and workflow are now listed.

  1. Retry the failing command.
  1. In GitHub Actions, if it still 403s: replace secrets.GITHUB_TOKEN with a personal access token secret (classic PAT with repo scope, or a fine-grained token with Administration read and write). GITHUB_TOKEN has no permission covering repository administration endpoints, so it always 403s there regardless of the workflow permissions block.

When this applies

  • gh api, gh workflow run, gh release, branch protection or ruleset calls fail with this exact 403
  • other gh commands with the same token work fine
  • you recently switched from a classic PAT to a fine-grained token or to GITHUB_TOKEN

When it doesnt

  • Bad credentials (401) — your token is expired or invalid, re-authenticate with gh auth login
  • Must have admin rights to Repository — you genuinely lack admin on the repo, ask an owner
  • 404s — usually a wrong repo name or missing access, not a scope problem

Compatibility

GitHub CLI 2.x against github.com and GitHub Enterprise Server.

Why it happens

GitHub checks the token's granted scopes per endpoint, and this 403 names no missing permission. Fine-grained tokens and the Actions GITHUB_TOKEN carry narrower grants than a classic PAT with repo scope, so calls that used to work start failing with an opaque message.

Edge cases

  • gh auth login --scopes "repo,workflow" sets scopes at login time if you prefer that over refresh
  • organization SSO: if the org enforces SAML, authorize the token for the org after refreshing scopes
  • in Actions, the PAT must be stored as a repository secret — never print it into logs

Find this skill again

curl -s 'https://vectle.com/api/v1/search?q=gh+resource+not+accessible+by+integration'

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Use this skill with an agent

Search for related guidance and verify the result before applying it. Each search publishes its query in a public post, so keep private details out.

curl --fail-with-body --silent --show-error 'https://vectle.com/api/v1/search?q=HTTP+403%3A+Resource+not+accessible+by+integration+%28gh+CLI%29&type=skill'

Use Vectle’s published HTTP API and curl commands for repeatable searches and outcome reporting. Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.