VectleSkillsrefusing to allow an OAuth App to create or update workflow on git push

refusing to allow an OAuth App to create or update workflow on git push

Export

Fixes the git push rejection 'refusing to allow an OAuth App to create or update workflow'. Use when a push over HTTPS fails only on .github/workflows files. Not for SSH push failures or general 403s.

TL;DR: Regenerate your personal access token with the workflow scope checked, then push again with the new token. GitHub refuses to let any OAuth token touch files under .github/workflows unless the token carries the workflow scope, so a token that works everywhere else still gets rejected on workflow files.

refusing to allow an OAuth App to create or update workflow

The fix

  1. Create a new token with the workflow scope. For a classic PAT, tick the workflow checkbox. For a fine-grained PAT, grant Actions read and write on the repo.

Expected: The token summary lists the workflow scope.

  1. Clear the cached credential so git asks for the new token on the next push, then paste the new token when prompted.
   printf 'protocol=https\nhost=github.com\n' | git credential reject

Expected: The next git push prompts for a username and password; the push completes.

  1. Push again.
   git push origin main

Expected: The push completes instead of the refusing error.

When this applies

  • git push over HTTPS fails only when the push includes .github/workflows files
  • you authenticate with a personal access token or OAuth app token

When it does NOT apply

  • the push has no workflow files (then it is a different auth problem)
  • you push over SSH (scopes do not apply there)

Compatibility

GitHub.com and GitHub Enterprise Server. Applies to PAT classic, fine-grained PATs, and OAuth app tokens used for git over HTTPS.

Variants of this error

refusing to allow an OAuth App to create or update workflow without workflow scope

Same error with the missing scope named. Same fix: reissue the token with that scope.

Why it happens

Workflow files can execute arbitrary code with access to repository secrets, so GitHub treats them as privileged. The workflow scope is a separate opt-in so a compromised token cannot silently install a secret-stealing workflow.

Edge cases and pitfalls

  • If a CI system or password manager holds the old token, rotate it there too or the next push fails the same way.
  • Fine-grained PATs do not have a checkbox literally named workflow; use Actions read and write permissions.
  • Inside Actions itself, GITHUB_TOKEN already has workflow-file access in its own repo; this error is about pushing from your machine.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=refusing+to+allow+an+OAuth+App+to+create+or+update+workflow+on+git+push&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.