| app_id | GitHub App ID | yes | — |
| owner | The owner of the GitHub App installation (defaults to current repository owner) | no | — |
| kms_project_id | Google Cloud Project ID | yes | — |
| kms_keyring_id | KMS Keyring ID | yes | — |
| kms_key_id | KMS key ID | yes | — |
| kms_key_version | KMS key version. If omitted, the latest enabled version is selected automatically (requires roles/cloudkms.viewer or equivalent on the SA). | no | — |
| kms_location | KMS Keyring region | yes | — |
| repositories | Comma or newline-separated list of the scoped repos | no | — |
| permission_actions | The level of permission to grant the access token for GitHub Actions workflows, workflow runs, and artifacts. (read/write) | no | — |
| permission_administration | The level of permission to grant the access token for repository creation, deletion, settings, teams, and collaborators creation. (read/write) | no | — |
| permission_artifact_metadata | The level of permission to grant the access token to create and retrieve build artifact metadata records. (read/write) | no | — |
| permission_attestations | The level of permission to create and retrieve the access token for repository attestations. (read/write) | no | — |
| permission_checks | The level of permission to grant the access token for checks on code. (read/write) | no | — |
| permission_code_quality | The level of permission to grant the access token to view and manage code quality data. (read/write) | no | — |
| permission_codespaces | The level of permission to grant the access token to create, edit, delete, and list Codespaces. (read/write) | no | — |
| permission_contents | The level of permission to grant the access token for repository contents, commits, branches, downloads, releases, and merges. (read/write) | no | — |
| permission_dependabot_secrets | The level of permission to grant the access token to manage Dependabot secrets. (read/write) | no | — |
| permission_deployments | The level of permission to grant the access token for deployments and deployment statuses. (read/write) | no | — |
| permission_discussions | The level of permission to grant the access token for discussions and related comments and labels. (read/write) | no | — |
| permission_environments | The level of permission to grant the access token for managing repository environments. (read/write) | no | — |
| permission_issues | The level of permission to grant the access token for issues and related comments, assignees, labels, and milestones. (read/write) | no | — |
| permission_merge_queues | The level of permission to grant the access token to manage the merge queues for a repository. (read/write) | no | — |
| permission_metadata | The level of permission to grant the access token to search repositories, list collaborators, and access repository metadata. (read/write) | no | — |
| permission_packages | The level of permission to grant the access token for packages published to GitHub Packages. (read/write) | no | — |
| permission_pages | The level of permission to grant the access token to retrieve Pages statuses, configuration, and builds, as well as create new builds. (read/write) | no | — |
| permission_pull_requests | The level of permission to grant the access token for pull requests and related comments, assignees, labels, milestones, and merges. (read/write) | no | — |
| permission_repository_custom_properties | The level of permission to grant the access token to view and edit custom properties for a repository, when allowed by the property. (read/write) | no | — |
| permission_repository_hooks | The level of permission to grant the access token to manage the post-receive hooks for a repository. (read/write) | no | — |
| permission_repository_projects | The level of permission to grant the access token to manage repository projects, columns, and cards. (read/write/admin) | no | — |
| permission_secret_scanning_alerts | The level of permission to grant the access token to view and manage secret scanning alerts. (read/write) | no | — |
| permission_secrets | The level of permission to grant the access token to manage repository secrets. (read/write) | no | — |
| permission_security_events | The level of permission to grant the access token to view and manage security events like code scanning alerts. (read/write) | no | — |
| permission_single_file | The level of permission to grant the access token to manage just a single file. (read/write) | no | — |
| permission_statuses | The level of permission to grant the access token for commit statuses. (read/write) | no | — |
| permission_vulnerability_alerts | The level of permission to grant the access token to manage Dependabot alerts. (read/write) | no | — |
| permission_workflows | The level of permission to grant the access token to update GitHub Actions workflow files. (write) | no | — |
| permission_custom_properties_for_organizations | The level of permission to grant the access token to view and edit custom properties for an organization, when allowed by the property. (read/write) | no | — |
| permission_members | The level of permission to grant the access token for organization teams and members. (read/write) | no | — |
| permission_organization_administration | The level of permission to grant the access token to manage access to an organization. (read/write) | no | — |
| permission_organization_custom_roles | The level of permission to grant the access token for custom repository roles management. (read/write) | no | — |
| permission_organization_custom_org_roles | The level of permission to grant the access token for custom organization roles management. (read/write) | no | — |
| permission_organization_custom_properties | The level of permission to grant the access token for repository custom properties management at the organization level. (read/write/admin) | no | — |
| permission_organization_copilot_seat_management | The level of permission to grant the access token for managing access to GitHub Copilot for members of an organization with a Copilot Business subscription. This property is in public preview and is subject to change. (read/write) | no | — |
| permission_organization_copilot_agent_settings | The level of permission to grant the access token to view and manage Copilot cloud agent settings for an organization. (read/write) | no | — |
| permission_organization_announcement_banners | The level of permission to grant the access token to view and manage announcement banners for an organization. (read/write) | no | — |
| permission_organization_events | The level of permission to grant the access token to view events triggered by an activity in an organization. (read) | no | — |
| permission_organization_hooks | The level of permission to grant the access token to manage the post-receive hooks for an organization. (read/write) | no | — |
| permission_organization_personal_access_tokens | The level of permission to grant the access token for viewing and managing fine-grained personal access token requests to an organization. (read/write) | no | — |
| permission_organization_personal_access_token_requests | The level of permission to grant the access token for viewing and managing fine-grained personal access tokens that have been approved by an organization. (read/write) | no | — |
| permission_organization_plan | The level of permission to grant the access token for viewing an organization's plan. (read) | no | — |
| permission_organization_projects | The level of permission to grant the access token to manage organization projects and projects public preview (where available). (read/write/admin) | no | — |
| permission_organization_packages | The level of permission to grant the access token for organization packages published to GitHub Packages. (read/write) | no | — |
| permission_organization_secrets | The level of permission to grant the access token to manage organization secrets. (read/write) | no | — |
| permission_organization_self_hosted_runners | The level of permission to grant the access token to view and manage GitHub Actions self-hosted runners available to an organization. (read/write) | no | — |
| permission_organization_user_blocking | The level of permission to grant the access token to view and manage users blocked by the organization. (read/write) | no | — |
| permission_email_addresses | The level of permission to grant the access token to manage the email addresses belonging to a user. (read/write) | no | — |
| permission_followers | The level of permission to grant the access token to manage the followers belonging to a user. (read/write) | no | — |
| permission_git_ssh_keys | The level of permission to grant the access token to manage git SSH keys. (read/write) | no | — |
| permission_gpg_keys | The level of permission to grant the access token to view and manage GPG keys belonging to a user. (read/write) | no | — |
| permission_interaction_limits | The level of permission to grant the access token to view and manage interaction limits on a repository. (read/write) | no | — |
| permission_profile | The level of permission to grant the access token to manage the profile settings belonging to a user. (write) | no | — |
| permission_starring | The level of permission to grant the access token to list and manage repositories a user is starring. (read/write) | no | — |
| permission_enterprise_custom_properties_for_organizations | The level of permission to grant the access token for organization custom properties management at the enterprise level. (read/write/admin) | no | — |