[metadata]
description: Learn how to diagnose and resolve common problems for the REST API.
google-site-verification: c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY
og:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
og:site_name: GitHub Docs
og:title: Troubleshooting the REST API - GitHub Docs
og:type: article
og:url: https://docs-internal.github.com/en/rest/using-the-rest-api/troubleshooting-the-rest-api
page-document-type: article
path-article: rest/using-the-rest-api/troubleshooting-the-rest-api
path-language: en
path-product: rest
path-version: free-pro-team@latest
status: 200
twitter:card: summary
twitter:description: Learn how to diagnose and resolve common problems for the REST API.
twitter:domain: docs-internal.github.com
twitter:image: https://docs.github.com/assets/cb-345/images/social-cards/rest.png
twitter:title: Troubleshooting the REST API - GitHub Docs
twitter:url: https://docs-internal.github.com/en/rest/using-the-rest-api/troubleshooting-the-rest-api
viewport: width=device-width, initial-scale=1

[document-links]
API Insights: /en/rest/orgs/api-insights
API Versions: /en/rest/about-the-rest-api/api-versions
About OAuth app access restrictions: /en/organizations/managing-oauth-access-to-your-organizations-data/about-oauth-app-access-restrictions
About the REST API: /en/rest/about-the-rest-api/about-the-rest-api
Actions concurrency groups: /en/rest/actions/concurrency-groups
Agent tasks: /en/rest/agent-tasks/agent-tasks
Alerts: /en/rest/dependabot/alerts
Approving updated permissions for a GitHub App: /en/apps/using-github-apps/approving-updated-permissions-for-a-github-app
Artifact attestations: /en/rest/orgs/attestations
Artifact metadata: /en/rest/orgs/artifact-metadata
Artifacts: /en/rest/actions/artifacts
Ask the GitHub community: https://github.com/orgs/community/discussions
Assignees: /en/rest/issues/assignees
Attestations: /en/rest/repos/attestations
Attestations: /en/rest/users/attestations
Authenticating to the REST API: /en/rest/authentication/authenticating-to-the-rest-api
Authenticating: /en/rest/authentication/authenticating-to-the-rest-api
Autolinks: /en/rest/repos/autolinks
Best practices for creating a GitHub App: /en/apps/creating-github-apps/about-creating-github-apps/best-practices-for-creating-a-github-app
Best practices for using the REST API: /en/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Best practices: /en/rest/using-the-rest-api/best-practices-for-using-the-rest-api
Billing usage: /en/rest/billing/usage
Blobs: /en/rest/git/blobs
Blocking users: /en/rest/orgs/blocking
Blocking users: /en/rest/users/blocking
Blog: https://github.blog
Branches: /en/rest/branches/branches
Breaking changes: /en/rest/about-the-rest-api/breaking-changes
Budgets: /en/rest/billing/budgets
Building a CI server: /en/rest/guides/building-a-ci-server
CORS and JSONP: /en/rest/using-the-rest-api/using-cors-and-jsonp-to-make-cross-origin-requests
Cache: /en/rest/actions/cache
Check runs: /en/rest/checks/runs
Check suites: /en/rest/checks/suites
Classroom: /en/rest/classroom/classroom
Cloud agent repository management: /en/rest/copilot/copilot-cloud-agent-management
Code quality: /en/rest/code-quality/code-quality
Code scanning: /en/rest/code-scanning/code-scanning
Codes of conduct: /en/rest/codes-of-conduct/codes-of-conduct
Codespaces: /en/rest/codespaces/codespaces
Collaborators: /en/rest/collaborators/collaborators
Collaborators: /en/rest/copilot-spaces/collaborators
Comments: /en/rest/gists/comments
Comments: /en/rest/issues/comments
Commit comments: /en/rest/commits/comments
Commit statuses: /en/rest/commits/statuses
Commits: /en/rest/commits/commits
Commits: /en/rest/git/commits
Community: /en/rest/metrics/community
Comparing GitHub's APIs: /en/rest/about-the-rest-api/comparing-githubs-rest-api-and-graphql-api
Configurations: /en/rest/code-security/configurations
Contact support: https://support.github.com
Contents: /en/rest/repos/contents
Copilot Spaces: /en/rest/copilot-spaces/copilot-spaces
Copilot cloud agent management: /en/rest/copilot/copilot-coding-agent-management
Copilot content exclusion management: /en/rest/copilot/copilot-content-exclusion-management
Copilot usage metrics: /en/rest/copilot/copilot-usage-metrics
Copilot user management: /en/rest/copilot/copilot-user-management
Custom patterns: /en/rest/secret-scanning/custom-patterns
Custom properties: /en/rest/orgs/custom-properties
Custom properties: /en/rest/repos/custom-properties
Delivering deployments: /en/rest/guides/delivering-deployments
Dependency review: /en/rest/dependency-graph/dependency-review
Dependency submission: /en/rest/dependency-graph/dependency-submission
Deploy keys: /en/rest/deploy-keys/deploy-keys
Deployment branch policies: /en/rest/deployments/branch-policies
Deployment statuses: /en/rest/deployments/statuses
Deployments: /en/rest/deployments/deployments
Discover resources for a user: /en/rest/guides/discovering-resources-for-a-user
Draft Project items: /en/rest/projects/drafts
Emails: /en/rest/users/emails
Emojis: /en/rest/emojis/emojis
Encrypt secrets: /en/rest/guides/encrypting-secrets-for-the-rest-api
Endpoints for GitHub App installation tokens: /en/rest/authentication/endpoints-available-for-github-app-installation-access-tokens
Endpoints for GitHub App user tokens: /en/rest/authentication/endpoints-available-for-github-app-user-access-tokens
Endpoints for fine-grained PATs: /en/rest/authentication/endpoints-available-for-fine-grained-personal-access-tokens
Enterprise team members: /en/rest/enterprise-teams/enterprise-team-members
Enterprise team organizations: /en/rest/enterprise-teams/enterprise-team-organizations
Enterprise teams: /en/rest/enterprise-teams/enterprise-teams
Environments: /en/rest/deployments/environments
Events: /en/rest/activity/events
Events: /en/rest/issues/events
Expert services: https://services.github.com
Feeds: /en/rest/activity/feeds
Followers: /en/rest/users/followers
Forks: /en/rest/repos/forks
GPG keys: /en/rest/users/gpg-keys
Get started - Checks: /en/rest/guides/using-the-rest-api-to-interact-with-checks
Get started - Git database: /en/rest/guides/using-the-rest-api-to-interact-with-your-git-database
Getting started: /en/rest/using-the-rest-api/getting-started-with-the-rest-api
Gists: /en/rest/gists/gists
Git SSH keys: /en/rest/users/keys
GitHub Apps: /en/rest/apps/apps
GitHub Docs: /en
GitHub event types: /en/rest/using-the-rest-api/github-event-types
GitHub status API: https://www.githubstatus.com/api
GitHub-hosted runners: /en/rest/actions/hosted-runners
Gitignore: /en/rest/gitignore/gitignore
Global security advisories: /en/rest/security-advisories/global-advisories
Home: /en
Installations: /en/rest/apps/installations
Invitations: /en/rest/collaborators/invitations
Issue dependencies: /en/rest/issues/issue-dependencies
Issue event types: /en/rest/using-the-rest-api/issue-event-types
Issue field values: /en/rest/issues/issue-field-values
Issue fields: /en/rest/orgs/issue-fields
Issue types: /en/rest/orgs/issue-types
Issue types: /en/rest/repos/issue-types
Issues: /en/rest/issues/issues
Keeping API credentials secure: /en/rest/authentication/keeping-your-api-credentials-secure
Labels: /en/rest/issues/labels
Learn how to contribute: /contributing
Libraries: /en/rest/using-the-rest-api/libraries-for-the-rest-api
Licenses: /en/rest/licenses/licenses
Machines: /en/rest/codespaces/machines
Make a contribution: https://github.com/github/docs/blob/main/content/rest/using-the-rest-api/troubleshooting-the-rest-api.md
Managing your personal access tokens: /en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens#creating-a-fine-grained-personal-access-token
Markdown: /en/rest/markdown/markdown
Marketplace: /en/rest/apps/marketplace
Members: /en/rest/orgs/members
Members: /en/rest/teams/members
Meta: /en/rest/meta/meta
Milestones: /en/rest/issues/milestones
Network configurations: /en/rest/orgs/network-configurations
Notifications: /en/rest/activity/notifications
OAuth authorizations: /en/rest/apps/oauth-applications
OIDC: /en/rest/actions/oidc
OpenAPI description: /en/rest/about-the-rest-api/about-the-openapi-description-for-the-rest-api
Organization configurations: /en/rest/private-registries/organization-configurations
Organization roles: /en/rest/orgs/organization-roles
Organization secrets: /en/rest/codespaces/organization-secrets
Organization: /en/rest/interactions/orgs
Organizations: /en/rest/codespaces/organizations
Organizations: /en/rest/migrations/orgs
Organizations: /en/rest/orgs/orgs
Outside collaborators: /en/rest/orgs/outside-collaborators
Packages: /en/rest/packages/packages
Pages: /en/rest/pages/pages
Pagination: /en/rest/using-the-rest-api/using-pagination-in-the-rest-api
Permissions for GitHub Apps: /en/rest/authentication/permissions-required-for-github-apps
Permissions for fine-grained PATs: /en/rest/authentication/permissions-required-for-fine-grained-personal-access-tokens
Permissions: /en/rest/actions/permissions
Personal access tokens: /en/rest/orgs/personal-access-tokens
Pricing: https://github.com/pricing
Privacy policy: /en/site-policy/privacy-policies/github-privacy-statement
Privacy: /en/site-policy/privacy-policies/github-privacy-statement
Project fields: /en/rest/projects/fields
Project items: /en/rest/projects/items
Project views: /en/rest/projects/views
Projects: /en/rest/projects/projects
Protected branches: /en/rest/branches/branch-protection
Protection rules: /en/rest/deployments/protection-rules
Pull requests: /en/rest/pulls/pulls
Push protection: /en/rest/secret-scanning/push-protection
Quickstart: /en/rest/quickstart
REST API: /en/rest
Rate limit: /en/rest/rate-limit/rate-limit
Rate limits for the REST API: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Rate limits: /en/rest/using-the-rest-api/rate-limits-for-the-rest-api
Reactions: /en/rest/reactions/reactions
References: /en/rest/git/refs
Release assets: /en/rest/releases/assets
Releases: /en/rest/releases/releases
Rendering data as graphs: /en/rest/guides/rendering-data-as-graphs
Repositories: /en/rest/repos/repos
Repository access: /en/rest/dependabot/repository-access
Repository secrets: /en/rest/codespaces/repository-secrets
Repository security advisories: /en/rest/security-advisories/repository-advisories
Repository: /en/rest/interactions/repos
Resources: /en/rest/copilot-spaces/resources
Review comments: /en/rest/pulls/comments
Review requests: /en/rest/pulls/review-requests
Reviews: /en/rest/pulls/reviews
Revocation: /en/rest/credentials/revoke
Rule suites: /en/rest/orgs/rule-suites
Rule suites: /en/rest/repos/rule-suites
Rules: /en/rest/orgs/rules
Rules: /en/rest/repos/rules
SSH signing keys: /en/rest/users/ssh-signing-keys
Scopes for OAuth apps: /en/apps/oauth-apps/building-oauth-apps/scopes-for-oauth-apps#available-scopes
Script with JavaScript: /en/rest/guides/scripting-with-the-rest-api-and-javascript
Script with Ruby: /en/rest/guides/scripting-with-the-rest-api-and-ruby
Search: /en/rest/search/search
Secret scanning: /en/rest/secret-scanning/secret-scanning
Secrets: /en/rest/actions/secrets
Secrets: /en/rest/agents/secrets
Secrets: /en/rest/dependabot/secrets
Security campaigns: /en/rest/campaigns/campaigns
Security managers: /en/rest/orgs/security-managers
Self-hosted runner groups: /en/rest/actions/self-hosted-runner-groups
Self-hosted runners: /en/rest/actions/self-hosted-runners
Social accounts: /en/rest/users/social-accounts
Software bill of materials (SBOM): /en/rest/dependency-graph/sboms
Source endpoints: /en/rest/migrations/source-imports
Stacked pull requests: /en/rest/pulls/stacks
Starring: /en/rest/activity/starring
Statistics: /en/rest/metrics/statistics
Status: https://www.githubstatus.com/
Sub-issues: /en/rest/issues/sub-issues
Tags: /en/rest/git/tags
Teams: /en/rest/teams/teams
Terms: /en/site-policy/github-terms/github-terms-of-service
Timeline: /en/rest/issues/timeline
Timezones: /en/rest/using-the-rest-api/timezones-and-the-rest-api
Token expiration and revocation: /en/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation
Traffic: /en/rest/metrics/traffic
Trees: /en/rest/git/trees
Troubleshooting webhooks: /en/webhooks/testing-and-troubleshooting-webhooks/troubleshooting-webhooks
Troubleshooting: /en/rest/using-the-rest-api/troubleshooting-the-rest-api
User secrets: /en/rest/codespaces/secrets
User: /en/rest/interactions/user
Users: /en/rest/migrations/users
Users: /en/rest/users/users
Using pagination in the REST API: /en/rest/using-the-rest-api/using-pagination-in-the-rest-api
Using the REST API: /en/rest/using-the-rest-api
Variables: /en/rest/actions/variables
Variables: /en/rest/agents/variables
Watching: /en/rest/activity/watching
Webhooks: /en/rest/apps/webhooks
Webhooks: /en/rest/orgs/webhooks
Webhooks: /en/rest/repos/webhooks
Workflow jobs: /en/rest/actions/workflow-jobs
Workflow runs: /en/rest/actions/workflow-runs
Workflows: /en/rest/actions/workflows
Working with comments: /en/rest/guides/working-with-comments
githubstatus.com: https://www.githubstatus.com/

[content]
Troubleshooting the REST API - GitHub Docs
Skip to main content
GitHub Docs
Version:
Free, Pro, & Team
Search or ask Copilot
Search or ask
Copilot
Select language: current language is English
Search or ask Copilot
Search or ask
Copilot
Open menu
Collapse sidebar
Expand sidebar
Scroll breadcrumbs left
Home
REST API
Using the REST API
Troubleshooting
Scroll breadcrumbs right
REST API
API Version:
2026-03-10 (latest)
Quickstart
About the REST API
About the REST API
Comparing GitHub's APIs
API Versions
Breaking changes
OpenAPI description
Using the REST API
Getting started
Rate limits
Pagination
Libraries
Best practices
Troubleshooting
Timezones
CORS and JSONP
Issue event types
GitHub event types
Authentication
Authenticating
Keeping API credentials secure
Endpoints for GitHub App installation tokens
Endpoints for GitHub App user tokens
Endpoints for fine-grained PATs
Permissions for GitHub Apps
Permissions for fine-grained PATs
Guides
Script with JavaScript
Script with Ruby
Discover resources for a user
Delivering deployments
Rendering data as graphs
Working with comments
Building a CI server
Get started - Git database
Get started - Checks
Encrypt secrets
Actions
Artifacts
Cache
Actions concurrency groups
GitHub-hosted runners
OIDC
Permissions
Secrets
Self-hosted runner groups
Self-hosted runners
Variables
Workflow jobs
Workflow runs
Workflows
Activity
Events
Feeds
Notifications
Starring
Watching
Agent tasks
Agent tasks
Agents
Secrets
Variables
Apps
GitHub Apps
Installations
Marketplace
OAuth authorizations
Webhooks
Billing
Budgets
Billing usage
Branches
Branches
Protected branches
Campaigns
Security campaigns
Checks
Check runs
Check suites
Classroom
Classroom
Code quality
Code quality
Code scanning
Code scanning
Code security settings
Configurations
Codes of conduct
Codes of conduct
Codespaces
Codespaces
Organizations
Organization secrets
Machines
Repository secrets
User secrets
Collaborators
Collaborators
Invitations
Commits
Commits
Commit comments
Commit statuses
Copilot
Cloud agent repository management
Copilot cloud agent management
Copilot content exclusion management
Copilot usage metrics
Copilot user management
Copilot Spaces
Collaborators
Copilot Spaces
Resources
Credentials
Revocation
Dependabot
Alerts
Repository access
Secrets
Dependency graph
Dependency review
Dependency submission
Software bill of materials (SBOM)
Deploy keys
Deploy keys
Deployments
Deployment branch policies
Deployments
Environments
Protection rules
Deployment statuses
Emojis
Emojis
Enterprise teams
Enterprise team members
Enterprise team organizations
Enterprise teams
Gists
Gists
Comments
Git database
Blobs
Commits
References
Tags
Trees
Gitignore
Gitignore
Interactions
Organization
Repository
User
Issues
Assignees
Comments
Events
Issue dependencies
Issue field values
Issues
Labels
Milestones
Sub-issues
Timeline
Licenses
Licenses
Markdown
Markdown
Meta
Meta
Metrics
Community
Statistics
Traffic
Migrations
Organizations
Source endpoints
Users
Organizations
API Insights
Artifact metadata
Artifact attestations
Blocking users
Custom properties
Issue fields
Issue types
Members
Network configurations
Organization roles
Organizations
Outside collaborators
Personal access tokens
Rule suites
Rules
Security managers
Webhooks
Packages
Packages
Pages
Pages
Private registries
Organization configurations
Projects
Draft Project items
Project fields
Project items
Projects
Project views
Pull requests
Review comments
Pull requests
Review requests
Reviews
Stacked pull requests
Rate limit
Rate limit
Reactions
Reactions
Releases
Releases
Release assets
Repositories
Attestations
Autolinks
Contents
Custom properties
Forks
Issue types
Repositories
Rule suites
Rules
Webhooks
Search
Search
Secret scanning
Custom patterns
Push protection
Secret scanning
Security advisories
Global security advisories
Repository security advisories
Teams
Members
Teams
Users
Attestations
Blocking users
Emails
Followers
GPG keys
Git SSH keys
Social accounts
SSH signing keys
Users
Troubleshooting the REST API
Learn how to diagnose and resolve common problems for the REST API.
Copy as Markdown
In this article
Rate limit errors
404 Not Found for an existing resource
Missing results
Requires authentication when using basic authentication
Timeouts
Resource not accessible
Problems parsing JSON
Body should be a JSON object
Invalid request
Validation Failed
Not a supported version
User agent required
Other errors
Further reading
Rate limit errors
GitHub enforces rate limits to ensure that the API stays available for all users. For more information, see
Rate limits for the REST API
.
If you exceed your primary rate limit, you will receive a
403 Forbidden
or
429 Too Many Requests
response, and the
x-ratelimit-remaining
header will be
0
. If you exceed a secondary rate limit, you will receive a
403 Forbidden
or
429 Too Many Requests
response and an error message that indicates that you exceeded a secondary rate limit.
If you receive a rate limit error, you should stop making requests temporarily according to these guidelines:
If the
retry-after
response header is present, you should not retry your request until after that many seconds has elapsed.
If the
x-ratelimit-remaining
header is
0
, you should not make another request until after the time specified by the
x-ratelimit-reset
header. The
x-ratelimit-reset
header is in UTC epoch seconds.
Otherwise, wait for at least one minute before retrying. If your request continues to fail due to a secondary rate limit, wait for an exponentially increasing amount of time between retries, and throw an error after a specific number of retries.
Continuing to make requests while you are rate limited may result in the banning of your integration.
For more information about how to avoid exceeding the rate limits, see
Best practices for using the REST API
.
404 Not Found
for an existing resource
If you make a request to access a private resource and your request isn't properly authenticated, you will receive a
404 Not Found
response. GitHub uses a
404 Not Found
response instead of a
403 Forbidden
response to avoid confirming the existence of private repositories.
If you get a
404 Not Found
response when you know that the resource that you are requesting exists, you should check your authentication. For example:
If you are using a personal access token (classic), you should ensure that:
The token has the scopes that are required to use the endpoint. For more information, see
Scopes for OAuth apps
and
Managing your personal access tokens
.
The owner of the token has any permissions that are required to use the endpoint. For example, if an endpoint can only be used by organization owners, only users that are owners of the affected organization can use the endpoint.
The token has not been expired or revoked. For more information, see
Token expiration and revocation
.
If you are using a fine-grained personal access token, you should ensure that:
The token has the permissions that are required to use the endpoint. For more information about the required permissions, see the documentation for the endpoint.
The resource owner that was specified for the token matches the owner of the resource that the endpoint will affect. For more information, see
Managing your personal access tokens
.
The token has access to any private repositories that the endpoint will affect. For more information, see
Managing your personal access tokens
.
The owner of the token has any permissions that are required to use the endpoint. For example, if an endpoint can only be used by organization owners, only users that are owners of the affected organization can use the endpoint.
The token has not been expired or revoked. For more information, see
Token expiration and revocation
.
If you are using a GitHub App installation access token, you should ensure that:
The GitHub App has the permissions that are required to use the endpoint. For more information about the required permissions, see the documentation for the endpoint.
The endpoint is only affecting resources owned by the account where the GitHub App is installed.
The GitHub App has access to any repositories that the endpoint will affect.
The token has not been expired or revoked. For more information, see
Token expiration and revocation
.
If you are using a GitHub App user access token, you should ensure that:
The GitHub App has the permissions that are required to use the endpoint. For more information about the required permissions, see the documentation for the endpoint.
The user that authorized the token has any permissions that are required to use the endpoint. For example, if an endpoint can only be used by organization owners, only users that are owners of the affected organization can use the endpoint.
The GitHub App has access to any repositories that the endpoint will affect.
The user has access to any repositories that the endpoint will affect.
The user has approved any updated permissions for your GitHub App. For more information, see
Approving updated permissions for a GitHub App
.
If you are using an OAuth app user access token, you should ensure that:
The token has the scopes that are required to use the endpoint. For more information, see
Scopes for OAuth apps
.
The user that authorized the token has any permissions that are required to use the endpoint. For example, if an endpoint can only be used by organization owners, only users that are owners of the affected organization can use the endpoint.
The organization has not blocked OAuth app access, if you are using an endpoint that will affect resources owned by an organization. App owners cannot see whether their app is blocked, but they can instruct users of the app to check this. For more information, see
About OAuth app access restrictions
.
The token has not been expired or revoked. For more information, see
Token expiration and revocation
.
If you are using
GITHUB_TOKEN
in a GitHub Actions workflow, you should ensure that:
The endpoint is only affecting resources owned by the repository where the workflow is running. If you need to access resources outside of that repository, such as resources owned by an organization or resources owned by another repository, you should use a personal access token or an access token for a GitHub App.
For more information about authentication, see
Authenticating to the REST API
.
You should also check for typos in your URL. For example, adding a trailing slash to the endpoint will result in a
404 Not Found
. You can refer to the reference documentation for the endpoint to confirm that you have the correct URL.
Additionally, any path parameters must be URL encoded. For example, any slashes in the parameter value must be replaced with
%2F
. If you don't properly encode any slashes in the parameter name, the endpoint URL will be misinterpreted.
You should also confirm that you are using an HTTP method that the endpoint supports. If you send a request with an HTTP method that the endpoint does not support, you will receive a
404 Not Found
response instead of
405 Method Not Allowed
. For example, sending a
DELETE
request to an endpoint that only supports
GET
will result in a
404 Not Found
response. You can refer to the reference documentation for the endpoint to confirm the supported HTTP method.
Missing results
Most endpoints that return a list of resources support pagination. For most of these endpoints, only the first 30 resources are returned by default. In order to see all of the resources, you need to paginate through the results. For more information, see
Using pagination in the REST API
.
If you are using pagination correctly and still do not see all of the results that you expect, you should confirm that the authentication credentials that you used have access to all of the expected resources. For example, if you are using a GitHub App installation access token, if the installation was only granted access to a subset of repositories in an organization, any request for all repositories in that organization will return only the repositories that the app installation can access.
Requires authentication when using basic authentication
Basic authentication with your username and password is not supported. Instead, you should use a personal access token or an access token for a GitHub App or OAuth app. For more information, see
Authenticating to the REST API
.
Timeouts
If GitHub takes more than 10 seconds to process an API request, GitHub will terminate the request and you will receive a timeout response and a "Server Error" message.
GitHub reserves the right to change the timeout window to protect the speed and reliability of the API.
You can check the status of the REST API at
githubstatus.com
to determine whether the timeout is due to a problem with the API. You can also try to simplify your request or try your request later. For example, if you are requesting 100 items on a page, you can try requesting fewer items.
Resource not accessible
If you are using a GitHub App or fine-grained personal access token and you receive a "Resource not accessible by integration" or "Resource not accessible by personal access token" error, then your token has insufficient permissions. For more information about the required permissions, see the documentation for the endpoint.
You can use the
X-Accepted-GitHub-Permissions
header to identify the permissions that are required to access the REST API endpoint.
The value of the
X-Accepted-GitHub-Permissions
header is a comma separated list of the permissions that are required to use the endpoint. Occasionally, you can choose from multiple permission sets. In these cases, multiple comma-separated lists will be separated by a semicolon.
For example:
X-Accepted-GitHub-Permissions: contents=read
means that your GitHub App or fine-grained personal access token needs read access to the contents permission.
X-Accepted-GitHub-Permissions: pull_requests=write,contents=read
means that your GitHub App or fine-grained personal access token needs write access to the pull request permission and read access to the contents permission.
X-Accepted-GitHub-Permissions: pull_requests=read,contents=read; issues=read,contents=read
means that your GitHub App or fine-grained personal access token needs either read access to the pull request permission and read access to the contents permission, or read access to the issues permission and read access to the contents permission.
Problems parsing JSON
If you send invalid JSON in the request body, you may receive a
400 Bad Request
response and a "Problems parsing JSON" error message. You can use a linter or JSON validator to help you identify errors in your JSON.
Body should be a JSON object
If the endpoint expects a JSON object and you do not format your request body as a JSON object, you may receive a
400 Bad Request
response and a "Body should be a JSON object" error message.
Invalid request
If you omit required parameters or you use the wrong type for a parameter, you may receive a
422 Unprocessable Entity
response and an "Invalid request" error message. For example, you will get this error if you specify a parameter value as an array but the endpoint is expecting a string. You can refer to the reference documentation for the endpoint to verify that you are using the correct parameter types and that you are including all of the required parameters.
Validation Failed
If your request could not be processed, you may receive a
422 Unprocessable Entity
response and a "Validation Failed" error message. The response body will include an
errors
property, which includes a
code
property to help you diagnose the problem.
Code
Description
missing
A resource does not exist.
missing_field
A parameter that was required was not specified. Review the documentation for the endpoint to see what parameters are required.
invalid
The formatting of a parameter is invalid. Review the endpoint documentation for more specific information.
already_exists
Another resource has the same value as one of your parameters. This can happen in resources that must have some unique key (such as label names).
unprocessable
The parameters that were provided were invalid.
custom
Refer to the
message
property to diagnose the error.
Not a supported version
You should use the
X-GitHub-Api-Version
header to specify an API version. For example:
curl --header "X-GitHub-Api-Version:2026-03-10" https://api.github.com/zen
If you specify a version that does not exist, you will receive a
400 Bad Request
error and a message about the version not being supported.
For more information, see
API Versions
.
User agent required
Requests without a valid
User-Agent
header will be rejected. You should use your username or the name of your application for the
User-Agent
value.
curl sends a valid
User-Agent
header by default.
Other errors
If you observe an error that is not addressed here, you should refer to the error message that the API gives you. Most error messages will provide a clue about what is wrong and a link to relevant documentation.
If you observe unexpected failures, you can use
githubstatus.com
or the
GitHub status API
to check for incidents affecting the API.
Further reading
Best practices for using the REST API
Troubleshooting webhooks
Best practices for creating a GitHub App
Help and support
Did you find what you needed?
Yes
No
Privacy policy
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
Learn how to contribute
Still need help?
Ask the GitHub community
Contact support
Legal
©
2026
GitHub, Inc.
Terms
Privacy
Status
Pricing
Expert services
Blog
