SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
CI/CD New Added 8 September 2026

GitHub Actions: refusing to allow an OAuth App to create or update workflow

A push that adds or edits anything under .github/workflows was rejected because the token lacks the workflow scope. It is a deliberate guard: a token that could edit workflows could run arbitrary code with the repository's secrets.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Personal access token: add the workflow scope alongside repo
# Fine grained tokens need Workflows: read and write

# gh CLI
gh auth refresh -h github.com -s workflow

# Inside Actions, the default GITHUB_TOKEN cannot push workflow changes.
# Use a PAT or an App token in a secret:
- uses: actions/checkout@v4
  with:
    token: ${{ secrets.WORKFLOW_PAT }}

# Prefer a GitHub App installation token over a long lived PAT

How to diagnose CI/CD errors

CI failures that do not reproduce locally are almost always about environment, permissions or resource limits rather than about your code. CI runners have less memory than a laptop, a deliberately restricted token, a clean cache, and often a different CPU architecture. Treating a CI failure as a code bug before checking those four things wastes an enormous amount of time.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Re-run the job with debug logging enabled (ACTIONS_STEP_DEBUG=true in GitHub Actions, CI_DEBUG_TRACE in GitLab). The default log deliberately hides the most useful lines.
  2. Print the environment early: env | sort, node -v, free -m, df -h. Half of all "works on my machine" CI bugs are visible in that output.
  3. Check token permissions explicitly. GitHub's GITHUB_TOKEN defaults to read-only in many organisations and produces the misleading Resource not accessible by integration error.
  4. Remember that secrets are not available to workflows triggered by pull requests from forks. This is a security feature, not a misconfiguration.
  5. Reproduce locally in the same container image the runner uses, rather than on your host, before changing pipeline configuration.

Tools worth reaching for

  • ACTIONS_STEP_DEBUG
  • act (local Actions runner)
  • docker run <runner image>
  • free -m / df -h in-job

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

docs.github.com

Related CI/CD errors

See all 18 CI/CD errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.