GitHub Actions: Error: Resource not accessible by integration (403)
The workflow’s GITHUB_TOKEN doesn’t have the permission needed for that API call (comment, push, create release, write packages).
Seen on:
GitHub Actions
Meaning
Default token permissions are often read-only, and pull requests from forks get a read-only token. Grant the needed scopes with the permissions key, or use a PAT/GitHub App for cross-repo actions.
Common causes
- permissions block missing the needed scope (contents, pull-requests, issues, packages)
- Repository/org default token set to read-only
- Workflow triggered by a fork PR (read-only token)
- Acting on another repository
⚡ Quick fix
- Add a permissions block with the needed write scopes
- Use pull_request_target carefully (or a PAT) for fork PRs
- Use a GitHub App token for other repos
Detailed fix by platform
YAML
- yaml
permissions: contents: write pull-requests: write issues: write
How to diagnose
- Call — Which API failed?
- Token — Effective permissions in the job log
- Trigger — Fork PR?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026