enterprise-application-connectors · prepared

GitLab REST API connector boundary

Official-source public-read, OAuth, personal/project/group token, job-token, and endpoint-specific authorization boundaries for GitLab connectors.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.gitlab-rest-api
sha256:627e732d08c41a782b4a370fa1b34fc18c2aa673d4e7d3670c22d164c2c6b10c

Open canonical machine JSON →

Evidence-backed facts

  1. GitLab documents some public endpoints that need no authentication, while most API requests require a supported credential. informative
  2. A token type or successful login does not authorize every mutation; project, group, user, role, and endpoint rules still apply. informative
  3. Supported API credentials include OAuth, personal, project, group, and endpoint-limited CI job tokens, normally carried in authorization headers. informative
  4. Deploy tokens cannot call the public REST API, job tokens cover only documented endpoints, and administrator impersonation must never be a default connector mode. informative