Skip to main content
The REST API is now versioned. For more information, see "About API versioning."

REST API endpoints for AI Scan

Use the REST API to get and update AI Scan settings for an organization.

Get the AI Scan setting for an organization

Note

This endpoint is in public preview and is subject to change.

Gets the AI Scan setting stored on an organization.

The response reports the value stored on the organization. Organization respects enterprise policy.

The authenticated user must be an owner or security manager for the organization to use this endpoint.

OAuth app tokens and personal access tokens (classic) need the admin:org, repo, or write:org scope to use this endpoint. Organization owners can use admin:org or repo; security managers need write:org.

Fine-grained access tokens for "Get the AI Scan setting for an organization"

This endpoint works with the following fine-grained token types:

The fine-grained token must have the following permission set:

  • "Administration" organization permissions (read)

Parameters for "Get the AI Scan setting for an organization"

Headers
Name, Type, Description
accept string

Setting to application/vnd.github+json is recommended.

Path parameters
Name, Type, Description
org string Required

The organization name. The name is not case sensitive.

HTTP response status codes for "Get the AI Scan setting for an organization"

Status codeDescription
200

OK

403

Forbidden

404

Resource not found

Code samples for "Get the AI Scan setting for an organization"

If you access GitHub at GHE.com, replace api.github.com with your enterprise's dedicated subdomain at api.SUBDOMAIN.ghe.com.

Request example

get/orgs/{org}/code-scanning/ai-scan
curl -L \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/code-scanning/ai-scan

Response

Status: 200
{ "pr_scan": "enabled" }

Update the AI Scan setting for an organization

Note

This endpoint is in public preview and is subject to change.

Updates the AI Scan setting stored on an organization.

The organization respects the enterprise policy, so enabling is rejected when the enterprise disallows AI Scan.

OAuth app tokens and personal access tokens (classic) need the admin:org, repo, or write:org scope to use this endpoint. Organization owners can use admin:org or repo; security managers need write:org.

Fine-grained access tokens for "Update the AI Scan setting for an organization"

This endpoint works with the following fine-grained token types:

The fine-grained token must have the following permission set:

  • "Administration" organization permissions (write)

Parameters for "Update the AI Scan setting for an organization"

Headers
Name, Type, Description
accept string

Setting to application/vnd.github+json is recommended.

Path parameters
Name, Type, Description
org string Required

The organization name. The name is not case sensitive.

Body parameters
Name, Type, Description
pr_scan string

Whether AI Scan is enabled for the organization. Organization respects enterprise policy. Disabled organizations prevent repositories from enabling AI Scan. Enabled organizations enable AI Scan for their repositories, but individual repositories can opt out.

Can be one of: enabled, disabled

HTTP response status codes for "Update the AI Scan setting for an organization"

Status codeDescription
200

OK

403

Forbidden

404

Resource not found

422

Validation failed, or the endpoint has been spammed.

Code samples for "Update the AI Scan setting for an organization"

If you access GitHub at GHE.com, replace api.github.com with your enterprise's dedicated subdomain at api.SUBDOMAIN.ghe.com.

Request example

patch/orgs/{org}/code-scanning/ai-scan
curl -L \ -X PATCH \ -H "Accept: application/vnd.github+json" \ -H "Authorization: Bearer <YOUR-TOKEN>" \ -H "X-GitHub-Api-Version: 2026-03-10" \ https://api.github.com/orgs/ORG/code-scanning/ai-scan \ -d '{"pr_scan":"enabled"}'

Response

Status: 200
{ "pr_scan": "enabled" }