REST API endpoints for AI Scan
Use the REST API to get and update AI Scan settings for an organization.
Get the AI Scan setting for an organization
Note
This endpoint is in public preview and is subject to change.
Gets the AI Scan setting stored on an organization.
The response reports the value stored on the organization. Organization respects enterprise policy.
The authenticated user must be an owner or security manager for the organization to use this endpoint.
OAuth app tokens and personal access tokens (classic) need the admin:org, repo, or write:org scope to use this endpoint. Organization owners can use admin:org or repo; security managers need write:org.
Fine-grained access tokens for "Get the AI Scan setting for an organization"
This endpoint works with the following fine-grained token types:
- GitHub App user access tokens
- GitHub App installation access tokens
- Fine-grained personal access tokens
The fine-grained token must have the following permission set:
- "Administration" organization permissions (read)
Parameters for "Get the AI Scan setting for an organization"
| Name, Type, Description |
|---|
accept string Setting to |
| Name, Type, Description |
|---|
org string RequiredThe organization name. The name is not case sensitive. |
HTTP response status codes for "Get the AI Scan setting for an organization"
| Status code | Description |
|---|---|
200 | OK |
403 | Forbidden |
404 | Resource not found |
Code samples for "Get the AI Scan setting for an organization"
Request example
curl -L \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/code-scanning/ai-scanResponse
Status: 200{
"pr_scan": "enabled"
}Update the AI Scan setting for an organization
Note
This endpoint is in public preview and is subject to change.
Updates the AI Scan setting stored on an organization.
The organization respects the enterprise policy, so enabling is rejected when the enterprise disallows AI Scan.
OAuth app tokens and personal access tokens (classic) need the admin:org, repo, or write:org scope to use this endpoint. Organization owners can use admin:org or repo; security managers need write:org.
Fine-grained access tokens for "Update the AI Scan setting for an organization"
This endpoint works with the following fine-grained token types:
- GitHub App user access tokens
- GitHub App installation access tokens
- Fine-grained personal access tokens
The fine-grained token must have the following permission set:
- "Administration" organization permissions (write)
Parameters for "Update the AI Scan setting for an organization"
| Name, Type, Description |
|---|
accept string Setting to |
| Name, Type, Description |
|---|
org string RequiredThe organization name. The name is not case sensitive. |
| Name, Type, Description |
|---|
pr_scan string Whether AI Scan is enabled for the organization. Organization respects enterprise policy. Disabled organizations prevent repositories from enabling AI Scan. Enabled organizations enable AI Scan for their repositories, but individual repositories can opt out. Can be one of: |
HTTP response status codes for "Update the AI Scan setting for an organization"
| Status code | Description |
|---|---|
200 | OK |
403 | Forbidden |
404 | Resource not found |
422 | Validation failed, or the endpoint has been spammed. |
Code samples for "Update the AI Scan setting for an organization"
Request example
curl -L \
-X PATCH \
-H "Accept: application/vnd.github+json" \
-H "Authorization: Bearer <YOUR-TOKEN>" \
-H "X-GitHub-Api-Version: 2026-03-10" \
https://api.github.com/orgs/ORG/code-scanning/ai-scan \
-d '{"pr_scan":"enabled"}'Response
Status: 200{
"pr_scan": "enabled"
}