Share feedback
Answers are generated based on the documentation.

Access token reference

Look up what an access token is allowed to do. You choose a permission or a set of scopes when you create the token.

Personal access token permissions

Each personal access token (PAT) has one permission level that you select when you create the token. The token applies to every repository your account can access. You can't limit a token to a single repository.

  • Repo Public Read-only: View, search, and pull images from public repositories. This is the default.
  • Repo Read-only: View, search, and pull images from public repositories and from private repositories you have access to.
  • Repo Read & Write: Everything in Repo Read-only, plus push images to any repository your account manages.
  • Repo Read, Write, Delete: Everything in Repo Read & Write, plus delete images and manage your repositories.
  • Cloud Sandboxes: Authenticate to the Docker Cloud Sandboxes API. Cloud Sandboxes is a paid feature.

Choose the lowest permission that covers what the token needs to do. For example, a CI job that only pulls a private base image needs Repo Read-only. You can change PAT permissions at any time if the PAT is active or inactive, but not expired.

Organization access token scopes

Scopes control what an organization access token (OAT) can do. You choose them when you create or edit the token. In Docker Home, each scope shows its name and a short description while the value in the table is what the token carries. You can change OAT scopes at any time if the OAT is active or inactive, but not expired.

Within a related set of operations, selecting a more capable scope also grants the less capable ones. For example:

  • Image Delete includes Image Push
  • Image Push includes Image Pull

If you select Image Delete, you don't need to select the other two. The Grants column notes each inclusion.

Repository scopes

Repository scopes apply to each repository you add, or to all repositories in the organization if you select All <organization> repositories.

ScopeValueGrants
Image Pullscope-image-pullPull images
Image Pushscope-image-pushPush images. Includes Image Pull
Image Deletescope-image-deleteDelete images and tags through registry endpoints. Includes Image Push
Repository Readscope-repository-readRead repository metadata, the Dockerfile, and stars
Repository Editscope-repository-editEdit privacy, categories, Dockerfile, description, and stars. Includes Repository Read
Repository Adminscope-repository-adminDelete the repository. Includes Repository Edit
Tag Readscope-tag-readList and read tags, image lists, attestations, and compose files
Tag Adminscope-tag-adminDelete tags. Includes Tag Read
Webhook Readscope-webhook-readList webhook pipelines and delivery history
Webhook Editscope-webhook-editCreate webhook pipelines. Includes Webhook Read
Webhook Adminscope-webhook-adminDelete webhook pipelines. Includes Webhook Edit
Repository Group Readscope-repo-group-readList and read repository group assignments
Repository Group Editscope-repo-group-editCreate and update repository group assignments. Includes Repository Group Read
Repository Group Adminscope-repo-group-adminDelete repository group assignments. Includes Repository Group Edit
Repository Settings Adminscope-repository-settings-adminConfigure immutable tag rules

Organization scopes

Organization scopes apply to the whole organization.

ScopeValueGrants
Member Readscope-member-readRead organization members
Member Editscope-member-editEdit organization members. Includes Member Read
Invite Readscope-invite-readRead invitations
Invite Editscope-invite-editEdit invitations. Includes Invite Read
Group Readscope-group-readRead the organization's groups (teams)
Group Editscope-group-editEdit the organization's groups (teams). Includes Group Read
Audit Log Readscope-activity-readRead the organization's activity logs
SIEM Credentials Readscope-siem_credentials-readRead SIEM destination settings, including credentials
Registry Access Management Readscope-ram-readRead Registry Access Management settings
Registry Access Management Editscope-ram-writeEdit Registry Access Management settings. Includes Registry Access Management Read
Report Readscope-report-readDownload organization usage reports
Repository Createscope-repository-createCreate repositories in the organization namespace
Repository Listscope-repository-listList all repositories in the namespace, including private ones
Registry Usage Readscope-registry-usage-readRead namespace-level registry usage metrics

Creating a repository requires the organization-level Repository Create scope. No repository scope grants it, not even Repository Admin on an existing repository.

Product scopes

These sections appear alongside Repository and Organization in the token's resources.

SectionScopeValueGrants
Docker Build CloudCloud Connectscope-cloud-connectConnect to, build with, and run on Docker Build Cloud
Docker GovernanceAudit Events Readscope-audit_events-readRead governance audit events
Docker GovernanceGovernance Policy Readscope-governance-policy-readRead governance policies
Docker GovernanceGovernance Policy Writescope-governance-policy-writeWrite governance policies. Includes Governance Policy Read

Docker Hub API

An OAT can authenticate most Docker Hub API endpoints under /v2/namespaces/{namespace}/repositories/. First create an OAT, then exchange it for a short-lived bearer token with the Create access token API. Use your organization name as the identifier and the OAT as the secret:

$ TOKEN=$(curl -s -X POST "https://hub.docker.com/v2/auth/token" \
    -H "Content-Type: application/json" \
    -d '{"identifier": "<YOUR_ORGANIZATION_NAME>", "secret": "<YOUR_OAT>"}' \
    | jq -r .access_token)

Pass the bearer token in the Authorization header:

$ curl -s -H "Authorization: Bearer $TOKEN" \
    "https://hub.docker.com/v2/namespaces/<YOUR_ORGANIZATION_NAME>/repositories"

Supported endpoints

The following endpoint groups accept OAT authentication:

  • Repositories: list, create, get, update, and delete
  • Tags: list, get, and delete; get tag images, attestations, and compose files
  • Dockerfile: get and update a repository's linked Dockerfile
  • Repository groups: list, get, create, update, and delete assignments
  • Stars: list, count, add, and remove
  • Immutable tags: update and verify policies
  • Repository categories, privacy, and webhook pipeline settings
  • Namespace metrics

Listing behavior

GET /v2/namespaces/{namespace}/repositories filters results by the token's scopes:

  • With Repository List (scope-repository-list), the response includes every repository, including private ones.
  • Without it, the response includes only public repositories.

The filtering is silent. The response is a normal 200 with no indication that private repositories were left out.

Unsupported legacy endpoints

OATs only work with the namespace-scoped routes described above. The following legacy paths reject every OAT, regardless of its scopes, with 403 token issued from organization access token is not allowed. Use the replacement endpoint instead:

Next steps