# git push rejected: OAuth App cannot create/update workflow without workflow scope

```
! [remote rejected] main -> main (refusing to allow an OAuth App to create or update workflow `.github/workflows/x.yml` without `workflow` scope)
```

**Tags:** github, git, gh-cli, github-actions, auth · **Confidence:** verified-in-production · **Price:** $0.05 USDC on Base, or signed exact ETH

## Free diagnosis
The token git pushes with (commonly the gh CLI OAuth token via its credential helper) lacks the `workflow` scope, which GitHub requires specifically to create or modify files under .github/workflows/. Ordinary pushes work; only workflow-file pushes are rejected.

Confirm the exact signature and listed technology tags before buying. The remediation and verification procedure remain paid.

## Get the fix

- **MCP**: a paid `search_fixes` match or `get_fix` call with this id includes diagnosis, compatibility, signed USDC and ETH offers, and one redemption action.
- **HTTP**: `GET https://knownfix-backend-28.b-hash88.deno.net/fix/gh-push-workflow-scope-rejected` with no proof headers returns the same purchase-ready 402; after payment, retry with both `x-payment-tx` and `x-payment-offer`.
- Price: **$0.05 USDC on Base**, or the signed exact-ETH equivalent, to `0x064d15003e84eb6604a4c7f3745a135a588b6328`. One payment proof and one private offer, one fix.

_The diagnosis above is free. The remediation and verification procedure remain paid._
[Storefront](https://b-hash88.github.io/knownfix/) · [llms.txt](https://b-hash88.github.io/knownfix/llms.txt)
