Repositories API Returns '401 Unauthorized' With Deploy Token

I was thinking about creating an issue for this, but I thought I’d ask here first. Is this expected behavior?:


When using a deploy token to access the Repositories API for a private, group repository, the response is

{"message":"401 Unauthorized"}

Steps to reproduce

  1. Generate a new read_repository scoped deploy token for your project via
  2. Run curl --request GET --header 'PRIVATE-TOKEN: your_deploy_token' ''

What is the current bug behavior?

The response is {"message":"401 Unauthorized"}

What is the expected correct behavior?

I expect this to return a list of repository files and directories in the project, because the deploy token should have read access to this repository.

Ah, I just found this issue