---
title: "Set main branch protection"
method: PUT
path: "/api/apps/{app_id}/branches/main/protection"
---

# Set main branch protection

`PUT /api/apps/{app_id}/branches/main/protection`

<Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Turns protection of the app's main branch on or off.

While main is protected, calls that change main directly are refused with a 409, and the builder's AI can't edit main either. Make changes on a branch and merge it back instead. Setting the value the app already has changes nothing. Read the current value from `main_branch_protected` in [Get app](/api-reference/get-app).

Only the app owner or an admin of the app's workspace can change it. Editors can't, even though they can edit the app. This endpoint is limited to 10 requests per minute.

<Note>This endpoint accepts a personal API key belonging to the app owner or a workspace admin. A read-only key is refused, and workspace API keys are not accepted.</Note>

## Path parameters

- `app_id` string, required — ID of the app whose main branch to protect or unprotect.

## Request body

- MainBranchProtection
  - `protected` boolean, required — Whether the app's main branch is protected. While it is, changes to main have to go through a branch that you merge back.

## Response `200`

The main branch's protection after the change.

- MainBranchProtection
  - `protected` boolean, required — Whether the app's main branch is protected. While it is, changes to main have to go through a branch that you merge back.

## Other responses

- `401` — Missing or invalid credentials.
- `403` — You don't have editor access to this app, you aren't the app owner or a workspace admin, or your API key is read-only.
- `404` — App not found.
- `422` — `protected` is missing or isn't a boolean, or the body has other fields.
- `429` — Rate limit exceeded. The base limit is 10 requests per minute. See [Rate limits](/developers/references/apps-api/get-started/rate-limits) for the multiplier your plan gets.

## Changes

> 18 revisions in range; 1 not diffed.

- **2026-09-28** `28fc82924122` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/adexad/apis/base44-app-management-api/changes/api/apps/:app_id/branches/main/protection/put.md)

---

[API](https://skmtc.dev/adexad/apis/base44-app-management-api.md) · [All operations](https://skmtc.dev/adexad/apis/base44-app-management-api/llms.txt) · [OpenAPI document](https://skmtc.dev/adexad/apis/base44-app-management-api/revisions/28fc82924122?raw)
