POST /api/v1/tenants/{tenantId}/repo-links.
releaseBranches (empty = no restriction). Because a git tag isn’t reliably “on” one branch, the OIDC path proves the branch through the workflow job’s environment: claim, checked against GitHub’s own environment deployment policy — not something this platform tries to derive itself. The PAT path takes --release-branch at face value: a weaker, unverified guarantee, consistent with PAT being the fallback auth path throughout.