GitHub Enterprise Cloud can now automate SSO authorization for classic PATs and SSH keys. An enterprise-installed GitHub App may authorize an existing credential across up to 50 organizations in one request.

Quick answer

ElementBehavior
Permissionenterprise_credentials:write.
Identifier sharedNon-secret PAT ID or SSH fingerprint.
ScopeUp to 50 organizations per call.
AvailabilityGitHub Enterprise Cloud.

Less manual work

In enterprises with many SSO organizations, every rotation previously required repeated approvals. That friction could encourage overly long-lived tokens. The API can run after rotation or when organizations are added.

Checks before delegation

GitHub verifies that targets belong to the enterprise, the credential owner belongs to them and enterprise-level SSO is in use. Existing active authorizations are safely skipped.

A highly sensitive permission

The delegating GitHub App needs strict scope, audit logs and protection. Automate against an expected organization list rather than open discovery, and test access removal paths.

Modernize beyond classic PATs

The feature solves an existing need but does not make long-lived tokens ideal. Prefer OIDC, short-lived GitHub App tokens or fine-grained PATs where possible. Automation should enable rotation, not preserve old secrets forever.