GitHub Enterprise Cloud can now automate SSO authorization for classic PATs and SSH keys. An enterprise-installed GitHub App may authorize an existing credential across up to 50 organizations in one request.
Quick answer
| Element | Behavior |
|---|---|
| Permission | enterprise_credentials:write. |
| Identifier shared | Non-secret PAT ID or SSH fingerprint. |
| Scope | Up to 50 organizations per call. |
| Availability | GitHub Enterprise Cloud. |
Less manual work
In enterprises with many SSO organizations, every rotation previously required repeated approvals. That friction could encourage overly long-lived tokens. The API can run after rotation or when organizations are added.
Checks before delegation
GitHub verifies that targets belong to the enterprise, the credential owner belongs to them and enterprise-level SSO is in use. Existing active authorizations are safely skipped.
A highly sensitive permission
The delegating GitHub App needs strict scope, audit logs and protection. Automate against an expected organization list rather than open discovery, and test access removal paths.
Modernize beyond classic PATs
The feature solves an existing need but does not make long-lived tokens ideal. Prefer OIDC, short-lived GitHub App tokens or fine-grained PATs where possible. Automation should enable rotation, not preserve old secrets forever.




Join the discussion
Comments
Loading comments…