API · SDK · runtime · authentication lifecycle intelligence

Last updated · 9 September 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-217 · Authentication & identity

GitHub adds credential revocation and deauthorization by token type

GitHub changed enterprise and organization incident-response controls so authorized administrators can revoke or deauthorize selected credential types for an enterprise or individual user instead of applying the prior all-credential kill switch.

GitHub Enterprisecredential revocationdeauthorizationpersonal access tokensSSH keys

Previous state

Incident-response deauthorization used broader credential handling rather than the newly documented token-type-specific revocation and deauthorization controls.

Current state

Authorized enterprise and organization administrators can target credential revocation or deauthorization by specific token type, including supported personal access tokens, SSH keys, OAuth app tokens and GitHub App user access tokens, with API/UI and audit-log support described by GitHub.

Who needs to care

GitHub Enterprise owners, organization administrators and delegated members managing credential incident response.

What to do

Review incident-response runbooks and automation so credential containment targets the intended token types and verify delegated permissions and audit logging before use.

What the source does not prove

GitHub proves administrator controls for credential-type-specific revocation/deauthorization. It does not automatically revoke credentials, change token permissions or lifetimes, or establish identical behavior for credential types outside the documented scope.

Lifecycle history

Dated event sequence

  1. Credential-type controls announced

    GitHub announced token-type-specific revocation and deauthorization controls.

Evidence ledger

First-party sources

  1. 01
    GitHub — Credential revocation and deauthorization by token type

    Official GitHub Changelog · 2026-08-18

    Open official source ↗