ST-2026-217 · Authentication & identity
GitHub adds credential revocation and deauthorization by token type
GitHub changed enterprise and organization incident-response controls so authorized administrators can revoke or deauthorize selected credential types for an enterprise or individual user instead of applying the prior all-credential kill switch.
Previous state
Incident-response deauthorization used broader credential handling rather than the newly documented token-type-specific revocation and deauthorization controls.
Current state
Authorized enterprise and organization administrators can target credential revocation or deauthorization by specific token type, including supported personal access tokens, SSH keys, OAuth app tokens and GitHub App user access tokens, with API/UI and audit-log support described by GitHub.
Affected users
Who needs to care
GitHub Enterprise owners, organization administrators and delegated members managing credential incident response.
Required response
What to do
Review incident-response runbooks and automation so credential containment targets the intended token types and verify delegated permissions and audit logging before use.
Evidence boundary
What the source does not prove
GitHub proves administrator controls for credential-type-specific revocation/deauthorization. It does not automatically revoke credentials, change token permissions or lifetimes, or establish identical behavior for credential types outside the documented scope.
Lifecycle history
Dated event sequence
- Credential-type controls announced
GitHub announced token-type-specific revocation and deauthorization controls.
Evidence ledger
First-party sources
- 01GitHub — Credential revocation and deauthorization by token type
Official GitHub Changelog · 2026-08-18
Open official source ↗