ST-2026-057 · Authentication & identity
GitHub adds enterprise and self-service credential revocation
Enterprise owners, delegated managers and individual members gained bulk SSO-authorisation revocation and bounded token or SSH-key deletion controls.
Previous state
Incident response lacked the new enterprise-wide and member self-service bulk revocation surfaces.
Current state
Authorised administrators and members can revoke SSO authorisations; EMU administrators can additionally delete tokens and SSH keys.
Affected users
Who needs to care
GitHub Enterprise Cloud organisations and members responding to credential compromise.
Required response
What to do
Delegate the manager role carefully, integrate audit receipts and distinguish revocation from deletion.
Evidence boundary
What the source does not prove
Credential deletion is EMU-only, and SSO revocation does not necessarily delete the credential or affect non-SSO resources.
Lifecycle history
Dated event sequence
- Controls released
Enterprise and self-service credential revocation became available.
Evidence ledger
First-party sources
- 01GitHub Changelog — Self-service credential revocation for incident response
Official product changelog · 2026-06-24
Open official source ↗