Skip to content

Fine-grained PATs can access Enterprise APIs [Preview] #1119

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
glider-bot opened this issue Mar 21, 2025 · 0 comments
Open

Fine-grained PATs can access Enterprise APIs [Preview] #1119

glider-bot opened this issue Mar 21, 2025 · 0 comments
Labels
Copilot Enterprise Product SKU: Copilot Enterprise Copilot for Business Product SKU: Copilot for Business Enterprise Product SKU: GitHub Enterprise preview Feature phase: Preview

Comments

@glider-bot
Copy link
Collaborator

Value Prop

Today, only PATs (Personal Access Tokens) Classic can interact with the Enterprise account - managing SCIM and users, creating organizations, setting policy, and provisioning self-hosted runners, as popular examples. By switching to fine-grained PATs for these APIs, enterprises get a better least-privilege security posture. With this release, you can use tokens with just enough permission to accomplish the job instead of a PAT (Classic) that requires permission to do anything to your enterprise.

Expected Outcome

This release trails #793, which establishes the fine-grained permissions model for the enterprise. Because each API must be updated individually to support new permissions, not every single API will be supported at the time of the public preview. We are prioritizing the most popular APIs to ensure that enterprises can replace the highest number of PATs (Classic), and will ship with at least those for the public preview.

These APIs are:

  1. Self-hosted runner management
  2. Organization creation
  3. SCIM support, for platforms that cannot use a GitHub App for provisioning
  4. Enterprise team creation and management
  5. Budgeting and Licensing management
@glider-bot glider-bot added Copilot Enterprise Product SKU: Copilot Enterprise Copilot for Business Product SKU: Copilot for Business Enterprise Product SKU: GitHub Enterprise Public Preview labels Mar 21, 2025
@github github locked and limited conversation to collaborators Mar 21, 2025
@ankneis ankneis added preview Feature phase: Preview and removed Public Preview labels Apr 24, 2025
@ankneis ankneis changed the title Fine-grained PATs can access Enterprise APIs [Public Preview] Fine-grained PATs can access Enterprise APIs [Preview] Apr 24, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Copilot Enterprise Product SKU: Copilot Enterprise Copilot for Business Product SKU: Copilot for Business Enterprise Product SKU: GitHub Enterprise preview Feature phase: Preview
Projects
Status: Future
Development

No branches or pull requests

2 participants