The useful part
Key Takeaways GitHub Enterprise Cloud owners can now export an inventory of SSH keys, PATs, OAuth app tokens and GitHub App credentials with details including ownership, scopes, expiration and last use. The inventory can be downloaded as CSV or accessed through a REST API, allowing security teams to identify stale, long-lived or overly broad credentials and integrate reviews into existing security workflows. AI coding agents, CI bots and other non-human identities are increasing credential volumes, making continuous visibility and automated review increasingly important.
How it works
- Far fewer can tell you how many credentials those people, and the apps they've installed, hold against the company's source code.
- The export covers SSH keys, classic and fine-grained personal access tokens (PATs), OAuth app access tokens, and GitHub App user-to-server and installation tokens.
- GitHub says teams can correlate that data with audit logs to see how credentials are actually being used.
- Researchers noted that extensions like that can reach everything on a developer's machine, including SSH keys and cloud credentials.
- Every agent a team adds is another non-human identity with its own credentials, often created in a hurry and scoped broadly to get a pilot working.
What to take from it
GitGuardian's State of Secrets Sprawl 2026 report puts numbers on the problem. Which GitHub Apps hold installation tokens in organizations that no longer use them? As organizations deploy more non-human identities, the number of tokens can grow rapidly, increasing the risk of forgotten, overprivileged or long-lived credentials.
Example or evidence
- Instead of chasing individual org admins for lists, a platform or security team can pull one dataset and ask direct questions.
- "Anyone building with AI can now create credentials, and accountability for them lands back on IT and security," said Mitch Ashley, vice president and practice lead for CIO & technology buyers and software...
- On September 21, the company announced that GitHub Enterprise Cloud owners can now export a full inventory of every credential that can access their enterprise.
Details worth keeping
GitHub Gives Enterprises a Full Count of Who Holds the Keys. Most security teams can tell you how many people work in engineering. They can filter by user, app, credential type, or organization.
Related coverage
- Infosecurity Magazine: GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
- Omega8: Handing an outside developer your one and only SSH login because the job was one theme on one site is the oldest mistake in hosting, and the collaborator button on the big platforms only hides the question...