What changed
GitHub added token-type-specific credential revocation on August 18, 2026. On September 21 it added a complementary enterprise credential inventory for GitHub Enterprise Cloud. Enterprise owners and members with the fine-grained `View enterprise credentials` permission can export or query credentials across the enterprise, including SSH keys, classic and fine-grained personal access tokens, OAuth App access tokens, and GitHub App user-to-server and installation tokens. The inventory includes owners, scopes/permissions, creation and expiration dates, last-used dates and target organizations or repositories, and can be correlated with audit-log activity. Together, the two changes let responders identify the exposed credential set before choosing a narrower revocation action.
Why it matters
Selective revocation is most useful when responders can quickly establish which credentials exist, who owns them and where they can reach. The new inventory closes that operational gap: security teams can build an enterprise-wide credential map before or during an incident, filter it by user, app, type or organization, and then use GitHub’s existing credential-class kill switches rather than defaulting to broad account disruption.
Enterprise owners can inventory the credential attack surface
GitHub Enterprise Cloud now exposes a complete credential inventory through CSV export and paginated REST API endpoints. GitHub says the inventory covers SSH keys, classic and fine-grained PATs, OAuth App access tokens, and GitHub App user-to-server and installation tokens.
The metadata is designed for incident triage
Inventory records include credential owner, scopes and permissions, creation and expiration dates, last-used dates, and target organizations or repositories. Teams can filter by user, app, credential type or organization and correlate the results with audit-log activity to identify credentials that plausibly participated in an incident.
Selective revocation remains the containment layer
GitHub’s August controls let responders revoke or deauthorize a specific credential class rather than every credential associated with a user. The September inventory makes that capability easier to use safely because teams can first determine the actual credential population and exposure.
Enterprise Server support is coming later
GitHub says the inventory is available now for GitHub Enterprise Cloud and will be supported in upcoming GitHub Enterprise Server releases. Self-hosted enterprises should not assume the new inventory API is available until their GHES release includes it.