> For the complete documentation index, see [llms.txt](https://docs.stepsecurity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.stepsecurity.io/github/apps-and-pats.md).

# Apps & PATs

{% hint style="warning" %}
**Available for Enterprise Tier Only**
{% endhint %}

{% hint style="info" %}
**GitHub Enterprise Server:** the Apps & PATs page is available for organizations on GitHub Enterprise Server. **GitHub Apps** and **Fine-Grained PATs** are collected automatically. **Classic PATs** are collected once a site administrator's token is connected; see Classic PATs on GitHub Enterprise Server.
{% endhint %}

The Apps & PATs page provides visibility into all GitHub Apps and Personal Access Tokens (PATs) that have access to your GitHub organization.

This view helps security and platform teams understand which integrations and tokens exist, what permissions they have, and where they are used across the organization.

#### Refreshing Apps & PATs Data

The Apps & PATs page shows the data collected during the most recent scan of your organization. The **Last refreshed** timestamp at the top of the page indicates when this data was last updated.

To re-scan your organization on demand, click **Refresh** in the top-right corner. This triggers a background operation that re-scans all GitHub Apps, Fine-Grained PATs, and Classic PATs and updates the page with the latest state. On GitHub Enterprise Server, Classic PATs are included once a site-admin token is connected.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FGIpkFodz9MddwpLsS1RC%2FScreenshot%202026-09-29%20at%2015.27.26.png?alt=media&amp;token=ebc533b6-de90-41b8-b44b-d38c5ceacfae" alt=""><figcaption></figcaption></figure>

{% hint style="warning" %}
Refreshing consumes a GitHub App installation token, which is rate-limited by GitHub. Avoid refreshing repeatedly in a short period, as excessive refreshes can exhaust the available installation tokens for your organization.
{% endhint %}

When you click **Refresh**, a confirmation dialog appears so you can avoid triggering a scan unintentionally. Select **Refresh** to continue, or **Cancel** to dismiss the dialog without re-scanning.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2F4Y71mt3YTL5MubGF7Vlh%2FScreenshot%202026-09-29%20at%2015.29.11.png?alt=media&amp;token=ffde4275-9ea4-4f96-87af-1c690e4a4691" alt=""><figcaption></figcaption></figure>

### Why Reviewing Apps & PATs Matters

GitHub Apps and Personal Access Tokens are commonly used to power CI/CD workflows, automation, and third-party integrations. Over time, organizations often accumulate:

* Apps with broad or outdated permissions
* Tokens that are long-lived or rarely reviewed
* Access owned by users or service accounts that no longer require it

These identities can introduce supply chain and CI/CD risk if they are over-privileged, unused, or poorly maintained. The Apps & PATs page helps teams continuously review and reduce this risk by making identity and access visibility easy and actionable.

### GitHub Apps

The GitHub Apps tab shows all third-party apps installed in the organization.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2F0zHBzxxhxqSrPcQ2vbfa%2FScreenshot%202026-09-29%20at%2015.27.26.png?alt=media&amp;token=242310b0-0e42-4fbe-8231-f8ba60e7dae2" alt=""><figcaption></figcaption></figure>

For each app, StepSecurity displays:

* App name and App ID
* Granted permissions grouped by scope(red for admin, orange for write, blue for read operations)
* Installation scope:
  * All repositories
  * Selected repositories
* GitHub events the app can receive, such as workflow\_run or workflow\_job
* Installation timestamp
* Current status

### Fine-Grained PATs

The Fine-Grained PATs section displays all fine-grained personal access tokens that have access to organization resources.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FAHwT9CLSDOwlvTEreTla%2FScreenshot%202026-09-29%20at%2015.30.33.png?alt=media&amp;token=c7682281-0210-4b3b-9a48-e8951802a0a5" alt=""><figcaption></figcaption></figure>

For each token, StepSecurity shows:

* Owner
* Token ID
* Granted permissions
* Repository access scope:
  * All repositories
  * Selected repositories
* Creation time
* Expiration time
* Last used timestamp
* Current status

This view helps teams understand which fine-grained tokens exist, who owns them, and how broadly they are scoped.

### Classic PATs

The Classic PATs section shows classic personal access tokens that have access to the organization:

* **GitHub Cloud:** classic PATs authorized for the organization via SAML/SSO are collected automatically.
* **GitHub Enterprise Server:** classic PATs belonging to the organization's members and outside collaborators are collected after you connect a site-admin token. See Classic PATs on GitHub Enterprise Server.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FPijPeir2FSCQehmNXgT6%2FScreenshot%202026-09-29%20at%2015.31.05.png?alt=media&amp;token=8043b09c-422e-464a-be02-1d50dbf9b1ae" alt=""><figcaption></figcaption></figure>

For each token, StepSecurity displays:

* Owner
* Credential ID
* Token identifier (last 8 characters)
* Authorized scopes
* Authorization timestamp

Classic PATs do not support fine-grained permissions and are often long-lived. Visibility into these tokens is critical for reducing organization-wide risk.

#### **Classic PATs on GitHub Enterprise Server**

GitHub Enterprise Server has no organization API for classic personal access tokens. StepSecurity lists them instance-wide using a site administrator's token, then keeps only the tokens that belong to the organization's members and outside collaborators. One token serves every organization on the instance.

Until a token is connected, the **Classic PATs** tab for a GitHub Enterprise Server organization shows a **Connect a site-admin token to inventory classic PATs** panel.

To connect a token:

1. Use a dedicated service account that is a site administrator on your GitHub Enterprise Server instance (**Site admin** > **Users** > **Promote to site admin**), not a personal account.
2. Signed in as that account, go to **Settings** > **Developer settings** > **Personal access tokens (classic)** > **Generate new token**. Select only the `site_admin` scope, set an expiration, and copy the token value. The `site_admin` scope covers both the listing and the deletion calls StepSecurity makes; GitHub does not offer a read-only variant.
3. In StepSecurity, open **Apps & PATs** > **Classic PATs**, paste the token into the **Site-admin token** field, and click **Connect**.

StepSecurity verifies the token with a single listing call, then stores it encrypted. The token is decrypted only for the hourly listing and for a revoke, and is never logged or shown again.

Once connected, a banner at the top of the tab shows when the token was last updated and by whom. Use **Rotate** to replace the token (for example before it expires) or **Remove** to disconnect it.

{% hint style="warning" %}
Revoking a classic PAT on GitHub Enterprise Server deletes the token for the whole instance, not only for this organization.
{% endhint %}

### Exemptions

The **Exemptions** tab lists tokens that are exempted from your PAT Governance policy. While an exemption is in force, the token is skipped by policy checks, pre-expiry reminders, and automated revocation. When the exemption expires, the token re-enrolls in the policy automatically.

Exemptions recorded by ServiceNow or through the StepSecurity API appear on this tab alongside exemptions added in the console.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2F35Nhxr0QcJpovCXHoQz9%2FScreenshot%202026-09-29%20at%2015.32.38.png?alt=media&amp;token=f28e3325-1775-438d-8970-ac2a8a0443c1" alt=""><figcaption></figcaption></figure>

For each exemption, StepSecurity shows:

* **Applies to**: the token (class and token ID or last characters) or user the exemption covers, and the token owner
* **Scope**: whether the exemption covers a single token or all tokens of a user
* **Expires (GMT)**: when the exemption ends and the token re-enrolls
* **Source**: where the exemption was recorded, such as **Console** or **ServiceNow** (with the ServiceNow request number)
* **Reason**: the reason entered for the audit trail, if any
* **Added by**: who added the exemption, and when

To end an exemption early, click the delete icon on its row.

#### **Add an exemption**

* On the **Exemptions** tab, click **Add exemption**.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2Fu3FB6CIYj5EMg70pebT6%2FScreenshot%202026-09-29%20at%2015.32.51.png?alt=media&amp;token=6d9129d9-4f9e-4fd0-8984-58606947d5bb" alt=""><figcaption></figcaption></figure>

* Choose a **Scope**:
  * **One token**: exempt a single token. Select the **Token type**, then identify the token:
    * **Fine-grained**: enter the **Token ID** shown on the **Fine-Grained PATs** tab.
    * **Classic**: enter the **Token suffix**, the final 8 characters of the classic token.
    * Optionally enter a **User login** (the GitHub login of the token owner). When set, the exemption applies only if the token belongs to that user.
  * **All tokens of a user**: exempt every token a user holds, including tokens they create later. Enter the user's GitHub **User login**.
* Select a **Duration**. The default is 30 days.
* Optionally enter a **Reason**. It is recorded for the audit trail.
* Click **Save exemption**.

The exemption applies from the next scan.

#### **Exempt a token from its row**

You can also exempt a token directly from the **Classic PATs** tab:

* Click the three-dot menu on the token's row and select **Exempt from policy**.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2FmvNnVJ9XLLxwpz7fBbDE%2FScreenshot%202026-09-29%20at%2015.35.45.png?alt=media&amp;token=7d35c00a-179a-42d8-a46d-68a94653f180" alt=""><figcaption></figcaption></figure>

* In the **Exempt token from the PAT policy?** dialog, select a **Duration** and optionally enter a **Reason**.

<figure><img src="https://754495266-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FQJRZY4cfEeY3I7DXTOCp%2Fuploads%2Faf0s7E3UB4Zm68H7abTc%2FScreenshot%202026-09-29%20at%2015.35.58.png?alt=media&amp;token=5301fe64-7951-47b6-adf3-8eba3e3616ea" alt=""><figcaption></figcaption></figure>

* Click **Exempt**.

Exempted tokens show an **Exempted** badge in the **Status** column. The exemption is listed on the **Exemptions** tab, where you can remove it early.

### Permission Scope Color Coding

To make permission reviews faster and more intuitive, StepSecurity uses color coding to highlight the risk level of GitHub App permissions:

* Red indicates administrative permissions. Permissions that allow access to organization-level or high-impact administrative operations.
* Yellow indicates write permissions. Permissions that allow modification of resources such as repositories, workflows, or Actions.
* Blue indicates read-only permissions. Permissions that allow viewing metadata or resources without making changes.

This visual distinction helps teams quickly identify apps with elevated privileges without inspecting each permission individually.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.stepsecurity.io/github/apps-and-pats.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
