For the complete documentation index, see llms.txt. This page is also available as Markdown.

Apps & PATs

The Apps & PATs page provides visibility into all GitHub Apps and Personal Access Tokens (PATs) that have access to your GitHub organization.

This view helps security and platform teams understand which integrations and tokens exist, what permissions they have, and where they are used across the organization.

Refreshing Apps & PATs Data

The Apps & PATs page shows the data collected during the most recent scan of your organization. The Last refreshed timestamp at the top of the page indicates when this data was last updated.

To re-scan your organization on demand, click Refresh in the top-right corner. This triggers a background operation that re-scans all GitHub Apps, Fine-Grained PATs, and Classic PATs and updates the page with the latest state.

When you click Refresh, a confirmation dialog appears so you can avoid triggering a scan unintentionally. Select Refresh to continue, or Cancel to dismiss the dialog without re-scanning.

Why Reviewing Apps & PATs Matters

GitHub Apps and Personal Access Tokens are commonly used to power CI/CD workflows, automation, and third-party integrations. Over time, organizations often accumulate:

  • Apps with broad or outdated permissions

  • Tokens that are long-lived or rarely reviewed

  • Access owned by users or service accounts that no longer require it

These identities can introduce supply chain and CI/CD risk if they are over-privileged, unused, or poorly maintained. The Apps & PATs page helps teams continuously review and reduce this risk by making identity and access visibility easy and actionable.

GitHub Apps

The GitHub Apps tab shows all third-party apps installed in the organization.

For each app, StepSecurity displays:

  • App name and App ID

  • Granted permissions grouped by scope(red for admin, orange for write, blue for read operations)

  • Installation scope:

    • All repositories

    • Selected repositories

  • GitHub events the app can receive, such as workflow_run or workflow_job

  • Installation timestamp

  • Current status

Fine-Grained PATs

The Fine-Grained PATs section displays all fine-grained personal access tokens that have access to organization resources.

For each token, StepSecurity shows:

  • Owner

  • Token ID

  • Granted permissions

  • Repository access scope:

    • All repositories

    • Selected repositories

  • Creation time

  • Expiration time

  • Last used timestamp

  • Current status

This view helps teams understand which fine-grained tokens exist, who owns them, and how broadly they are scoped.

Classic PATs

The Classic PATs section shows classic personal access tokens that are authorized for the organization via SAML/SSO.

For each token, StepSecurity displays:

  • Owner

  • Credential ID

  • Token identifier (last 8 characters)

  • Authorized scopes

  • Authorization timestamp

Classic PATs do not support fine-grained permissions and are often long-lived. Visibility into these tokens is critical for reducing organization-wide risk.

Permission Scope Color Coding

To make permission reviews faster and more intuitive, StepSecurity uses color coding to highlight the risk level of GitHub App permissions:

  • Red indicates administrative permissions. Permissions that allow access to organization-level or high-impact administrative operations.

  • Yellow indicates write permissions. Permissions that allow modification of resources such as repositories, workflows, or Actions.

  • Blue indicates read-only permissions. Permissions that allow viewing metadata or resources without making changes.

This visual distinction helps teams quickly identify apps with elevated privileges without inspecting each permission individually.

Last updated

Was this helpful?