Resource icon

Audit GitHub apps that can read your private repositories

A coding helper, CI service or portfolio builder may retain GitHub access long after you stop using it. An OAuth app with broad repository scope can read more than the one project you first connected. GitHub provides separate lists for authorized OAuth apps and GitHub Apps, so reviewing only one tab misses grants. Removing an app may break an automation, but leaving an unknown app connected is a poor trade-off. Inventory first, then revoke deliberately.

Before you start​

Sign into GitHub from a known browser. List integrations your projects genuinely need and identify a maintainer for work accounts. If an app belongs to an organization, check whether it is installed at organization level before changing it. Do not grant a new app access just to 'scan' old permissions.

Do it step by step​

  1. From your profile picture, open Settings, Applications and Authorized OAuth Apps. For each entry, read its name, permissions and accessible repositories. Note a legitimate workflow before revoking so you can restore it later if needed.
  2. Revoke an app you cannot recognize or no longer use with the control beside that app. GitHub says revoking authorization invalidates the associated OAuth tokens. Prefer one-app decisions over Revoke all when you need to preserve important automations.
  3. Return to Applications and inspect Authorized GitHub Apps, then any installed GitHub Apps you control. Look at repository selection and permissions, which can differ from OAuth scopes. Revoke or uninstall an unexpected integration using the appropriate owner controls.
  4. Review fine-grained and classic personal access tokens in Developer settings separately. A token you created for a script is not displayed as an authorized OAuth app. Revoke stale tokens and replace needed ones with a narrow repository selection and expiration.
  5. Review SSH keys and deploy keys too. App revocation does not automatically prove no other credential grants access. Match each key fingerprint or title to a current device or deployment before removal.
  6. Check your personal security log for authorization changes you did not initiate, then test the legitimate integrations you kept. If an app was unknown, rotate any secrets it could access and inspect affected repositories for unauthorized changes.

Check the result​

The authorized app lists, personal tokens and keys have named owners and purposes, and a required automation still works with the smallest practical permission set. Unrecognized access is gone.

If something goes wrong​

If a revoked app breaks a workflow, reconnect it through its official vendor site and inspect the new grant before approval. If you lack organization permissions, ask its owner to inspect the installation. If a grant reappears, investigate the linked service or another administrator instead of repeatedly revoking it.

Know the limit​

Revoking app access stops future API use by that authorization but cannot retract data already copied. Some apps can create other resources or keys; inspect those separately. A GitHub App installation, OAuth authorization, personal token and SSH key are different access paths. GitHub authorized OAuth app review GitHub account access checklist GitHub token management
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack