A coding helper, CI service or portfolio builder may retain GitHub access long after you stop using it. An OAuth app with broad repository scope can read more than the one project you first connected. GitHub provides separate lists for authorized OAuth apps and GitHub Apps, so reviewing only one tab misses grants. Removing an app may break an automation, but leaving an unknown app connected is a poor trade-off. Inventory first, then revoke deliberately.
Before you start
Sign into GitHub from a known browser. List integrations your projects genuinely need and identify a maintainer for work accounts. If an app belongs to an organization, check whether it is installed at organization level before changing it. Do not grant a new app access just to 'scan' old permissions.Do it step by step
- From your profile picture, open Settings, Applications and Authorized OAuth Apps. For each entry, read its name, permissions and accessible repositories. Note a legitimate workflow before revoking so you can restore it later if needed.
- Revoke an app you cannot recognize or no longer use with the control beside that app. GitHub says revoking authorization invalidates the associated OAuth tokens. Prefer one-app decisions over Revoke all when you need to preserve important automations.
- Return to Applications and inspect Authorized GitHub Apps, then any installed GitHub Apps you control. Look at repository selection and permissions, which can differ from OAuth scopes. Revoke or uninstall an unexpected integration using the appropriate owner controls.
- Review fine-grained and classic personal access tokens in Developer settings separately. A token you created for a script is not displayed as an authorized OAuth app. Revoke stale tokens and replace needed ones with a narrow repository selection and expiration.
- Review SSH keys and deploy keys too. App revocation does not automatically prove no other credential grants access. Match each key fingerprint or title to a current device or deployment before removal.
- Check your personal security log for authorization changes you did not initiate, then test the legitimate integrations you kept. If an app was unknown, rotate any secrets it could access and inspect affected repositories for unauthorized changes.