Credential ownership · Available on Enterprise Cloud
GitHub Enterprise adds credential inventory exports
Announced September 21, 2026. Sources checked September 28, 2026.
GitHub now offers a credential inventory through CSV export and a paginated API. It includes personal access tokens, app access and user SSH keys, with ownership and lifecycle fields where available. The export contains metadata, not token values.
Who it affects. Enterprise Cloud owners and people with the View enterprise credentials permission. GitHub App installations represent the ability to issue tokens, not every short-lived installation token. CSV rows can repeat a credential for each authorizing organization.
What remains uncertain. Enterprise Server support is announced for a future release without a version or date. An empty expiry field can mean unavailable or inapplicable data; it is not proof that a credential never expires. Inventory review and remediation remain separate tasks.
One next step. Ask the enterprise access owner to review an export, confirm who maintains each relevant credential, and assign follow-up for unknown expiry or ownership. Verify dependencies before changing access.
SSH authentication · Announced schedule
Check new RSA keys before October 14
Announced September 22, 2026. Sources checked September 28, 2026.
GitHub sets October 14, 2026 for the new RSA upload minimum, covering authentication and signing keys. It also schedules November 4 and December 9 brownouts for RSA/SHA-1 signatures and the diffie-hellman-group-exchange-sha256 key exchange.
Who it affects. Teams using Git over SSH on GitHub Cloud. HTTPS Git remotes are unaffected. Existing RSA keys can continue with clients that support RSA/SHA-2. The announcement places these restrictions in Enterprise Server 3.25 rather than applying the Cloud dates to every server.
What remains uncertain. The announcement lists January 13, 2026 for final removal, a date before its publication. We cannot confirm the intended final date and have not silently changed the year. The October milestone and two brownout dates are stated separately.
One next step. Have the repository or build-system owner check SSH client compatibility and new-key provisioning before October 14. GitHub recommends Ed25519 where supported; test any replacement before retiring a working key.
Related
Where to go next
Automation access: npm tokens, workflow policies, and an IoT TLS fix