GitHub
Connect GitHub with access review source using OAuth or a personal access token so the platform can list your organization’s members and roles.
The platform reads your organization’s members through GitHubRESTAPI so you can check who has access. Connect (OAuth) is the recommended method and does not require token management. A personal access token is also available if you prefer not to authorize an OAuth application.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- Member in the GitHub organization that you want to review becauseGitHubor a token can only read the organizations to which it belongs
- If your organization restricts OAuth App access (Settings > Third-party Access > OAuth app policy in the organization), a owner must approve the platform before it appears in the organization's selector
- For the Personal Access Token option: the option Organization slug, the part of
github.com/<organization>, which is requested by the Connect dialog because a token does not have a selector
Collected Fields
Section entitled “Collected Fields”| the platform field | GitHub field | Notes |
|---|---|---|
| Name | name |
Returns to login when the profile does not have a name set |
email |
GitHub keeps a private member’s email by default. the platform records what exposes the public profile and leaves it empty otherwise | |
| Role | role |
The role of the organization member, admin or member |
| Admin | role |
Showed as administrator when role is admin |
| Status | state |
Active when the member state is active. |
| MFA | filter=2fa_disabled |
Reading this requires the connected account to hold the role of the owner of the organization. the platform marks Unknown MFA for each member whenGitHub replies this request |
| Last login | Not supported | |
| External ID | id |
Stable ID used to track your account through reviews |
| Created at | created_at |
When the member’s GitHub account was created, not when he joined the organization |
Members whose type is Bot are registered as service accounts.
Connect GitHub
Section entitled “ConnectGitHub”Option A: Connect with GitHub (recommended)
Section entitled “Option A: Connect withGitHub(recommended)”- On the platform, go to Access Reviews > Sources > Add Source.
- Find GitHub and click Connect.
- Authorize the platform onGitHub. the platform requires
read:orgscope. - In the new source line, select the organization from Select organization dropdown.
If the dropdown shows GitHub returned no organizations, click Review the platform’s accessAsk an organization owner to approve the platform Organization Settings > Third-party Access > OAuth app policy, then reopen the dropdown.
Option B: Personal Access Token
Section “Option B: Personal Access Token”- InGitHub, signed as a member of the organization, go to Settings > Developer settings > Personal access tokens > Fine-grained tokens, and to create a targeted organization with Members organization permission set to Read-only. A classic token (Tokens (classic)) cu cea
read:orgscope also works. - Copy the token and store it securely.GitHubdisplays it only once.
- On the platform, go to Access Reviews > Sources > Add Source, find GitHubOpen Dropdown next to Connect, and click Connect with API Key.
- Enter the token, enter the Organization (the service in
github.com/<organization>) and click on Connect.
the platform names the source after your organizationGitHuband attracts its members to your campaigns.
Troubleshooting
Section “Troubleshooting”- The picker organization is empty. When an organization restricts third-party access to the OAuth app, GitHubo omits from ___ZBT_I18N_RUNTIME_BLOCK_194__ until a owner approves the platform. Review the platform’s access the source or ask a owner to approve the platform Organization Settings > Third-party Access > OAuth app policy.
- Token rejected or no members appear. Confirms that the token has the domain
read:org(classic) or Members: Read-only Fine-grain, and that it belongs to a member of the organization who has entered the Organization. - The MFA looks unknown to each member. Reading the two-factor status requires the connected account to hold the role of the owner of the organization. the platform returns to the unknown for the entire review whenGitHubresponses this request.
- Emails are empty. GitHub saves a private member’s email by default. the platform can’t read an email that the member has not made public.
- A pending invitation is missing. GitHub member endpointReturns only current members of the organization. the platform does not collect waiting invitations.