Skip to main content
GitHub versus GitHub Enterprise: which integration should I use? Follow the instructions on this page if your organization accesses GitHub at a custom domain.If you access GitHub at github.com, go to the GitHub integration.

Capabilities

The GitHub Enterprise connector supports automatic account provisioning and deprovisioning. New accounts will send an invitation to the account owner; if an invitation is pending, the account status will be shown as Pending. * Due to limitations on the GitHub API, syncing multiple orgs requires a personal access token (PAT). A separate connector and GitHub app is required when using the GitHub App integration. ** Organization roles are also referred to as “enterprise licenses” in GitHub’s documentation. *** Only synced when Sync user last activity is enabled. See Sync member last activity below. This connector can sync secrets and display them on the Inventory page.
Syncing the Licenses resource type only works with a personal access token (classic). GitHub App installation tokens are not supported for license sync.

Gather GitHub Enterprise credentials

Configuring the connector requires you to pass in credentials generated in GitHub Enterprise. Gather these credentials before you move on. To set up the GitHub Enterprise connector, you can choose to create either a personal access token (classic) or a fine-grained access token.

Option 1: Use a personal access token (classic)

Follow these instructions to integrate your GitHub Enterprise instance by using a GitHub Enterprise personal access token (classic).
A user with Enterprise Owner access in GitHub Enterprise must perform this task.
If you’re using SAML single sign-on, avoid a You must grant your Personal Access token access to this organization error by following the Authorizing a personal access token for use with SAML single sign-on instructions in the GitHub documentation.
1
In GitHub Enterprise, click your profile photo, then click Settings.
2
In the left sidebar, select Developer settings.
3
Click Personal access tokens > Tokens (classic).
4
Click Generate new token > Generate new token (classic).
5
Name your token (for example, C1 Integration). Optionally, add a token expiration date.
6
Select the following Scopes:
  • repo - select all
  • admin:org - select all if using C1 for GitHub Enterprise provisioning (see the note below), or read:org
  • user - select all
  • admin:enterprise - select read:enterprise
The write::org scope is used by C1 when automatically provisioning and deprovisioning GitHub Enterprise access on your behalf. If you do not want C1 to perform these tasks for you, do not give your token this scope.
7
Click Generate token. Copy and save the new token.
If you use SAML SSO, you must authorize the PAT using these instructions.
Done. Next, move on to the connector configuration instructions.

Option 2: Use a GitHub app

Follow these instructions to integrate your GitHub instance by using a GitHub app. This process creates a GitHub app that is only available to your GitHub organization, then generates an installation token for that app, which can be used to integrate the GitHub organization with C1. This creates the equivalent of a personal access token, but does not tie the token to a specific identity.
Integrating multiple GitHub organizations requires separate GitHub Apps and connectors. GitHub Enterprise APIs do not support GitHub App tokens and require classic PATs with the admin:enterprise scope.
A user with the Org Owner permission in the GitHub organization to be integrated with C1 must perform this task.
1
In GitHub, navigate to Your organizations > Settings.
2
In the left sidebar, select Developer settings.
3
Click GitHub Apps.
4
Click New GitHub App.
5
Give the app a globally unique name, such as “c1-integration-<org name>”. There is a 34 character limit.
6
In the Homepage URL field, enter a placeholder URL such as http://example.com. Because this app is not public, it does not have or need a website to direct other users to, so we can use a placeholder URL.
7
In the Callback URL field, enter a placeholder URL such as http://example.com. This app will not use a callback, so we can use a placeholder URL.
8
Check the Expire user authorization tokens and Enable Device Flow checkboxes to enable these settings.
9
In the Webhook section of the page, uncheck the Active checkbox to disable this setting.
10
In the Permissions section of the page, give the app the following permissions:
  • Repository permissions:
    • Administration: Read and write access
    • Metadata: Read-only access
  • Organization permissions:
    • Administration: Read-only access (required to detect SAML/SSO configuration)
    • Custom organization roles: Read and write access
    • Members: Read and write access
  • Enterprise permissions:
    • Custom enterprise roles: Read-only access
    • Enterprise custom properties for organizations: Read-only access
For details, see the GitHub docs on Permissions required for GitHub Apps.
11
In the Where can this app be installed? section of the page, choose Only on this account. This limits the app’s scope to the GitHub Enterprise organization you’ve set it up on.
12
Click Create GitHub App. The app is created.
13
On the app’s details page, carefully copy and save the App ID.
14
Scroll down to the Private keys section of the app’s page and click Generate a private key.
15
Carefully save the private key file.
16
Finally, install the new app on your GitHub organization. Navigate to Developer Settings > GitHub Apps.
17
Find your app and click Edit > Install App.
18
Click Install next to the GitHub organization where you want to install the app.
19
Select the repositories the app can act on.
20
Click Install.
Done. Next, move on to the connector configuration instructions.

Configure the GitHub Enterprise connector

To complete this task, you’ll need:
  • The Connector Administrator or Super Administrator role in C1
  • Access to the set of GitHub Enterprise credentials generated by following the instructions above
Follow these instructions to use a built-in, no-code connector hosted by C1.
1
In C1, navigate to Apps > Connectors and click Add connector.
2
Search for GitHub Enterprise and click Add.
3
Choose where to add the connector: Create a new app, or Add to an existing app (then select the app).If you’re creating a new app, choose whether to link it to an application discovered from your identity provider: select Yes and pick the IdP application, or No to continue with just the connector.
4
Set the connector’s Name and, optionally, a Description.
5
Click the pencil icon next to Owners to choose who can configure and manage this connector.
6
Click Add. The connector is created and its configuration page opens.
7
Find the Settings area of the page and click Edit.
8
If you’re using a personal access token to set up the connector:
  1. Click Personal access token.
  2. In the Instance URL field, enter the URL of your GitHub Enterprise instance.
  3. Paste the token you generated into the Personal access token field.
  4. Optional. If you want to sync only specific organizations, enter the organizations’ names in the Organizations field. If you do not specify specific organizations, C1 will sync all organizations.
  5. Optional. If you want to sync roles for only some enterprises, add the names of the enterprises in the Enterprises to sync enterprise roles for field.
  6. Optional. If you do not want to include archived repos in syncs, click to enable Omit archived repositories.
  7. Optional. For large organizations, click to enable Optimize sync for large organizations. This reduces API calls by using grant expansion for team-based repo access and skipping per-team detail fetches.
  8. Optional. If you want to see when members were last active, click to enable Sync user last activity. See Sync member last activity for requirements and limitations.
9
If you’re using a GitHub app to set up the connector:
  1. Click GitHub app.
  2. In the Instance URL field, enter the URL of your GitHub Enterprise instance.
  3. Enter your app ID into the GitHub app ID field.
  4. Click Choose file and upload your private key file.
  5. In the Organization field, enter the name of the GitHub organization associated with the GitHub app. You must enter a single organization name in this field or the connector configuration will fail.
  6. Optional. If you want to sync roles for only some enterprises, add the names of the enterprises in the Enterprises to sync enterprise roles for field.
  7. Optional. If you do not want to include archived repos in syncs, click to enable Omit archived repositories.
  8. Optional. For large organizations, click to enable Optimize sync for large organizations. This reduces API calls by using grant expansion for team-based repo access and skipping per-team detail fetches.
  9. Optional. If you want to see when members were last active, click to enable Sync user last activity. See Sync member last activity for requirements and limitations.
10
Click Save.
11
The connector’s label changes to Syncing, followed by Connected. You can view the logs to ensure that information is syncing.
Done. Your GitHub Enterprise connector is now pulling access data into C1.

Sync member last activity

You can enable Sync user last activity to have C1 show, for each member, the most recent recorded action across all synced organizations (for example, changing an organization or repository setting, creating or deleting a repository, or adding someone to a team). This appears on the member’s profile in C1 alongside their other access details. Requirements:
  • Personal access token: the token must have the read:audit_log scope, and permission to view each organization’s audit log (typically an organization owner).
  • GitHub App: the app must have the Organization permissions > Administration: Read-only access permission. If you followed the GitHub App setup instructions above, this is already granted (it’s also required for SAML/SSO detection), so no extra permission needs to be added.
Enabling the config option alone is not enough. After you enable Sync user last activity (or set --sync-last-activity / BATON_SYNC_LAST_ACTIVITY=true) and save the connector, go to the connector’s Capabilities & configuration page in C1 and confirm the GitHub Activity resource type is enabled for sync — it will show up in the resource list as available, but disabled, until you manually enable it.
What “last activity” means: This is not necessarily a login timestamp. GitHub’s audit log only records actions members take, not every time someone signs in or browses the product. Because of this, C1 shows the most recent recorded action for a member, whatever that action was, as a best-effort signal of when they were last active. A member who only reads or browses without taking any recorded action won’t show a last-activity date, even if they use GitHub regularly. What is not counted: The organization audit log records administrative events, not content activity. Writing an issue or pull request comment and reviewing code are not recorded there, so neither produces a last-activity date. An organization whose members write and review code but administer nothing may therefore show no last-activity dates at all. To keep this fast on large organizations, raw Git operations (pushes, fetches, and clones done via git rather than the website or API) are not counted toward last activity — only web and API actions are. Combined with the point above, this means a member whose work is limited to writing and reviewing code won’t show a last-activity date, even though they’re actively using GitHub. If a member has never taken a recorded action, or if the connector can’t reach an organization’s audit log for any reason (for example, a missing scope or a plan without audit log access), C1 simply won’t show a last-activity date for that member — this does not affect the rest of the sync. Activity is delivered as an ongoing background feed rather than as part of each full sync, so it may take a little time after enabling this option before last-activity dates first appear, and dates update continuously afterward rather than only at sync time.

Troubleshooting

”Resource not accessible by integration” error

If you see this error during sync, it most commonly means the GitHub App is missing the Organization administration: Read-only permission. This permission is required because the connector queries GitHub’s GraphQL API to check whether your organization has SAML/SSO configured. GitHub restricts this data to apps with organization admin read access. Without it, the sync will fail. To fix: Go to your GitHub App settings, then navigate to Permissions > Organization permissions > Administration and set it to Read-only.