Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To use a classic personal access token (PAT) or an SSH key with a GitHub organization that uses single sign-on (SSO), you authorize that credential for the organization from your own account settings. A classic PAT is authorized after you create it, under Developer settings. An SSH key is authorized under SSH and GPG keys. Authorization is set separately for each organization, and it only works once your external identity is linked to that organization, which happens when you sign in through the organization’s identity provider at least once.
Before you start: link your external identity
You cannot authorize a PAT or SSH key for an organization until your GitHub account has a linked external identity for it. GitHub’s documentation says you can create that link by authenticating to the organization through its identity provider at least once. Once a linked identity exists, GitHub requires authorized PATs and SSH keys for that organization, even if SSO is not enforced for every member.
Source: GitHub Docs: Authorizing a personal access token for use with single sign-on.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchAuthorize a classic personal access token
GitHub requires a classic PAT to be authorized after it is created. The steps below apply to the account settings layout described in GitHub’s Enterprise Cloud documentation reviewed in October 2026.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Sign in to the organization through its identity provider so your external identity is linked.
- Click your profile photo in the top-right corner and select Settings.
- In the left sidebar, select Developer settings, then Personal access tokens.
- Beside the token you want to use, select Configure SSO.
- In the organization list, select Authorize beside the organization that needs access.
Once authorization completes, the token can be used against that organization’s resources. Authorization is not transferred to a new token; each token must be authorized on its own.
Authorize an SSH key
SSH keys follow the same identity requirement, but the key lives in a different settings page. You can authorize a key you already have or generate a new one and authorize it.
- Sign in to the organization through its identity provider so your external identity is linked.
- Click your profile photo in the top-right corner and select Settings.
- In the Access section of the sidebar, select SSH and GPG keys.
- Beside the key, select Configure SSO.
- In the organization list, select Authorize beside the organization that needs access.
SSH certificates signed by an organization’s SSH certificate authority do not need this authorization. The per-key authorization applies only to keys you add to your account.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Source: GitHub Docs: Authorizing an SSH key for use with single sign-on.
How the two workflows differ
| Item | Classic personal access token | Fine-grained personal access token | SSH key |
|---|---|---|---|
| Where you authorize it | Settings, then Developer settings, then Personal access tokens, then Configure SSO | During the token creation flow | Settings, then SSH and GPG keys, then Configure SSO |
| When authorization happens | After the token is created | During creation | After the key exists (existing or newly generated) |
| Certificates signed by an organization CA | Not applicable | Not applicable | Do not need this authorization |
| If an organization revokes authorization | Not stated in the documentation reviewed | Not stated in the documentation reviewed | The same key cannot be reauthorized; create and authorize a new key |
The comparison covers authorization only. It does not compare the security of tokens and SSH keys in general.
Source: GitHub Docs: GitHub credential types reference.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
If Configure SSO does not appear
The button is missing in most cases for one of two reasons:
- No linked identity yet. GitHub’s instruction is to make sure you have authenticated at least once through the identity provider to access GitHub resources. Complete that sign-in and reload the settings page.
- An IP allow list at the enterprise level. If the organization belongs to an enterprise that has both enterprise-level SSO and an IP allow list enabled, your IP address must also be allowed at the enterprise level before authorization works.
Errors from an unauthorized classic token
A classic PAT that has not been authorized for a SAML-enforced organization can fail against the API. GitHub documents two possible responses:
- 404 Not Found or 403 Forbidden for a request to a single SAML-enforced organization.
- For a 403, the
X-GitHub-SSOresponse header can include a URL for authorizing the token. GitHub states that this URL expires after one hour, so generate a fresh request if it has lapsed.
When a request spans multiple organizations, the X-GitHub-SSO header can list the organizations that still need authorization, and the API may return partial results. Authorize the listed organizations and repeat the request.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Source: GitHub Docs: Authenticating to the REST API.
What can and cannot be automated
The documented authorization steps are account settings procedures performed in the GitHub interface. GitHub’s documentation describes a multi-organization GitHub App method intended for enterprise administrators. The documentation reviewed does not establish that an individual user can script or use the CLI to complete the per-token or per-key authorization. Do not write a personal script that assumes it can bypass the authorization step; plan for the one-time UI action for each credential and organization.
Free tools Windows power users keep installed
One-click scans. No signup required.
Revoking and recovering authorization
An authorization stays in place until one of the following happens:
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- An organization or enterprise owner revokes it.
- You are removed from the organization.
- The token is changed or expires.
If an organization revokes authorization for an SSH key, that key cannot be reauthorized. Generate a new SSH key, add it to your account, and authorize the new key.
On GitHub Enterprise Cloud, deleting a credential and revoking its SSO authorization are different actions. Revoking blocks that credential from the specific organization’s resources but does not delete the credential. GitHub’s credential reference states that SSO credential authorization does not apply to GitHub Enterprise Server.
Source: GitHub Docs: Authorizing a personal access token for use with single sign-on.
GitHub’s wording for the two requirements is direct. For PATs, GitHub Docs says: “To use a personal access token (classic) with an organization that uses single sign-on (SSO), you must first authorize the token.” For SSH keys, it says: “To use an SSH key with an organization that uses single sign-on (SSO), you must first authorize the key.”
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

