Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To use a classic personal access token (PAT) or an SSH key with a GitHub organization that uses single sign-on (SSO), you authorize that credential for the organization from your own account settings. A classic PAT is authorized after you create it, under Developer settings. An SSH key is authorized under SSH and GPG keys. Authorization is set separately for each organization, and it only works once your external identity is linked to that organization, which happens when you sign in through the organization’s identity provider at least once.

Before you start: link your external identity

You cannot authorize a PAT or SSH key for an organization until your GitHub account has a linked external identity for it. GitHub’s documentation says you can create that link by authenticating to the organization through its identity provider at least once. Once a linked identity exists, GitHub requires authorized PATs and SSH keys for that organization, even if SSO is not enforced for every member.

Source: GitHub Docs: Authorizing a personal access token for use with single sign-on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Authorize a classic personal access token

GitHub requires a classic PAT to be authorized after it is created. The steps below apply to the account settings layout described in GitHub’s Enterprise Cloud documentation reviewed in October 2026.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Sign in to the organization through its identity provider so your external identity is linked.
  2. Click your profile photo in the top-right corner and select Settings.
  3. In the left sidebar, select Developer settings, then Personal access tokens.
  4. Beside the token you want to use, select Configure SSO.
  5. In the organization list, select Authorize beside the organization that needs access.

Once authorization completes, the token can be used against that organization’s resources. Authorization is not transferred to a new token; each token must be authorized on its own.

Authorize an SSH key

SSH keys follow the same identity requirement, but the key lives in a different settings page. You can authorize a key you already have or generate a new one and authorize it.

  1. Sign in to the organization through its identity provider so your external identity is linked.
  2. Click your profile photo in the top-right corner and select Settings.
  3. In the Access section of the sidebar, select SSH and GPG keys.
  4. Beside the key, select Configure SSO.
  5. In the organization list, select Authorize beside the organization that needs access.

SSH certificates signed by an organization’s SSH certificate authority do not need this authorization. The per-key authorization applies only to keys you add to your account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Source: GitHub Docs: Authorizing an SSH key for use with single sign-on.

How the two workflows differ

Item Classic personal access token Fine-grained personal access token SSH key
Where you authorize it Settings, then Developer settings, then Personal access tokens, then Configure SSO During the token creation flow Settings, then SSH and GPG keys, then Configure SSO
When authorization happens After the token is created During creation After the key exists (existing or newly generated)
Certificates signed by an organization CA Not applicable Not applicable Do not need this authorization
If an organization revokes authorization Not stated in the documentation reviewed Not stated in the documentation reviewed The same key cannot be reauthorized; create and authorize a new key

The comparison covers authorization only. It does not compare the security of tokens and SSH keys in general.

Source: GitHub Docs: GitHub credential types reference.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

If Configure SSO does not appear

The button is missing in most cases for one of two reasons:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • No linked identity yet. GitHub’s instruction is to make sure you have authenticated at least once through the identity provider to access GitHub resources. Complete that sign-in and reload the settings page.
  • An IP allow list at the enterprise level. If the organization belongs to an enterprise that has both enterprise-level SSO and an IP allow list enabled, your IP address must also be allowed at the enterprise level before authorization works.

Errors from an unauthorized classic token

A classic PAT that has not been authorized for a SAML-enforced organization can fail against the API. GitHub documents two possible responses:

  • 404 Not Found or 403 Forbidden for a request to a single SAML-enforced organization.
  • For a 403, the X-GitHub-SSO response header can include a URL for authorizing the token. GitHub states that this URL expires after one hour, so generate a fresh request if it has lapsed.

When a request spans multiple organizations, the X-GitHub-SSO header can list the organizations that still need authorization, and the API may return partial results. Authorize the listed organizations and repeat the request.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Source: GitHub Docs: Authenticating to the REST API.

What can and cannot be automated

The documented authorization steps are account settings procedures performed in the GitHub interface. GitHub’s documentation describes a multi-organization GitHub App method intended for enterprise administrators. The documentation reviewed does not establish that an individual user can script or use the CLI to complete the per-token or per-key authorization. Do not write a personal script that assumes it can bypass the authorization step; plan for the one-time UI action for each credential and organization.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Revoking and recovering authorization

An authorization stays in place until one of the following happens:

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • An organization or enterprise owner revokes it.
  • You are removed from the organization.
  • The token is changed or expires.

If an organization revokes authorization for an SSH key, that key cannot be reauthorized. Generate a new SSH key, add it to your account, and authorize the new key.

On GitHub Enterprise Cloud, deleting a credential and revoking its SSO authorization are different actions. Revoking blocks that credential from the specific organization’s resources but does not delete the credential. GitHub’s credential reference states that SSO credential authorization does not apply to GitHub Enterprise Server.

Source: GitHub Docs: Authorizing a personal access token for use with single sign-on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub’s wording for the two requirements is direct. For PATs, GitHub Docs says: “To use a personal access token (classic) with an organization that uses single sign-on (SSO), you must first authorize the token.” For SSH keys, it says: “To use an SSH key with an organization that uses single sign-on (SSO), you must first authorize the key.”

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.