GitHub Enterprise
Connect GitHub Enterprise Cloud to vScope to inventory your enterprise’s member accounts, license consumption, and GitHub Copilot seats. GitHub Enterprise Server (self-hosted) is not supported.
Prerequisites
Section titled “Prerequisites”- A GitHub Enterprise Cloud account. You need to be, or have help from, an enterprise owner.
- A classic personal access token with the
read:enterprisescope (created in Create a personal access token). Fine-grained tokens and GitHub App tokens are not supported. - Your enterprise slug — the name in the URL when you visit your enterprise, for example
my-companyinhttps://github.com/enterprises/my-company. - Network access from the vScope server or Discovery Proxy to
https://api.github.comover HTTPS (port443).
Create a personal access token
Section titled “Create a personal access token”- Sign in to GitHub as an enterprise owner.
- Go to Settings > Developer settings > Personal access tokens > Tokens (classic).
- Click Generate new token > Generate new token (classic).
- Name the token, for example
vScope, and set an expiration according to your security policy. Renew the token before it expires and update the credential in vScope. - Under Select scopes, check
read:enterprise. - Click Generate token and copy the token (it starts with
ghp_).
Add the GitHub Enterprise credential in vScope
Section titled “Add the GitHub Enterprise credential in vScope”- In vScope, go to Discovery > Credentials.
- Click Create credential and choose GitHub Enterprise.
- In Enterprise Slug, enter your enterprise slug (for example
my-company). - In Personal Access Token, paste the token you copied (for example
ghp_...). Enter only the token. vScope adds theBearerprefix automatically. - Optional: add a Note to describe the credential.
- Optional: assign a Proxy if vScope should connect to GitHub through a Discovery Proxy.
- Click Test Credential.
- Save the credential and run discovery.
Troubleshooting
Section titled “Troubleshooting”Authentication fails
Section titled “Authentication fails”GitHub returns 401 Bad credentials when the token is wrong, expired, or revoked. Confirm that the Personal Access Token is a current, valid token (for example ghp_...) and that it has not expired.
Permission errors or partial inventory
Section titled “Permission errors or partial inventory”GitHub returns 403 or 404 when the token cannot read the enterprise, and the inventory can be incomplete when the token is missing access. Check that:
- The token was created by an enterprise owner.
- The token is a classic personal access token with the
read:enterprisescope. - The Enterprise Slug matches
https://github.com/enterprises/<slug>exactly. - The vScope server or Discovery Proxy can reach
https://api.github.comon HTTPS (port443).
Then run a new discovery.
Email addresses are missing
Section titled “Email addresses are missing”GitHub only exposes a member’s email address if your enterprise has verified its domains and the member has a matching verified email on their GitHub account. On enterprises with SAML or Enterprise Managed Users, the SAML identity is used as a fallback.
Verify your domain in the enterprise settings and make sure members add their work email to their GitHub account. Accounts without an email cannot be correlated with user accounts from other datasources.
Copilot fields are empty
Section titled “Copilot fields are empty”Copilot data requires an active GitHub Copilot Business or Copilot Enterprise subscription. Trial enterprises do not include Copilot. For missing Copilot Last Activity, confirm the member has IDE telemetry enabled.