Skip to content

GitHub Enterprise

Connect GitHub Enterprise Cloud to vScope to inventory your enterprise’s member accounts, license consumption, and GitHub Copilot seats. GitHub Enterprise Server (self-hosted) is not supported.

  • A GitHub Enterprise Cloud account. You need to be, or have help from, an enterprise owner.
  • A classic personal access token with the read:enterprise scope (created in Create a personal access token). Fine-grained tokens and GitHub App tokens are not supported.
  • Your enterprise slug — the name in the URL when you visit your enterprise, for example my-company in https://github.com/enterprises/my-company.
  • Network access from the vScope server or Discovery Proxy to https://api.github.com over HTTPS (port 443).
  1. Sign in to GitHub as an enterprise owner.
  2. Go to Settings > Developer settings > Personal access tokens > Tokens (classic).
  3. Click Generate new token > Generate new token (classic).
  4. Name the token, for example vScope, and set an expiration according to your security policy. Renew the token before it expires and update the credential in vScope.
  5. Under Select scopes, check read:enterprise.
  6. Click Generate token and copy the token (it starts with ghp_).

Add the GitHub Enterprise credential in vScope

Section titled “Add the GitHub Enterprise credential in vScope”
  1. In vScope, go to Discovery > Credentials.
  2. Click Create credential and choose GitHub Enterprise.
  3. In Enterprise Slug, enter your enterprise slug (for example my-company).
  4. In Personal Access Token, paste the token you copied (for example ghp_...). Enter only the token. vScope adds the Bearer prefix automatically.
  5. Optional: add a Note to describe the credential.
  6. Optional: assign a Proxy if vScope should connect to GitHub through a Discovery Proxy.
  7. Click Test Credential.
  8. Save the credential and run discovery.

GitHub returns 401 Bad credentials when the token is wrong, expired, or revoked. Confirm that the Personal Access Token is a current, valid token (for example ghp_...) and that it has not expired.

GitHub returns 403 or 404 when the token cannot read the enterprise, and the inventory can be incomplete when the token is missing access. Check that:

  1. The token was created by an enterprise owner.
  2. The token is a classic personal access token with the read:enterprise scope.
  3. The Enterprise Slug matches https://github.com/enterprises/<slug> exactly.
  4. The vScope server or Discovery Proxy can reach https://api.github.com on HTTPS (port 443).

Then run a new discovery.

GitHub only exposes a member’s email address if your enterprise has verified its domains and the member has a matching verified email on their GitHub account. On enterprises with SAML or Enterprise Managed Users, the SAML identity is used as a fallback.

Verify your domain in the enterprise settings and make sure members add their work email to their GitHub account. Accounts without an email cannot be correlated with user accounts from other datasources.

Copilot data requires an active GitHub Copilot Business or Copilot Enterprise subscription. Trial enterprises do not include Copilot. For missing Copilot Last Activity, confirm the member has IDE telemetry enabled.