Skip to main content
StackOne must reach the instance over HTTPS with a certificate from a public certificate authority. If the instance is behind a firewall, allow inbound HTTPS from StackOne’s IP addresses.

Create a personal access token (classic)

Create the token on the GitHub Enterprise Server instance you are connecting. Any user’s token lists every user on the instance. To read an organization’s members and teams, use a member of that organization. For two-factor status, outside collaborators, rulesets and audit logs, use an organization owner.

1

Open Developer settings

Sign in to your GitHub Enterprise Server instance.

  • Click your profile photo in the upper-right corner, then click Settings
  • In the left sidebar, click Developer settings
2

Generate the token

Create a classic token.

  • In the left sidebar, under Personal access tokens, click Tokens (classic)
  • Select Generate new token, then click Generate new token (classic)
  • Enter a Note, for example StackOne
  • Choose an Expiration that fits your rotation policy
3

Select scopes for user access reviews

Enables actions: Check Organization Membership, Get Authenticated User, Get Organization, Get Organization Membership, Get Team, Get Unified Group, Get Unified Organization, Get Unified User, Get User, List Authenticated User Organization Memberships, List Authenticated User Organizations, List Collaborators, List Organization Audit Log, List Organization Members, List Organization Members With Two-Factor Status, List Outside Collaborators, List Team Members, List Team Repositories, List Teams, List Unified Groups, List Unified Organizations, List Unified Users, List User Organizations, List Users

Select these two scopes.

4

Add scopes for compliance checks

Enables actions: Add Collaborator, Add Team Member, Add Team Repository, Check Organization Membership, Create Deployment, Create Deployment Status, Create Git Reference, Create Issue, Create Issue Comment, Create Or Update File, Create Organization Repository, Create Pull Request, Create Pull Request Review, Create Pull Request Review Comment, Create Release, Create Team, Create User Repository, Delete Deployment, Delete File, Delete Git Reference, Delete Release, Delete Team, Fork Repository, Get Branch, Get Branch Protection, Get Branch Rules, Get Combined Status For Ref, Get Commit, Get Git Reference, Get Issue, Get Latest Release, Get Organization, Get Organization Membership, Get Organization Ruleset, Get Pull Request, Get Repository, Get Repository Content, Get Repository Ruleset, Get Team, List Authenticated User Organizations, List Authenticated User Repositories, List Branches, List Check Runs For Ref, List Code Scanning Alerts, List Collaborators, List Commits, List Dependabot Alerts, List Deployments, List Enterprise Audit Log, List Forks, List Issue Comments, List Issues, List Matching Git References, List Organization Audit Log, List Organization Branch Protection, List Organization Members, List Organization Members With Two-Factor Status, List Organization Repositories, List Organization Rulesets, List Outside Collaborators, List Pull Request Reviews, List Pull Requests, List Pull Requests For Commit, List Releases, List Repository Rulesets, List Repository Teams, List Secret Scanning Alerts, List Team Members, List Team Repositories, List Teams, List User Organizations, Merge Pull Request, Remove Collaborator, Remove Organization Member, Remove Team Member, Search Code, Search Issues, Search Pull Requests With Reviews, Search Repositories, Star Repository, Trigger Workflow, Unstar Repository, Update Code Scanning Alert, Update Dependabot Alert, Update Git Reference, Update Issue, Update Organization, Update Pull Request, Update Release, Update Repository, Update Secret Scanning Alert, Update Team

admin:org adds the organization’s two-factor requirement and organization rulesets. repo reads private repositories, pull requests, reviews, branch protection and collaborators. admin:enterprise reads the enterprise audit log for an enterprise owner. The organization audit log needs only read:org.

5

Add scopes for other actions

Enables actions: Add Collaborator, Add Team Member, Add Team Repository, Cancel Workflow Run, Check Organization Membership, Create Deployment, Create Deployment Status, Create Git Reference, Create Issue, Create Issue Comment, Create Or Update File, Create Organization Repository, Create Pull Request, Create Pull Request Review, Create Pull Request Review Comment, Create Release, Create Team, Create User Repository, Create Webhook, Delete Deployment, Delete File, Delete Git Reference, Delete Release, Delete Repository, Delete Team, Delete Webhook, Download Artifact, Fork Repository, Get Authenticated User, Get Branch, Get Branch Protection, Get Branch Rules, Get Combined Status For Ref, Get Commit, Get Git Reference, Get Issue, Get Latest Release, Get Organization, Get Organization Membership, Get Organization Ruleset, Get Pull Request, Get Repository, Get Repository Content, Get Repository Ruleset, Get Team, Get Webhook, Get Workflow Run, List Artifacts, List Authenticated User Organizations, List Authenticated User Repositories, List Branches, List Check Runs For Ref, List Code Scanning Alerts, List Collaborators, List Commits, List Dependabot Alerts, List Deployments, List Enterprise Audit Log, List Forks, List Issue Comments, List Issues, List Matching Git References, List Organization Audit Log, List Organization Branch Protection, List Organization Members, List Organization Members With Two-Factor Status, List Organization Repositories, List Organization Rulesets, List Outside Collaborators, List Pull Request Reviews, List Pull Requests, List Pull Requests For Commit, List Releases, List Repository Rulesets, List Repository Teams, List Secret Scanning Alerts, List Team Members, List Team Repositories, List Teams, List User Organizations, List User Repositories, List Webhooks, List Workflow Jobs, List Workflow Runs, Merge Pull Request, Ping Webhook, Re-run Workflow, Remove Collaborator, Remove Organization Member, Remove Team Member, Search Code, Search Issues, Search Pull Requests With Reviews, Search Repositories, Star Repository, Trigger Workflow, Unstar Repository, Update Code Scanning Alert, Update Dependabot Alert, Update Git Reference, Update Issue, Update Organization, Update Pull Request, Update Release, Update Repository, Update Secret Scanning Alert, Update Team, Update User, Update Webhook

Add these only for the actions you plan to use.

6

Copy the token

Click Generate token and copy it. GitHub shows it only once.

Find your server URL

Use the address you open GitHub Enterprise Server at, such as https://github.example.com. Only the host name is used, so a path such as an organization page or /api/v3 is ignored. The connection always uses https://, even if you type http://.

Check the organization’s token policy

If an organization blocks classic tokens, its requests fail with 403. An organization owner can allow them in the organization’s Settings: under Personal access tokens, click Settings, open the Tokens (classic) tab, and under Restrict personal access tokens (classic) from accessing your organizations, select Allow access via personal access tokens. An enterprise policy can also block them for every organization.

Linking the Account from the Hub

1

Navigate to the Hub

Use one of the three Linking Account Methods to access the Hub.
2

Fill out the fields

Fill out the following fields using details from your provider:
  • GitHub Enterprise Server URL
  • Personal Access Token
  • Organization ID (Optional)
3

Connect

  • Click Connect
  • If applicable, the provider will redirect you to a sign-in or authorization page. Complete the provider’s authorization flow.
  • Once authorization is successful, you will see a confirmation popup

If the account linking is successful, you will see the newly linked account in your Accounts page.

Next Steps

Webhooks setup

Configure receiving Events for GitHub into StackOne.