GitHub Enterprise Cloud administrators may need to review external identity information via the GraphQL API. Historically, this has required a token with the admin:org
or admin:enterprise
scope. We've taken a "least privilege" mindset in reviewing this flow and have now made this information available via the read:enterprise
and read:org
scopes for enterprise owner and organization owner actors.
For more information, see the GraphQL API documentation for Enterprise and Organization SAMLIdentity
objects.