Skip to content

Connect GitHub to Black Cat SSPM

Version française

Connect your GitHub organization so Black Cat can review two-factor coverage, repository protection, secret scanning, Actions settings, webhooks and personal access tokens.

≈ 15 min · audit access · no write-capable permission

What Black Cat reads, and why

PermissionWhat it lets Black Cat doStatus
Organization: Administration (read)Lets Black Cat review organization settings such as two-factor enforcement, default permissions and repository creation rules.Required
Organization: Members (read)Lets Black Cat list members, their roles, two-factor status and last activity.Required
Repository: Administration (read)Lets Black Cat review repository visibility, branch protection, secret scanning and Dependabot settings.Required
Repository: Webhooks (read)Lets Black Cat review webhook destinations and whether they are sent over HTTPS.Required
Organization: Self-hosted runners (read)Lets Black Cat list self-hosted runners and which repositories may use them.Optional
Organization: Personal access tokens (read)Lets Black Cat see which personal access tokens reach your organization and what they can do.Optional

What you'll need

  • GitHub App identifier Required — Shown on the settings page of the GitHub App you create for Black Cat.
  • Installation identifier Required — Shown in the address bar after you install the app on your organization.
  • App private key (PEM) Required — Downloaded once from the GitHub App settings when you generate a key.
  • Server address — Optional — only needed for GitHub Enterprise Server.

Where to create it

What we check on GitHub →

Other setup guides

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications are based on publicly available documentation and may change over time.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default access you can revoke any time.

Run a free posture scan