> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-bp-2731-onprem-architecture.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure a Personal Access Token

> Create a Fine-grained Personal Access Token for GitHub data collection.

<img noZoom src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/cSg9r7u_qWc5sQQj/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=cSg9r7u_qWc5sQQj&q=85&s=332ab7c1e25fb10fd9f92afff92c688b" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

This page covers creating a Fine-grained Personal Access Token (PAT) for GitHub. PATs have a rate limit of **5,000 API requests per hour**.

<Tip>For higher rate limits, see [Configure a GitHub App Installation](/openhound/collectors/github/configure-app).</Tip>

## Create a Fine-grained Personal Access Token

<Steps>
  <Step title="Navigate to Personal Access Tokens">
    Navigate to your GitHub **Profile** > **Settings**.

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/1_proile_settings.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=cecf3a1fbb90490cf9798220430848b8" alt="GitHub profile settings menu" width="344" height="751" data-path="images/extensions/github/pat/1_proile_settings.png" />
    </Frame>
  </Step>

  <Step title="Open Developer Settings">
    Go to **Developer settings** (bottom left).

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/2_developer_settings.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=0b96a9773d8a40b48d0bb558a56662ee" alt="Developer settings in GitHub profile" width="1300" height="1163" data-path="images/extensions/github/pat/2_developer_settings.png" />
    </Frame>
  </Step>

  <Step title="Go to Fine-grained Tokens">
    Navigate to **Personal access tokens** > **Fine-grained tokens**.

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/3_fine-grained_tokens.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=63c2e2fc13db017dc6b851184ba97bc5" alt="Fine-grained tokens in Developer settings" width="1135" height="196" data-path="images/extensions/github/pat/3_fine-grained_tokens.png" />
    </Frame>
  </Step>

  <Step title="Generate a new token">
    Click **Generate new token**.

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/4_generate_token.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=f9ed190f8dc4ecffd5a078adbca9b61c" alt="Generate new fine-grained token page" width="1135" height="278" data-path="images/extensions/github/pat/4_generate_token.png" />
    </Frame>
  </Step>

  <Step title="Set resource owner">
    Set the **Resource owner** to your target organization.
  </Step>

  <Step title="Configure the access scope">
    Under **Repository access**, select **All repositories**.

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/5_all_repositories.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=c0d6d8f2390ce8d0135c8f5bc2eba785" alt="Select All repositories for token access" width="1135" height="763" data-path="images/extensions/github/pat/5_all_repositories.png" />
    </Frame>
  </Step>

  <Step title="Configure the repository and org permissions">
    Set the following permissions to **Read-only**:

    <Expandable title="required permissions">
      **Repository permissions**

      * Actions
      * Administration
      * Contents
      * Environments
      * Metadata
      * Secret scanning alerts
      * Secrets
      * Variables

      **Organization permissions**

      * Administration
      * Custom organization roles
      * Custom repository roles
      * Members
      * Personal access tokens
      * Personal access token requests
      * Secrets
      * Self-hosted runners
      * Variables
    </Expandable>
  </Step>

  <Step title="Generate the token">
    <Warning>You must save the token value (preferably in a password manager) at this point. You will not be able to recover it later.</Warning>

    Click **Generate token** and copy the token value.

    <Frame>
      <img src="https://mintcdn.com/specterops-bp-2731-onprem-architecture/OmgD6tg6Dsp0leSV/images/extensions/github/pat/7_save_pat.png?fit=max&auto=format&n=OmgD6tg6Dsp0leSV&q=85&s=2f73299feffb98a4b942f822dedaf961" alt="Copy the generated token" width="803" height="243" data-path="images/extensions/github/pat/7_save_pat.png" />
    </Frame>
  </Step>
</Steps>

<Tip>For organizations with SAML SSO enabled, you must [authorize the PAT for SSO access](https://docs.github.com/en/enterprise-cloud@latest/authentication/authenticating-with-saml-single-sign-on/authorizing-a-personal-access-token-for-use-with-saml-single-sign-on) after creating it.</Tip>

## Next Steps

After creating a token, proceed to [configure the collector](/openhound/collectors/github/collect-data) to start collection.
