github / github/roadmap

Arbitrary issuers and claims for federated credentials [GA]

Open
#1,288 0 comments 0 reactions 0 assignees View on GitHub
Copilot Enterprise Copilot for Business Enterprise Free Team
Dominant language
No language data
Stars
8.9k
Forks
1.8k
PR merge metrics
No merged PRs in 30d

Description

### Value Prop
You can now authenticate GitHub Apps using any compatible identity provider — including SPIFFE, Okta, GCP, AWS, Kubernetes clusters, and more — instead of managing private keys. Configure any issuer and claims that fit your infrastructure, and use federated credentials to mint installation tokens for your app's installations. This gives every team, regardless of their technology stack, a secure and flexible alternative to long-lived private keys.

### Expected Outcome
Developers and platform teams can eliminate the operational burden of storing, rotating, and securing GitHub App private keys by integrating directly with the identity providers already powering their infrastructure. By extending federated credential support to any compatible issuer, GitHub Apps fit naturally into modern zero-trust and cloud-native environments. The result is a more secure authentication model that reduces credential sprawl and scales with the diversity of real-world infrastructure setups.

Contributor guide

Open the contributing guide

Research direction

This roadmap entry does not identify repository files, tests, or implementation entry points to inspect first. Use the GitHub App federated-credential authentication area as the starting scope; the work is done when compatible arbitrary issuers and claims can mint installation tokens without private keys.

Written by the indexing model from the issue text.

Assessment

Tech stack
github
Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.