Open-Source AI

Enterprises can now install third-party GitHub Apps

Enterprises can now install third-party GitHub Apps

Enterprises can now install third-party GitHub Apps - GitHub Changelog

GitHub expanded enterprise GitHub App installations to cover third-party public apps created outside an enterprise, a shift announced on August 7, 2026, in the GitHub Changelog. Until now, enterprise owners could install apps built within their own enterprise or by organizations inside it, but external integrators had no supported path for enterprise-level deployments. That boundary is gone for public apps.

The change matters for companies that rely on specialized tools for identity provisioning, repository governance, or cross-organization automation. When an enterprise owner installs a third-party GitHub App at the enterprise level, the app receives only the enterprise permissions it requests. It does not automatically gain access to repositories or organizations within the enterprise, which preserves the existing isolation model. Enterprise-installed GitHub Apps are in public preview, so admins should treat the behavior as subject to change until general availability.

Security controls remain strict. Apps that request the Enterprise organization installations or Enterprise organization installation repositories permissions cannot be installed across enterprise boundaries. If an app already operates across multiple enterprises, it cannot add those permissions afterward. That safeguard prevents a single compromised app from fanning out across unrelated organizations.

Third-party developers also gained a new capability: any user or organization can now create GitHub Apps with enterprise permissions. Previously, only internal enterprise developers could build for that scope. External maintainers can now target enterprise management scenarios directly, provided they respect the cross-enterprise permission block.

The practical takeaway is a broader marketplace for enterprise automation. Organizations can evaluate external GitHub Apps for enterprise-wide tasks such as creating organizations, managing SCIM provisioning, or auditing app installations across teams. At the same time, enterprise owners should verify which permissions an app requests before installation, because enterprise-level access carries more blast radius than organization-level access.

For readers following platform policy shifts, this fits the pattern of opening closed ecosystems: Apple’s move to allow third-party app stores in Brazil showed regulatory pressure opening distribution, while GitHub’s move is a proactive API expansion for enterprise integrators.

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Aug 9, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.