---
title: "Create an impersonation OAuth token"
method: POST
path: "/admin/users/{username}/authorizations"
tags: ["enterprise-admin"]
---

# Create an impersonation OAuth token

`POST /admin/users/{username}/authorizations`

## Path parameters

- `username` string, required

## Request body

- object
  - `scopes` string[], required — A list of [scopes](https://docs.github.com/enterprise-server@3.7/apps/building-oauth-apps/understanding-scopes-for-oauth-apps/).

## Response `200`

Response when getting an existing impersonation OAuth token

- Authorization — The authorization for an OAuth app, GitHub App, or a Personal Access Token.
  - `id` integer, required
  - `url` string, uri, required
  - `scopes` string[], nullable, required — A list of scopes that this authorization is in.
  - `token` string, required
  - `token_last_eight` string, nullable, required
  - `hashed_token` string, nullable, required
  - `app` object, required
    - `client_id` string, required
    - `name` string, required
    - `url` string, uri, required
  - `note` string, nullable, required
  - `note_url` string, uri, nullable, required
  - `updated_at` string, date-time, required
  - `created_at` string, date-time, required
  - `fingerprint` string, nullable, required
  - `user` NullableSimpleUser, nullable — A GitHub user.
    - `name` string, nullable
    - `email` string, nullable
    - `login` string, required
    - `id` integer, required
    - `node_id` string, required
    - `avatar_url` string, uri, required
    - `gravatar_id` string, nullable, required
    - `url` string, uri, required
    - `html_url` string, uri, required
    - `followers_url` string, uri, required
    - `following_url` string, required
    - `gists_url` string, required
    - `starred_url` string, required
    - `subscriptions_url` string, uri, required
    - `organizations_url` string, uri, required
    - `repos_url` string, uri, required
    - `events_url` string, required
    - `received_events_url` string, uri, required
    - `type` string, required
    - `site_admin` boolean, required
    - `starred_at` string
  - `installation` NullableScopedInstallation, nullable
    - `permissions` AppPermissions, required — The permissions granted to the user access token.
      - `actions` 'read' | 'write' — The level of permission to grant the access token for GitHub Actions workflows, workflow runs, and artifacts.
      - `administration` 'read' | 'write' — The level of permission to grant the access token for repository creation, deletion, settings, teams, and collaborators creation.
      - `checks` 'read' | 'write' — The level of permission to grant the access token for checks on code.
      - `codespaces` 'read' | 'write' — The level of permission to grant the access token to create, edit, delete, and list Codespaces.
      - `contents` 'read' | 'write' — The level of permission to grant the access token for repository contents, commits, branches, downloads, releases, and merges.
      - `dependabot_secrets` 'read' | 'write' — The leve of permission to grant the access token to manage Dependabot secrets.
      - `deployments` 'read' | 'write' — The level of permission to grant the access token for deployments and deployment statuses.
      - `environments` 'read' | 'write' — The level of permission to grant the access token for managing repository environments.
      - `issues` 'read' | 'write' — The level of permission to grant the access token for issues and related comments, assignees, labels, and milestones.
      - `metadata` 'read' | 'write' — The level of permission to grant the access token to search repositories, list collaborators, and access repository metadata.
      - `packages` 'read' | 'write' — The level of permission to grant the access token for packages published to GitHub Packages.
      - `pages` 'read' | 'write' — The level of permission to grant the access token to retrieve Pages statuses, configuration, and builds, as well as create new builds.
      - `pull_requests` 'read' | 'write' — The level of permission to grant the access token for pull requests and related comments, assignees, labels, milestones, and merges.
      - `repository_hooks` 'read' | 'write' — The level of permission to grant the access token to manage the post-receive hooks for a repository.
      - `repository_projects` 'read' | 'write' | 'admin' — The level of permission to grant the access token to manage repository projects, columns, and cards.
      - `secret_scanning_alerts` 'read' | 'write' — The level of permission to grant the access token to view and manage secret scanning alerts.
      - `secrets` 'read' | 'write' — The level of permission to grant the access token to manage repository secrets.
      - `security_events` 'read' | 'write' — The level of permission to grant the access token to view and manage security events like code scanning alerts.
      - `single_file` 'read' | 'write' — The level of permission to grant the access token to manage just a single file.
      - `statuses` 'read' | 'write' — The level of permission to grant the access token for commit statuses.
      - `vulnerability_alerts` 'read' | 'write' — The level of permission to grant the access token to manage Dependabot alerts.
      - `workflows` 'write' — The level of permission to grant the access token to update GitHub Actions workflow files.
      - `members` 'read' | 'write' — The level of permission to grant the access token for organization teams and members.
      - `organization_administration` 'read' | 'write' — The level of permission to grant the access token to manage access to an organization.
      - `organization_copilot_seat_management` 'write' — The level of permission to grant the access token for managing access to GitHub Copilot for members of an organization with a Copilot Business subscription. This property is in beta and is subject to change.
      - `organization_events` 'read' — The level of permission to grant the access token to view events triggered by an activity in an organization.
      - `organization_hooks` 'read' | 'write' — The level of permission to grant the access token to manage the post-receive hooks for an organization.
      - `organization_personal_access_tokens` 'read' | 'write' — The level of permission to grant the access token for viewing and managing fine-grained personal access token requests to an organization.
      - `organization_personal_access_token_requests` 'read' | 'write' — The level of permission to grant the access token for viewing and managing fine-grained personal access tokens that have been approved by an organization.
      - `organization_plan` 'read' — The level of permission to grant the access token for viewing an organization's plan.
      - `organization_projects` 'read' | 'write' | 'admin' — The level of permission to grant the access token to manage organization projects and projects beta (where available).
      - `organization_packages` 'read' | 'write' — The level of permission to grant the access token for organization packages published to GitHub Packages.
      - `organization_secrets` 'read' | 'write' — The level of permission to grant the access token to manage organization secrets.
      - `organization_self_hosted_runners` 'read' | 'write' — The level of permission to grant the access token to view and manage GitHub Actions self-hosted runners available to an organization.
      - `organization_user_blocking` 'read' | 'write' — The level of permission to grant the access token to view and manage users blocked by the organization.
      - `team_discussions` 'read' | 'write' — The level of permission to grant the access token to manage team discussions and related comments.
      - `email_addresses` 'read' | 'write' — The level of permission to grant the access token to manage the email addresses belonging to a user.
      - `followers` 'read' | 'write' — The level of permission to grant the access token to manage the followers belonging to a user.
      - `git_ssh_keys` 'read' | 'write' — The level of permission to grant the access token to manage git SSH keys.
      - `gpg_keys` 'read' | 'write' — The level of permission to grant the access token to view and manage GPG keys belonging to a user.
      - `interaction_limits` 'read' | 'write' — The level of permission to grant the access token to view and manage interaction limits on a repository.
      - `profile` 'write' — The level of permission to grant the access token to manage the profile settings belonging to a user.
      - `starring` 'read' | 'write' — The level of permission to grant the access token to list and manage repositories a user is starring.
    - `repository_selection` 'all' | 'selected', required — Describe whether all repositories have been selected or there's a selection involved
    - `single_file_name` string, nullable, required
    - `has_multiple_single_files` boolean
    - `single_file_paths` string[]
    - `repositories_url` string, uri, required
    - `account` SimpleUser, required — A GitHub user.
      - `name` string, nullable
      - `email` string, nullable
      - `login` string, required
      - `id` integer, required
      - `node_id` string, required
      - `avatar_url` string, uri, required
      - `gravatar_id` string, nullable, required
      - `url` string, uri, required
      - `html_url` string, uri, required
      - `followers_url` string, uri, required
      - `following_url` string, required
      - `gists_url` string, required
      - `starred_url` string, required
      - `subscriptions_url` string, uri, required
      - `organizations_url` string, uri, required
      - `repos_url` string, uri, required
      - `events_url` string, required
      - `received_events_url` string, uri, required
      - `type` string, required
      - `site_admin` boolean, required
      - `starred_at` string
  - `expires_at` string, date-time, nullable, required

## Other responses

- `201` — Response when creating a new impersonation OAuth token

---

[API](https://skmtc.net/github/apis/github-v3-rest-api-6.md) · [All operations](https://skmtc.net/github/apis/github-v3-rest-api-6/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/github/github-v3-rest-api-6/versions/15db3fa0759b/schema)
