# GitHub OAuth allowed\_organizations?

**URL:** <https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507>\
**Category:** JupyterHub\
**Created:** [March 6, 2025, 1:09am UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507 "2025-03-06T01:09:18Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ana-v-espinoza](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/ana-v-espinoza/32/13722_2.png) [@ana-v-espinoza](https://discourse.jupyter.org/u/ana-v-espinoza)\
**Post date:** [March 6, 2025, 1:09am UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507/1 "2025-03-06T01:09:19Z")

</div>

Hello all,

I’m deploying a JupyterHub with Kubernetes and am trying to allow access to users based on GitHub organization membership, but am getting a 403 Forbidden error on login.

I’ve created the GitHub OAuth app and have added the following in my config file:

```yaml
hub:
    GitHubOAuthenticator:
      client_id: "xxx"
      client_secret: "xxx"
      oauth_callback_url: "xxx"
      allowed_organizations:
        - "xxx"
      scope:
        - "read:org"
        - "read:user"
    JupyterHub:
      authenticator_class: github

```

The [GitHub OAuth docs](https://oauthenticator.readthedocs.io/en/latest/reference/api/gen/oauthenticator.github.html#oauthenticator.github.GitHubOAuthenticator.allowed_organizations) on allowed\_organizations tells me all I need is the `read:org` scope. Of course, I am part of the GitHub org that I’ve added to the allow list.

I’m using the most recent helm chart version 4.1.0.

Is there something obvious that I’m missing?

Thanks,

ana v. e.

---

<div class="post-metadata">

**Author:** ![mahendrapaipuri](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/mahendrapaipuri/32/6800_2.png) [@mahendrapaipuri](https://discourse.jupyter.org/u/mahendrapaipuri)\
**Post date:** [March 6, 2025, 8:27am UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507/2 "2025-03-06T08:27:25Z")

</div>

Could you share the logs of JupyterHub, if possible in debug mode? Does it work if you use [`allowed_users`](https://oauthenticator.readthedocs.io/en/latest/reference/api/gen/oauthenticator.github.html#oauthenticator.github.GitHubOAuthenticator.allowed_users) instead of `allowed_organizations`?

---

<div class="post-metadata">

**Author:** ![ana-v-espinoza](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/ana-v-espinoza/32/13722_2.png) [@ana-v-espinoza](https://discourse.jupyter.org/u/ana-v-espinoza)\
**Post date:** [March 6, 2025, 4:17pm UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507/3 "2025-03-06T16:17:15Z")

</div>

Hello Mahendra,

The non-debug logs are what you might expect: I successfully authenticate with GitHub, but I am not _authorized_ to access the JupyterHub.

However, once I’ve done as you suggest and looked at the debug logs, I think I see the problem:

```auto
[D 2025-03-06 16:08:35.760 JupyterHub github:313] Checking GitHub organization membership: ana-v-espinoza in <org>?
[D 2025-03-06 16:08:36.000 JupyterHub github:331] ana-v-espinoza does not appear to be a member of <org> (status=404): User does not exist or is not a ***public*** member of the organization
[W 2025-03-06 16:08:36.000 JupyterHub github:186] User ana-v-espinoza is not part of allowed_organizations
[W 2025-03-06 16:08:36.000 JupyterHub auth:732] User 'ana-v-espinoza' not allowed.

```

The emphasis on “public” is mine. Sure enough, it seems like my status as a member of that org isn’t public.

Thank you for the suggestion to take a look at the debug-level logs.

Best,

ana v. e.

---

<div class="post-metadata">

**Author:** ![ana-v-espinoza](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/ana-v-espinoza/32/13722_2.png) [@ana-v-espinoza](https://discourse.jupyter.org/u/ana-v-espinoza)\
**Post date:** [March 6, 2025, 7:21pm UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507/4 "2025-03-06T19:21:50Z")

</div>

In case somebody is looking for a “full” solution to this problem, to change the visibility of my organization membership from private to public, I followed the official GitHub docs on the matter:

> **[Publicizing or hiding organization membership - GitHub Docs](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-your-membership-in-organizations/publicizing-or-hiding-organization-membership)**
>
> If you'd like to tell the world which organizations you belong to, you can display the avatars of the organizations on your profile.

---

<div class="post-metadata">

**Author:** ![consideRatio](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/consideratio/32/1033_2.png) [@consideRatio](https://discourse.jupyter.org/u/consideRatio)\
**Post date:** [March 6, 2025, 11:58pm UTC](https://discourse.jupyter.org/t/github-oauth-allowed-organizations/33507/5 "2025-03-06T23:58:16Z")

</div>

It is not a great user experience to be asked to do these steps, but thankfully there is an option to it with the approval by an admin of the allowed github orgs permission.

Details on doing this are documented by @sgibson91 with [2i2c.org](http://2i2c.org) in [GitHub Orgs and Teams — Infrastructure Guide](https://infrastructure.2i2c.org/hub-deployment-guide/configure-auth/github-orgs/#granting-access-to-the-oauth-app) !

It would be great to have that good documentation about this in the oauthenticator project!
