GitHub previews 'proof of presence' re-auth for token creation, webhook edits and soon PR merges, aimed at hijacked sessions and agents
GitHub Changelog·medium signal
GitHub's 2026-09-24 changelog introduces proof of presence in public preview. Before high-impact actions such as creating a token, editing webhooks, changing org security settings or viewing recovery codes, the user must re-authenticate or pass MFA. PR merges are next. GitHub names stolen session cookies, long-lived tokens from recent supply-chain attacks, and 'agents going an extra step without your knowledge' as the threat. A passed challenge lasts two hours per browser session, and the preview is limited to EMU enterprises and GHEC-DR using Entra ID SSO.