GitHub Enterprise and organization owners now have improved visibility into authentication activity via personal access token (classic), fine-grained personal access token (FGP), OAuth token, SSH key or deploy key. The audit log may now contain hashed renderings of the token or key used for authentication and the programmatic_access_type
field describing the type of token/key used for authentication. Enterprise and organization owners can query by specific token or key to identify and track activity.
To learn more, read our documentation on identifying audit log events performed by an access token.