About DockerHub Organization
The DockerHub Organization integration connects Serval to a Docker Hub organization using an Organization Access Token (OAT). It covers the organization-administration side of Docker Hub: listing and searching members, changing member roles, removing members, viewing pending invites, and creating and managing teams (Docker Hub calls them groups). Repository-level work - image tags, repository descriptions, and granting teams access to repositories - lives on the sibling DockerHub integration instead. Serval talks to a single host for this integration: hub.docker.com. Authentication: Organization Access Token (OAT). Serval stores the token encrypted and exchanges it behind the scenes for a short-lived session credential when workflows make requests, caching and refreshing that credential automatically - your workflows never see the raw token. Data sync: On-demand only. Nothing is imported or polled in the background; Serval calls Docker Hub at the moment a workflow runs an action.What the DockerHub Organization integration enables
Get your credentials
You need two things: your organization’s exact name (slug) on Docker Hub, and an Organization Access Token (OAT) issued for that organization. An OAT is an opaque secret starting withdckr_oat_ that carries organization-admin scopes such as Member Read and Group Read. See Docker’s organization access tokens documentation for full details.
Check the prerequisites
Open the Admin Console
Generate the token
Note your organization name
Connect in Serval
Open the connect form
Enter the Organization Name (required)
Paste the Organization Access Token (required)
dckr_oat_ token into the password field. Leaving it empty when first connecting fails with: “Organization Access Token is required.”Enter an Instance Name (required)
Save
Verifying the connection
The integration ships three health checks that run against your real organization: Validate DockerHub OAT Connection - confirms the token authenticates and has organization-admin access by fetching a single member of the configured organization.- Success: “Successfully authenticated against DockerHub organization “[name]” ([number] members visible).”
- Failure: “Unable to authenticate against the DockerHub organization. Verify the Organization Access Token has not been revoked, that the Organization Name matches a DockerHub org the OAT was issued for, and that the OAT has org-admin scope.”
- Success: “Successfully fetched member listing for “[name]” ([number] members; showing first [number]).”
- Failure: “Unable to list members of the DockerHub organization. Confirm the Organization Access Token has organization-admin scope.”
- Success: “Successfully listed organization groups ([number] total in “[name]”).”
- Failure: “Unable to list groups in the DockerHub organization. Confirm the Organization Access Token has organization-admin scope.”
Gotchas and troubleshooting
A Personal Access Token will not work here
A Personal Access Token will not work here
Connection fails even though the token is valid
Connection fails even though the token is valid
Adding someone to a team fails
Adding someone to a team fails
Granting a team access to a repository happens on the other DockerHub integration
Granting a team access to a repository happens on the other DockerHub integration
Custom requests: no trailing slashes, and no bare organization lookup
Custom requests: no trailing slashes, and no bare organization lookup
Editing the connection: blank fields keep their saved values
Editing the connection: blank fields keep their saved values
Pagination defaults
Pagination defaults
Need help? Contact support@serval.com for assistance with your DockerHub Organization integration.

