OSCR

Tokens for git

git uses GitHub's own fine-grained personal access tokens, made on GitHub's page: OSCR issues no git token.

Over HTTPS, git asks for your GitHub account and a password: the password is a token you make on GitHub (git with GitHub). OSCR never sees it: git sends it to github.com only.OSCR's own tokens, for its API, come later; they will never reach git.

Fine-grained personal access tokens

A fine-grained token acts for one account, on the repositories you choose, with the permissions you choose, until the date you choose. For git, the right token reaches one repository, with Contents write, and expires. Source:Managing your personal access tokens.

The token template URLs

A link to GitHub's new-token page can fill the form in advance; you review it and confirm on GitHub. Each repository's page on OSCR gives its own link, which asks for Contents write, an expiry of 30 days and a name, and says in the description which repository to pick, since the link cannot choose it. For a repository NAME of the account OWNER:

https://github.com/settings/personal-access-tokens/new?name=git+for+NAME&description=git+clone%2C+pull+and+push+for+OWNER%2FNAME.+Under+%22Repository+access%22%2C+choose+%22Only+select+repositories%22+and+pick+OWNER%2FNAME.&target_name=OWNER&expires_in=30&contents=write

Or start from GitHub's new-token page. Source:GitHub's changelog.

Classic tokens, and why not

A classic token's scopes reach every repository your account can reach (repo is all of them, private ones included), and it may never expire. A classic token that leaks gives away everything; a fine-grained one, one repository until its date. Use a fine-grained token unless GitHub's page says a feature needs a classic one.

Making a token

Name and description
A name of at most 40 characters, and a description of at most 1,024 characters: say what the token is for and on which computer, to know which to delete later.
Expiry and reminder
30 days by default, or a date up to 366 days ahead; GitHub also offers no expiry, which is best avoided. GitHub reminds you by email before a token expires; after that, git's password is refused until you make a new one.
Repository access
Public repositories (read-only), all repositories, or only select repositories: for git, "Only select repositories", and the one repository.
Permissions per resource
Repository permissions and account permissions, each none, read or write. Metadata read is always included. For git: Contents read to clone a private repository, Contents write to push. Nothing else. Source:Permissions required for fine-grained personal access tokens.

The token is shown once: give it to git's credential helper at once (the credential cache).

Prefixes

Every GitHub token starts with a prefix that tells its kind, so that a leaked token is recognised (GitHub's push protection and secret scanning, push protection):

GitHub's token prefixes
PrefixKind
github_pat_a fine-grained personal access token
ghp_a classic personal access token
gho_an OAuth app's token
ghu_a GitHub App's user access token
ghs_a GitHub App's installation token
ghr_a refresh token

Source: About authentication to GitHub.

Managing your tokens

List and last use
GitHub's token settings list your tokens, their expiry, and when each was last used.
Regenerate
A new value with the same settings and a new expiry; the old value stops working at once. Update the credential helper of each computer.
Delete
Revokes the token at once. Delete a token you no longer use, and any token that may have leaked.
Count limit
An account holds at most 50 fine-grained tokens.
Revocation after a year unused
GitHub revokes a personal access token left unused for a year, and one found pushed to a public repository.

Sources: Managing your personal access tokens,Token expiration and revocation.

Credential revocation by token type

Since 2026-08-18, the administrators of an organization or enterprise can revoke or deauthorize every credential of one type at once (personal access tokens, SSH keys, OAuth or GitHub App tokens), for everyone or for one member. If your lab's organization does it, make a new token. Source:GitHub's changelog.

Permissions that git does not need

Artifact metadata
Since 2026-01-13, a fine-grained permission of its own, in place of Contents, for GitHub's artifact metadata API. A token for git never needs it. Source: GitHub's changelog.
Vulnerability alerts
Since 2026-09-03, a vulnerability-alerts permission for the token of GitHub Actions workflows (GITHUB_TOKEN), to read Dependabot alerts with nothing more. It is not for git either. Source:GitHub's changelog.

The npm token changes

If you publish a package on npm: npm's classic tokens can no longer be made, and a granular token that can publish expires within 90 days and asks for two-factor authentication. Since 2026-07-31, a granular token that bypasses two-factor authentication can no longer make tokens nor manage maintainers or organizations. Sources:npm's classic tokens, bypass tokens.

OSCR's own tokens

OSCR issues no git token and runs no git server. When you create or change a repository through OSCR, you authorize its GitHub App on GitHub for that one action; the token GitHub gives it is used once, revoked, and never stored. OSCR's own API tokens come with its API, later; they will reach that API only.

The hosting guides