Tokens for git
git uses GitHub's own fine-grained personal access tokens, made on GitHub's page: OSCR issues no git token.
Over HTTPS, git asks for your GitHub account and a password: the password is a token you make on GitHub (git with GitHub). OSCR never sees it: git sends it to github.com only.OSCR's own tokens, for its API, come later; they will never reach git.
Fine-grained personal access tokens
A fine-grained token acts for one account, on the repositories you choose, with the permissions you choose, until the date you choose. For git, the right token reaches one repository, with Contents write, and expires. Source:Managing your personal access tokens.
The token template URLs
A link to GitHub's new-token page can fill the form in advance; you review it and confirm on GitHub. Each repository's page on OSCR gives its own link, which asks for Contents write, an expiry of 30 days and a name, and says in the description which repository to pick, since the link cannot choose it. For a repository NAME of the account OWNER:
https://github.com/settings/personal-access-tokens/new?name=git+for+NAME&description=git+clone%2C+pull+and+push+for+OWNER%2FNAME.+Under+%22Repository+access%22%2C+choose+%22Only+select+repositories%22+and+pick+OWNER%2FNAME.&target_name=OWNER&expires_in=30&contents=write
Or start from GitHub's new-token page. Source:GitHub's changelog.
Classic tokens, and why not
A classic token's scopes reach every repository your account can reach (repo is all of them, private ones included), and it may never expire. A classic token that leaks gives away everything; a fine-grained one, one repository until its date. Use a fine-grained token unless GitHub's page says a feature needs a classic one.
Making a token
- Name and description
- A name of at most 40 characters, and a description of at most 1,024 characters: say what the token is for and on which computer, to know which to delete later.
- Expiry and reminder
- 30 days by default, or a date up to 366 days ahead; GitHub also offers no expiry, which is best avoided. GitHub reminds you by email before a token expires; after that, git's password is refused until you make a new one.
- Repository access
- Public repositories (read-only), all repositories, or only select repositories: for git, "Only select repositories", and the one repository.
- Permissions per resource
- Repository permissions and account permissions, each none, read or write. Metadata read is always included. For git: Contents read to clone a private repository, Contents write to push. Nothing else. Source:Permissions required for fine-grained personal access tokens.
The token is shown once: give it to git's credential helper at once (the credential cache).
Prefixes
Every GitHub token starts with a prefix that tells its kind, so that a leaked token is recognised (GitHub's push protection and secret scanning, push protection):
| Prefix | Kind |
|---|---|
github_pat_ | a fine-grained personal access token |
ghp_ | a classic personal access token |
gho_ | an OAuth app's token |
ghu_ | a GitHub App's user access token |
ghs_ | a GitHub App's installation token |
ghr_ | a refresh token |
Source: About authentication to GitHub.
Managing your tokens
- List and last use
- GitHub's token settings list your tokens, their expiry, and when each was last used.
- Regenerate
- A new value with the same settings and a new expiry; the old value stops working at once. Update the credential helper of each computer.
- Delete
- Revokes the token at once. Delete a token you no longer use, and any token that may have leaked.
- Count limit
- An account holds at most 50 fine-grained tokens.
- Revocation after a year unused
- GitHub revokes a personal access token left unused for a year, and one found pushed to a public repository.
Sources: Managing your personal access tokens,Token expiration and revocation.
Credential revocation by token type
Since 2026-08-18, the administrators of an organization or enterprise can revoke or deauthorize every credential of one type at once (personal access tokens, SSH keys, OAuth or GitHub App tokens), for everyone or for one member. If your lab's organization does it, make a new token. Source:GitHub's changelog.
Permissions that git does not need
- Artifact metadata
- Since 2026-01-13, a fine-grained permission of its own, in place of Contents, for GitHub's artifact metadata API. A token for git never needs it. Source: GitHub's changelog.
- Vulnerability alerts
- Since 2026-09-03, a
vulnerability-alertspermission for the token of GitHub Actions workflows (GITHUB_TOKEN), to read Dependabot alerts with nothing more. It is not for git either. Source:GitHub's changelog.
The npm token changes
If you publish a package on npm: npm's classic tokens can no longer be made, and a granular token that can publish expires within 90 days and asks for two-factor authentication. Since 2026-07-31, a granular token that bypasses two-factor authentication can no longer make tokens nor manage maintainers or organizations. Sources:npm's classic tokens, bypass tokens.
OSCR's own tokens
OSCR issues no git token and runs no git server. When you create or change a repository through OSCR, you authorize its GitHub App on GitHub for that one action; the token GitHub gives it is used once, revoked, and never stored. OSCR's own API tokens come with its API, later; they will reach that API only.
