Resource icon

Fine-grained GitHub token versus classic token

What it means​

A fine-grained personal access token can be scoped to one resource owner, selected repositories, specific permissions and an expiration. A classic token uses broader scopes and may reach more repositories than a single script needs. GitHub recommends the fine-grained type when the operation supports it, while documenting feature gaps that can still require classic tokens. Both are secrets tied to the account that generated them.

A real-world example​

A build script only needs to read one private repository. A classic token with broad repo scope gives the script more access than required; a fine-grained token limited to that repository and Contents read is a closer match, subject to any organization approval policy.

What to do​

Inventory existing tokens in Developer settings, then issue a narrow replacement and test the exact operation. Store it in a protected secret manager, revoke the older token after migration and record an expiration date. Never commit either token to source code.

The distinction that matters​

Fine-grained does not mean leak-proof, and an app or SSH key may still access the same repository. Classic is not automatically a mistake when GitHub has a documented compatibility gap, but its wider authority deserves tighter review and a plan to replace it. GitHub token types and limits
Posted by
Jack
Views
6
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack