What it means
A fine-grained personal access token can be scoped to one resource owner, selected repositories, specific permissions and an expiration. A classic token uses broader scopes and may reach more repositories than a single script needs. GitHub recommends the fine-grained type when the operation supports it, while documenting feature gaps that can still require classic tokens. Both are secrets tied to the account that generated them.
A real-world example
A build script only needs to read one private repository. A classic token with broad repo scope gives the script more access than required; a fine-grained token limited to that repository and Contents read is a closer match, subject to any organization approval policy.
What to do
Inventory existing tokens in Developer settings, then issue a narrow replacement and test the exact operation. Store it in a protected secret manager, revoke the older token after migration and record an expiration date. Never commit either token to source code.
The distinction that matters
Fine-grained does not mean leak-proof, and an app or SSH key may still access the same repository. Classic is not automatically a mistake when GitHub has a documented compatibility gap, but its wider authority deserves tighter review and a plan to replace it.
GitHub token types and limits