Stateless GitHub App installation tokens rolled out
GitHub has completed the rollout of stateless GitHub App installation token format. All newly created GitHub App installation tokens now use the stateless format by default.
The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API.
What’s changed
Installation tokens still start with the ghs_ prefix, but they’re now about 520 characters long instead of 40.
Token permissions, repository scoping, the one-hour expiration, and the installation access token REST API endpoint are unchanged. Tokens minted before the change continue to work until they expire.
What to expect going forward
The temporary X-GitHub-Stateless-S2S-Token request header, which we introduced so you could validate the new format on demand, will be deprecated on November 30, 2026. After that date, GitHub will no longer respect the header, and all eligible apps will always receive stateless tokens. To learn more about the temporary header, see our original changelog for its release.
Once you’ve validated your apps and workflows with both token formats, remove the header from your production code before November 30, 2026.
Check your integrations
If you haven’t already, confirm that every system that handles installation tokens treats them as opaque strings. Look for:
- Validation that requires tokens to be exactly 40 characters or patterns written for the legacy format.
- Database columns, secret stores, or environment variables with a fixed or small maximum length.
- Proxies, gateways, or middleware that truncate or reject long
Authorizationheaders. - Logging and secret redaction rules that only match the legacy token pattern.
To learn more, see Generating an installation access token for a GitHub App.
The post Stateless GitHub App installation tokens rolled out appeared first on The GitHub Blog.
Source: original entry ↗
More from GitHub
Follow GitHub to get its new changes in your feed and email digest.
Claude Haiku 5.5 now available in GitHub Copilot
Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.
Purpose-built model for leaked secret detection
GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.