The quiet break is a fixed width.
GitHub completed its staged rollout of stateless installation access tokens on October 2. New tokens still begin with ghs_, but GitHub says they are now about 520 characters long instead of 40.[1] Code that asks only whether a value starts with ghs_ may pass. A database column, secret store, environment handoff, proxy, or redaction rule can still clip the rest.
GitHub says repository scope, permissions, the one-hour expiration, and the token endpoint did not change.[1] That makes this a useful compatibility lesson. The meaning stayed stable while the serialized value changed shape.
If a secret parser knows the length, it knows too much.
Read the response, not the string.
The installation-token endpoint returns the token with its expiry, permissions, and repository access. Callers may narrow repositories and permissions when they mint it. They cannot grant more access than the installation already has.[2]
Those response fields belong in your control record. The token itself does not. Treat it as a bearer credential, keep it out of URLs and logs, use transport security, and limit its exposure.[3] A longer token does not need decoding by every service that forwards it.
Fix the whole handling route.
GitHub calls out four failure points: exact-length validation, fixed or small storage, intermediaries that reject long authorization headers, and redaction patterns written for the old format.[1] Add renewal and expiry handling to the test plan. A one-hour token needs a controlled refresh path even when its format is accepted.
GitHub's app guidance also recommends minimum permissions, secure secret storage, and the correct token type for the actor.[4] Format compatibility does not replace access review.
Run a synthetic envelope test.
- Mint a test installation token in a non-production installation. Do not copy it into tickets or chat.
- Pass it through the same storage, process environment, proxy, and request library used in production.
- Confirm that logs and error reports redact the entire value. Test both the former and current lengths.
- Call one low-risk endpoint allowed by the test installation. Record only the response status, installation, scope, and expiry.
- Let the token expire. Confirm that the renewal path replaces it without printing either credential.
- Remove the temporary format-override header before GitHub's November 30, 2026 deprecation date.
The migration is done when the route handles an opaque credential. It is not done when one regular expression accepts 520 characters.