GitHub Personal Access Token (PAT) — secure authentication for GitHub
Introduction
The GitHub Personal Access Token (PAT) is a modern method for secure authentication on the GitHub platform.
Since August 2021, GitHub no longer supports using passwords for Git operations via HTTPS. This means that for any action that previously required a password, a token is now required. PAT allows you to:
- securely access repositories;
- work with the GitHub API;
- automate processes in scripts, CI/CD, and other tools without risking account compromise.
In short: a PAT is a “key” that provides limited access, can be easily revoked, and can have an expiration date.
Why use a PAT
The main purpose of a PAT is to secure work with GitHub while maintaining convenience.
Key functions:
- Security
A password gives full access to the account. If compromised, everything is at risk. A token can be limited by permissions and duration. - Automation
Scripts, CI/CD, bots, and other tools can use a PAT instead of manually entering a username and password. - Access control
Multiple tokens can be created with different permissions for different tasks. If one token leaks, it can be revoked without affecting others.
Types of tokens
GitHub offers two types of tokens:
- Classic
- Access is defined through scopes (e.g.,
repo,workflow). - Grants permissions to all user repositories.
- Simple to use but less flexible.
- Access is defined through scopes (e.g.,
- Fine-grained
- Allows limiting access to specific repositories.
- Can assign precise permissions, e.g., “read-only issues.”
- Organizations may require approval for these tokens.
💡 Tip: use fine-grained tokens where security and restricted access are important; classic tokens are for compatibility with older tools.
How to create a PAT
Step 1. Go to settings
- Open GitHub → Settings → Developer settings → Personal access tokens → Tokens (classic).
Step 2. Generate a new token
- Click Generate new token (classic).
- Set a name (Note), e.g.,
CI-tokenorGit-PC. - Set the expiration date — 90 days or 1 year is recommended.
- Select the required permissions (Scopes) — minimum for Git:
repo, for Actions:workflow. - Generate the token and save it immediately — it will only be shown once.
Using a PAT
1. Git via HTTPS
git clone https://github.com/username/repo.git
# Username: your GitHub username
# Password: generated token
To avoid entering the token every time, you can cache it:
git config --global credential.helper manager # Windows/Mac
git config --global credential.helper 'cache --timeout=3600' # Linux
2. Working with GitHub API
$token = Get-Secret -Name GitHubToken # securely retrieve token
$headers = @{ Authorization = "token $token" }
$repos = Invoke-RestMethod -Uri "https://api.github.com/user/repos" -Headers $headers
$repos | ForEach-Object { $_.name }
Creating an issue:
$body = @{
title = "New test task"
body = "Task description"
} | ConvertTo-Json
Invoke-RestMethod -Uri "https://api.github.com/repos/username/repo/issues" `
-Method Post `
-Headers $headers `
-Body $body
3. CI/CD and scripts
$token = Get-Secret -Name GitHubToken
git config --global user.name "CI Bot"
git config --global user.email "ci@example.com"
git add .
git commit -m "Automatic update"
git push "https://$token@github.com/username/repo.git" main
💡 Tip: use a separate token with minimal permissions for CI/CD.
4. IDE and local development
- In Visual Studio Code and other IDEs, you can use the PAT instead of a password to work with private repositories and pull requests.
- For different machines or IDEs, create separate tokens to limit the impact of a potential leak.
5. Management and security
- Store tokens in password managers or SecretStore.
- Create separate tokens for different tasks.
- Regularly review and revoke unused tokens.
- Always set an expiration date (do not use “No expiration”).
- Plan token rotation for CI/CD and automated scripts.
6. Alternative: GitHub CLI
gh auth login
The CLI will open the browser, perform authentication, create, and save the token locally. This avoids manual PAT generation and simplifies key management.