Skip to main content

Stateless GitHub App installation tokens rolled out

By Steven Van ·

Installation tokens are now about 520 characters instead of 40, and the opt-in header stops working on November 30, 2026.

The staged rollout of stateless GitHub App installation tokens, which began on April 27, 2026, is now complete. All newly minted installation tokens default to the ghs_APPID_JWT format. GitHub says this makes token issuance and validation faster and improves the reliability of the API.

Tokens still start with ghs_, but they are now about 520 characters long instead of 40. Permissions, repository scoping, the one-hour expiration and the installation access token REST API endpoint are unchanged. Tokens minted before the change keep working until they expire.

The temporary X-GitHub-Stateless-S2S-Token request header, which let developers try the new format on demand, will be deprecated on November 30, 2026. After that date GitHub will stop respecting it, and all eligible apps will always receive stateless tokens. GitHub recommends removing the header from production code before then.

GitHub lists what to check in integrations that handle installation tokens:

  • Validation that requires exactly 40 characters, or patterns written for the legacy format.
  • Database columns, secret stores or environment variables with a fixed or small maximum length.
  • Proxies, gateways or middleware that truncate or reject long Authorization headers.
  • Logging and secret redaction rules that only match the legacy token pattern.
GitHub
GitHub
Where the world builds software — Git hosting, pull requests, issues, Actions CI/CD, and Copilot, free for public and private repos.
View GitHub →

Original source

Read Stateless GitHub App installation tokens rolled out on Creators Toolbox