Stateless GitHub App installation tokens rolled out
The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API.
Installation tokens still start with the ghs_ prefix, but they’re now about 520 characters long instead of 40.
Token permissions, repository scoping, the one-hour expiration, and the installation access token REST API endpoint are unchanged. Tokens minted before the change continue to work until they expire.
The temporary X-GitHub-Stateless-S2S-Token request header, which we introduced so you could validate the new format on demand, will be deprecated on November 30, 2026. After that date, GitHub will no longer respect the header, and all eligible apps will always receive stateless tokens. To learn more about the temporary header, see our original changelog for its release.
Once you’ve validated your apps and workflows with both token formats, remove the header from your production code before November 30, 2026.
If you haven’t already, confirm that every system that handles installation tokens treats them as opaque strings. Look for:
- Validation that requires tokens to be exactly 40 characters or patterns written for the legacy format.
- Database columns, secret stores, or environment variables with a fixed or small maximum length.
- Proxies, gateways, or middleware that truncate or reject long
Authorizationheaders. - Logging and secret redaction rules that only match the legacy token pattern.
To learn more, see Generating an installation access token for a GitHub App.