← All vendor deprecations
GitHubDeprecationmedium

Stateless GitHub App installation tokens rolled out

Takes effect
30 Nov 2026
Published
4 Oct 2026

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API. What’s changed Installation tokens still start with the ghs_ prefix, but they’re now about 520 characters long instead of 40. Token permissions, repository scoping, the one-hour expiration, and the installation access token REST API endpoint are unchanged. Tokens minted before the change continue to work until they expire. What to expect going forward The temporary X-GitHub-Stateless-S2S-Token request header, which we introduced so you could validate the new format on demand, will be deprecated on November 30, 2026. After that date, GitHub will no longer respect the header, and all eligible apps will always receive stateless tokens. To learn more about the temporar

Read the vendor's announcement

Get this on your timeline

Add your stack to StackClock and we will remind you before it takes effect, along with your domain, certificate and license expiries.

Start free
GitHub: Stateless GitHub App installation tokens rolled out · StackClock