GitHub App installation tokens grow from 40 to about 520 characters
GitHub has finished moving GitHub App installation tokens to a new stateless format, the company says in its changelog. The staged rollout began on 27 April 2026; from now on every newly minted installation token uses the ghs_APPID_JWT form by default. GitHub says the change makes issuing and validating tokens faster and improves the reliability of its API.
The visible difference is length. Tokens still begin with ghs_, but they are now about 520 characters long instead of 40. Everything else that callers rely on stays the same: permissions, repository scoping, the one-hour lifetime and the REST endpoint that issues installation access tokens. Tokens created before the switch keep working until they expire.
There is also a deadline. While the rollout ran, apps could request the new format on demand with a temporary X-GitHub-Stateless-S2S-Token header, so that teams could test both formats side by side. That header will be deprecated on 30 November 2026. After that GitHub will ignore it and every eligible app will always receive stateless tokens, so the header should be taken out of production code before then.
The changelog lists where things can go wrong, all of them places where code treated a token as something with a known shape rather than as an opaque string:
- validation that expects exactly 40 characters, or regular expressions written for the old format;
- storage with a short length cap, whether a database column, a secrets vault or an environment variable;
- proxies, gateways or middleware that cut off or reject long
Authorizationheaders; - logging and redaction rules that only recognise the legacy token pattern.

Why it matters
The last item is the quiet one. A token that breaks a 40-character column fails loudly; a token that no longer matches a redaction pattern is written into logs in full, and nobody notices until someone reads them. Anyone running CI systems, bots or internal tools that mint installation tokens should check secret scanning and log masking rules as well as storage limits, and search the codebase for the temporary header while there are still two months left.