github pack needs a personal access
token and nothing else: no app, no consent screen. GitHub’s token form takes its
scopes from the link that opens it, so the one below arrives with exactly the
scopes the pack’s tools declare.
The links open in a new tab; this page stays where you left it.
1
Generate the token
Open GitHub’s token form
— the note says Charter, and
repo and read:user are ticked.Pick an expiration, then Generate token at the bottom of the page. GitHub
shows the token once, beginning ghp_.2
Set it
3
Authorize it for SSO organisations
Skip this unless an organisation you belong to signs in through SAML. If one
does, its repositories answer
403 — “Resource protected by organization SAML
enforcement” — until the token is authorized for it: on
your tokens page, Configure SSO beside
the token → Authorize for that organisation.4
Verify
verify_github.py
A narrower token
A fine-grained token reaches only the repositories you pick, with only the permissions you grant. This form opens with read and write on contents, issues and pull requests; choose the resource owner and the repositories yourself, since GitHub will not prefill them. Two costs come with it: an organisation can require its admins to approve the token before it works, and a few endpoints — notifications among them — accept only classic tokens.Your users’ accounts
Each user authorizes an app you register, and the app’s token acts as them.- A GitHub App — github.com/settings/apps/new. Set the Callback URL to your consent route. Whether Expire user authorization tokens is ticked decides whether you get a refresh token, and that changes which credential provider you use: which token you have.
- An OAuth App — github.com/settings/applications/new. Simpler, with an Authorization callback URL and tokens that never expire.
scope, the token that reports no scopes at all — are on its
provider page.
Related
- GitHub — the server constant, every token type, and refresh under expiry
- Every pack — what the other packs need, in one table