MikhbarMIKHBAR
Apps & Software

GitHub Completes Rollout of Stateless App Installation Tokens

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is officially complete across the platform.

GitHub Completes Rollout of Stateless App Installation Tokens

Rollout Completion and New Format Specifications

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete, according to the [GitHub Changelog](https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out/). By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API.

Although installation tokens still start with the ghs_ prefix, they are now about 520 characters long instead of the legacy 40 characters. Despite this structural transformation, underlying parameters such as token permissions, repository scoping, the standard one-hour expiration, and the installation access token REST API endpoint remain completely unchanged. Furthermore, tokens that were minted prior to this transition will continue to function normally until they reach their natural expiration.

Deprecation Timeline for Temporary Request Headers

The temporary X-GitHub-Stateless-S2S-Token request header, which was initially introduced to allow users to validate the new format on demand, is set for deprecation on November 30, 2026. Developers can review details about its initial deployment via [our original changelog for its release](https://github.blog/changelog/2026-05-15-github-app-installation-tokens-per-request-override-header/). After the November deadline, the platform will no longer respect the header, and all eligible applications will receive stateless tokens automatically.

Development teams are advised to finish validating their applications and workflows using both token formats and to remove the header from their production code before November 30, 2026. Ensuring that systems adapt to these longer headers prevents unexpected integration failures.

System Verification and Opaque String Handling

Organizations that have not yet done so must confirm that every system handling installation tokens treats them as opaque strings rather than relying on fixed-length assumptions. Developers need to check for validation routines that require tokens to be strictly 40 characters long or patterns tailored specifically for the legacy format.

Additional areas to review include database columns, secret stores, and environment variables that feature fixed or small maximum length constraints. Proxies, API gateways, and middleware layers must also be inspected to ensure they do not inadvertently truncate or reject longer Authorization headers.

Logging and Further Developer Resources

Logging configurations and secret redaction rules must also be audited, as legacy rules might only match the old 40-character token pattern and fail to redact the new format properly. Comprehensive guidance on proper implementation can be found in the official documentation covering [Generating an installation access token for a GitHub App](https://docs.github.com/apps/creating-github-apps/authenticating-with-a-github-app/generating-an-installation-access-token-for-a-github-app).

Developers can continue to track platform updates, tips, and technical guides by reviewing the full archive available on the [Back to changelog](https://github.blog/changelog/) portal.

Sources

Continue chronologically

You are readingGitHub Completes Rollout of Stateless App Installation Tokens
GitHub Introduces Confidential Comments on Security Advisories
Older storyGitHub Introduces Confidential Comments on Security AdvisoriesOctober 2, 2026 · 3 min

Related entity coverage