跳到主内容
@wquguru
精选88GitHub Changelog云与平台

GitHub App安装令牌格式变更:长度增至520字符,11月30日起弃用兼容头

Stateless GitHub App installation tokens rolled out

原文
发到 X
推荐理由

集成GitHub App的开发者必须检查代码与基础设施,确保能容纳520字符的新令牌格式,并在11月30日前移除临时的兼容Header,否则将面临鉴权失败或服务中断风险。

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API.

无状态 GitHub App 安装令牌格式的阶段性发布已于 2026 年 4 月 27 日开始,现已完成。默认情况下,所有新签发的 GitHub App 安装令牌都将采用无状态的 ghs_APPID_JWT 格式,这使令牌的签发和验证速度更快,并提高了 GitHub API 的可靠性。

What’s changed

变更内容

Installation tokens still start with the ghs_ prefix, but they’re now about 520 characters long instead of 40.

安装令牌仍以 ghs_ 前缀开头,但现在长度约为 520 个字符,而非之前的 40 个字符。

Token permissions, repository scoping, the one-hour expiration, and the installation access token REST API endpoint are unchanged. Tokens minted before the change continue to work until they expire.

令牌权限、仓库范围限定、一小时过期时间以及安装访问令牌 REST API 端点均保持不变。在此次变更前签发的令牌在过期前仍可继续使用。

What to expect going forward

后续预期

The temporary X-GitHub-Stateless-S2S-Token request header, which we introduced so you could validate the new format on demand, will be deprecated on November 30, 2026. After that date, GitHub will no longer respect the header, and all eligible apps will always receive stateless tokens. To learn more about the temporary header, see our original changelog for its release.

我们此前引入的临时 X-GitHub-Stateless-S2S-Token 请求头,旨在让您按需验证新格式,将于 2026 年 11 月 30 日弃用。在此日期之后,GitHub 将不再识别该请求头,所有符合条件的应用将始终接收无状态令牌。如需了解更多关于该临时请求头的信息,请参阅其发布时的原始更新日志。

Once you’ve validated your apps and workflows with both token formats, remove the header from your production code before November 30, 2026.

在您使用两种令牌格式对应用和工作流进行验证后,请在 2026 年 11 月 30 日之前从生产代码中移除该请求头。

Check your integrations

检查您的集成

If you haven’t already, confirm that every system that handles installation tokens treats them as opaque strings. Look for:

如果您尚未确认,请确保所有处理安装令牌的系统都将其视为不透明字符串。请留意:

  • Validation that requires tokens to be exactly 40 characters or patterns written for the legacy format.
  • Database columns, secret stores, or environment variables with a fixed or small maximum length.
  • Proxies, gateways, or middleware that truncate or reject long Authorization headers.
  • Logging and secret redaction rules that only match the legacy token pattern.
  • 要求令牌长度必须恰好为 40 个字符或为旧格式编写的模式的验证逻辑。
  • 具有固定或较小最大长度的数据库列、密钥存储库或环境变量。
  • 会截断或拒绝长 Authorization 标头的代理、网关或中间件。
  • 仅匹配旧令牌模式的日志记录和密钥脱敏规则。

To learn more, see Generating an installation access token for a GitHub App.

如需了解更多,请参阅为 GitHub App 生成安装访问令牌。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件