Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

Behind GitHub's new authentication token formats

Blog post from GitHub

Post Details
Company
Date Published
Author
Indigo K
Word Count
732
Company Posts That Month
19
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitHub has introduced new authentication token formats designed to enhance security and improve the detection of compromised tokens. The updated tokens feature identifiable three-letter prefixes and a separator to distinguish them clearly, reducing false positives in secret scanning to 0.5%. A checksum has been added to virtually eliminate false positives, using a CRC32 algorithm encoded with Base62. The new token formats also maintain or increase token entropy, ensuring a high level of uniqueness without altering token length. GitHub encourages users to reset personal access and OAuth tokens to benefit from these security improvements. Additionally, service providers issuing tokens are advised to adopt these practices and participate in GitHub's secret scanning program to enhance their security measures.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.