A fine-grained personal access token (prefix github_pat_) works for one resource owner (your account or one organization), on the repositories you pick, with the permissions you tick, until the date you set. GitHub 29 recommends it over the classic kind wherever it works. Create one in the browser (from GitHub's documentation): Settings, Developer settings, Personal access tokens, Fine-grained tokens, Generate new token. Choose a name, an expiration (30 days by default), the resource owner, the repositories, and the permissions: repository permissions such as Contents, Issues, Pull requests and Workflows, and account permissions such as Git 1,932 SSH keys. Copy it at once: GitHub never shows it again. The API reports a token's expiry in a header, and a refused call names the permission it needed:
gh api -i user --silent | grep -i -e '^HTTP' -e 'token-expiration'
gh api -i user/keys --silent | grep -i -e '^HTTP' -e 'accepted-github-permissions'HTTP/2.0 200 OK Github-Authentication-Token-Expiration: 2026-12-24 08:09:11 UTC gh: Resource not accessible by personal access token (HTTP 403) HTTP/2.0 403 Forbidden X-Accepted-Github-Permissions: keys=read
This book's token belongs to binarybehemoth, expires on 24 December 2026, and has repository permissions but no account permissions. Fine-grained tokens still cannot reach GitHub Packages 29 , the Checks API or user-owned Projects (Project Boards), and an organization can require an owner to approve each one before it gains access.