A personal token acts as you: its actions carry your name, it stops working when you leave, and it is a long-lived secret. A GitHub 29 App is an identity of its own. It is registered once, installed on accounts or repositories with fine-grained permissions, and signs a short JWT with its private key to obtain installation tokens that expire after an hour. Its commits and comments show as app-name[bot], and it can receive webhooks for everything it is installed on. Creating an App needs the web UI or the manifest flow, so it is not run here.
| Fine-grained token | GitHub App | GITHUB_TOKEN | |
|---|---|---|---|
| Acts as | You | The app (name[bot]) | github-actions[bot] |
| Lifetime | Set at creation | 1 hour per token | One job |
| REST limit per hour | 5,000 | 5,000 to 12,500 | 1,000 per repository |
| Webhooks | Separate, per repository | Built in | None |
| Best for | Personal scripts | Bots, integrations, CI across repositories | Steps inside a workflow |
Use a token for scripts you run yourself, GITHUB_TOKEN inside workflows, and an App for anything unattended: a release bot, a CI integration, or cross-repository work GITHUB_TOKEN cannot reach. Probot 126 (https://github.com/probot/probot 9,615 ) (ISC) and the octokit npm 2,036 package handle JWTs, token refresh and webhook verification for you.