[{"data":1,"prerenderedAt":938},["ShallowReactive",2],{"navigation_docs":3,"-engineering-github-personal-access-token":369,"-engineering-github-personal-access-token-surround":934},[4,8,72,102,220,266,280,301,365],{"title":5,"path":6,"stem":7},"Introduction","\u002Fintroduction","0.introduction",{"title":9,"icon":10,"path":11,"stem":12,"children":13,"page":67},"Company","i-lucide-building-2","\u002Fcompany","1.company",[14,18,22,26,30,34,38,42,46,50,54,68],{"title":15,"path":16,"stem":17},"About","\u002Fcompany\u002Fabout","1.company\u002F0.about",{"title":19,"path":20,"stem":21},"Values","\u002Fcompany\u002Fvalues","1.company\u002F1.values",{"title":23,"path":24,"stem":25},"Communication","\u002Fcompany\u002Fcommunication","1.company\u002Fcommunication",{"title":27,"path":28,"stem":29},"Competition","\u002Fcompany\u002Fcompetition","1.company\u002Fcompetition",{"title":31,"path":32,"stem":33},"Hybrid Working","\u002Fcompany\u002Fhybrid-working","1.company\u002Fhybrid-working",{"title":35,"path":36,"stem":37},"Manchester Office","\u002Fcompany\u002Foffice","1.company\u002Foffice",{"title":39,"path":40,"stem":41},"Operations","\u002Fcompany\u002Foperations","1.company\u002Foperations",{"title":43,"path":44,"stem":45},"Policies","\u002Fcompany\u002Fpolicies","1.company\u002Fpolicies",{"title":47,"path":48,"stem":49},"Problem Statement","\u002Fcompany\u002Fproblem-statement","1.company\u002Fproblem-statement",{"title":51,"path":52,"stem":53},"Product Strategy","\u002Fcompany\u002Fproduct-strategy","1.company\u002Fproduct-strategy",{"title":55,"path":56,"stem":57,"children":58,"page":67},"Products","\u002Fcompany\u002Fproducts","1.company\u002Fproducts",[59,63],{"title":60,"path":61,"stem":62},"Capability Exchange","\u002Fcompany\u002Fproducts\u002Fcapability-exchange","1.company\u002Fproducts\u002Fcapability-exchange",{"title":64,"path":65,"stem":66},"ESProfiler Platform","\u002Fcompany\u002Fproducts\u002Fesprofiler","1.company\u002Fproducts\u002Fesprofiler",false,{"title":69,"path":70,"stem":71},"Security","\u002Fcompany\u002Fsecurity","1.company\u002Fsecurity",{"title":73,"icon":74,"path":75,"stem":76,"children":77,"page":67},"People Ops","i-lucide-users","\u002Fpeople-ops","2.people-ops",[78,82,86,90,94,98],{"title":79,"path":80,"stem":81},"Compensation","\u002Fpeople-ops\u002Fcompensation","2.people-ops\u002Fcompensation",{"title":83,"path":84,"stem":85},"Education","\u002Fpeople-ops\u002Feducation","2.people-ops\u002Feducation",{"title":87,"path":88,"stem":89},"Expenses","\u002Fpeople-ops\u002Fexpenses","2.people-ops\u002Fexpenses",{"title":91,"path":92,"stem":93},"Holiday & Leave","\u002Fpeople-ops\u002Fleave","2.people-ops\u002Fleave",{"title":95,"path":96,"stem":97},"Onboarding","\u002Fpeople-ops\u002Fonboarding","2.people-ops\u002Fonboarding",{"title":99,"path":100,"stem":101},"Recruitment","\u002Fpeople-ops\u002Frecruitment","2.people-ops\u002Frecruitment",{"title":103,"icon":104,"path":105,"stem":106,"children":107,"page":67},"Engineering","i-lucide-rocket","\u002Fengineering","3.engineering",[108,151,155,175,196,200,208,212,216],{"title":109,"path":110,"stem":111,"children":112,"page":67},"Contributing","\u002Fengineering\u002Fcontributing","3.engineering\u002Fcontributing",[113,117,121,125,129,142],{"title":114,"path":115,"stem":116},"Development Setup","\u002Fengineering\u002Fcontributing\u002Fdevelopment-setup","3.engineering\u002Fcontributing\u002F1.development-setup",{"title":118,"path":119,"stem":120},"Engineering Operations","\u002Fengineering\u002Fcontributing\u002Fengineering-operations","3.engineering\u002Fcontributing\u002F2.engineering-operations",{"title":122,"path":123,"stem":124},"Documentation","\u002Fengineering\u002Fcontributing\u002Fdocumentation","3.engineering\u002Fcontributing\u002F3.documentation",{"title":126,"path":127,"stem":128},"Agentic Coding","\u002Fengineering\u002Fcontributing\u002Fagentic-coding","3.engineering\u002Fcontributing\u002Fagentic-coding",{"title":130,"path":131,"stem":132,"children":133,"page":67},"Back End","\u002Fengineering\u002Fcontributing\u002Fback-end","3.engineering\u002Fcontributing\u002Fback-end",[134,138],{"title":135,"path":136,"stem":137},"API Guidelines","\u002Fengineering\u002Fcontributing\u002Fback-end\u002Fapi-guidelines","3.engineering\u002Fcontributing\u002Fback-end\u002Fapi-guidelines",{"title":139,"path":140,"stem":141},"LLM Prompts & Langfuse Integration","\u002Fengineering\u002Fcontributing\u002Fback-end\u002Fllm-prompts","3.engineering\u002Fcontributing\u002Fback-end\u002Fllm-prompts",{"title":143,"path":144,"stem":145,"children":146,"page":67},"Front End","\u002Fengineering\u002Fcontributing\u002Ffront-end","3.engineering\u002Fcontributing\u002Ffront-end",[147],{"title":148,"path":149,"stem":150},"Testing","\u002Fengineering\u002Fcontributing\u002Ffront-end\u002Ftesting","3.engineering\u002Fcontributing\u002Ffront-end\u002Ftesting",{"title":152,"path":153,"stem":154},"Production Database","\u002Fengineering\u002Fdatabase-connection","3.engineering\u002Fdatabase-connection",{"title":156,"path":157,"stem":158,"children":159},"Deployment","\u002Fengineering\u002Fdeployment","3.engineering\u002Fdeployment",[160,163,167,171],{"title":60,"path":161,"stem":162},"\u002Fengineering\u002Fdeployment\u002Fcapability-exchange","3.engineering\u002Fdeployment\u002Fcapability-exchange",{"title":164,"path":165,"stem":166},"Langfuse Deployment","\u002Fengineering\u002Fdeployment\u002Fecs-langfuse-deployment","3.engineering\u002Fdeployment\u002Fecs-langfuse-deployment",{"title":168,"path":169,"stem":170},"ESP Platform Configuration","\u002Fengineering\u002Fdeployment\u002Fesp-platform-configuration","3.engineering\u002Fdeployment\u002Fesp-platform-configuration",{"title":172,"path":173,"stem":174},"Platform","\u002Fengineering\u002Fdeployment\u002Fplatform","3.engineering\u002Fdeployment\u002Fplatform",{"title":176,"path":177,"stem":178,"children":179,"page":67},"Github","\u002Fengineering\u002Fgithub","3.engineering\u002Fgithub",[180,184,188,192],{"title":181,"path":182,"stem":183},"Packages","\u002Fengineering\u002Fgithub\u002Fpackages","3.engineering\u002Fgithub\u002Fpackages",{"title":185,"path":186,"stem":187},"Personal Access Token","\u002Fengineering\u002Fgithub\u002Fpersonal-access-token","3.engineering\u002Fgithub\u002Fpersonal-access-token",{"title":189,"path":190,"stem":191},"Troubleshooting","\u002Fengineering\u002Fgithub\u002Ftroubleshooting","3.engineering\u002Fgithub\u002Ftroubleshooting",{"title":193,"path":194,"stem":195},"Workflows","\u002Fengineering\u002Fgithub\u002Fworkflows","3.engineering\u002Fgithub\u002Fworkflows",{"title":197,"path":198,"stem":199},"Platform Ops","\u002Fengineering\u002Fplatform-ops","3.engineering\u002Fplatform-ops",{"title":172,"path":201,"stem":202,"children":203,"page":67},"\u002Fengineering\u002Fplatform","3.engineering\u002Fplatform",[204],{"title":205,"path":206,"stem":207},"useAPI","\u002Fengineering\u002Fplatform\u002Fuse-api","3.engineering\u002Fplatform\u002Fuse-api",{"title":209,"path":210,"stem":211},"Project Management","\u002Fengineering\u002Fproject-management","3.engineering\u002Fproject-management",{"title":213,"path":214,"stem":215},"Releases","\u002Fengineering\u002Frelease","3.engineering\u002Frelease",{"title":217,"path":218,"stem":219},"Tools","\u002Fengineering\u002Ftools","3.engineering\u002Ftools",{"title":221,"icon":222,"path":223,"stem":224,"children":225,"page":67},"Design","i-lucide-palette","\u002Fdesign","4.design",[226,247,251,255,259,262],{"title":227,"path":228,"stem":229,"children":230,"page":67},"Personas","\u002Fdesign\u002Fpersonas","4.design\u002F0.personas",[231,235,239,243],{"title":232,"path":233,"stem":234},"CISO - Simon","\u002Fdesign\u002Fpersonas\u002F01-ciso-simon","4.design\u002F0.personas\u002F01-ciso-simon",{"title":236,"path":237,"stem":238},"Head of Cyber - Harry","\u002Fdesign\u002Fpersonas\u002F02-head-of-cyber-harry","4.design\u002F0.personas\u002F02-head-of-cyber-harry",{"title":240,"path":241,"stem":242},"Security Architect - Sasha","\u002Fdesign\u002Fpersonas\u002F03-security-architect-sasha","4.design\u002F0.personas\u002F03-security-architect-sasha",{"title":244,"path":245,"stem":246},"Procurement Officer - Paige","\u002Fdesign\u002Fpersonas\u002F04-procurement-officer-paige","4.design\u002F0.personas\u002F04-procurement-officer-paige",{"title":248,"path":249,"stem":250},"Design Thinking","\u002Fdesign\u002Fdesign-thinking","4.design\u002F1.design-thinking",{"title":252,"path":253,"stem":254},"Design & Development","\u002Fdesign\u002Fdesign-and-development","4.design\u002F3.design-and-development",{"title":256,"path":257,"stem":258},"Branding","\u002Fdesign\u002Fbranding","4.design\u002F4.branding",{"title":217,"path":260,"stem":261},"\u002Fdesign\u002Ftools","4.design\u002F5.tools",{"title":263,"path":264,"stem":265},"Customer Success","\u002Fdesign\u002Fworking-with-customers","4.design\u002F6.working-with-customers",{"title":267,"icon":268,"path":269,"stem":270,"children":271,"page":67},"Sales","i-lucide-dollar-sign","\u002Fsales","4.sales",[272,276],{"title":273,"path":274,"stem":275},"Customer Onboarding","\u002Fsales\u002Fonboarding","4.sales\u002Fonboarding",{"title":277,"path":278,"stem":279},"Sales Tools","\u002Fsales\u002Ftools","4.sales\u002Ftools",{"title":281,"icon":282,"path":283,"stem":284,"children":285,"page":67},"Marketing","i-lucide-book-image","\u002Fmarketing","5.marketing",[286,290,294,297],{"title":287,"path":288,"stem":289},"Content","\u002Fmarketing\u002Fcontent","5.marketing\u002Fcontent",{"title":291,"path":292,"stem":293},"Messaging","\u002Fmarketing\u002Fmessaging","5.marketing\u002Fmessaging",{"title":217,"path":295,"stem":296},"\u002Fmarketing\u002Ftools","5.marketing\u002Ftools",{"title":298,"path":299,"stem":300},"Website","\u002Fmarketing\u002Fwebsite","5.marketing\u002Fwebsite",{"title":302,"icon":303,"path":304,"stem":305,"children":306,"page":67},"AI & Data Ops","i-lucide-database","\u002Fdata-ops","6.data-ops",[307,315,319,344,361],{"title":60,"path":308,"stem":309,"children":310,"page":67},"\u002Fdata-ops\u002Fcapability-exchange","6.data-ops\u002FCapability Exchange",[311],{"title":312,"path":313,"stem":314},"Leaderboard Calculation","\u002Fdata-ops\u002Fcapability-exchange\u002Fleaderboard-calculation","6.data-ops\u002FCapability Exchange\u002Fleaderboard-calculation",{"title":316,"path":317,"stem":318},"Account Portal (CAS)","\u002Fdata-ops\u002Faccount-portal","6.data-ops\u002Faccount-portal",{"title":320,"path":321,"stem":322,"children":323,"page":67},"Data Management","\u002Fdata-ops\u002Fdata-management","6.data-ops\u002Fdata-management",[324,328,332,336,340],{"title":325,"path":326,"stem":327},"Adding Products","\u002Fdata-ops\u002Fdata-management\u002Fadding-products","6.data-ops\u002Fdata-management\u002Fadding-products",{"title":329,"path":330,"stem":331},"Adding Vendors","\u002Fdata-ops\u002Fdata-management\u002Fadding-vendors","6.data-ops\u002Fdata-management\u002Fadding-vendors",{"title":333,"path":334,"stem":335},"Framework Mapping","\u002Fdata-ops\u002Fdata-management\u002Fframework-mapping","6.data-ops\u002Fdata-management\u002Fframework-mapping",{"title":337,"path":338,"stem":339},"Refreshing Vendors","\u002Fdata-ops\u002Fdata-management\u002Frefreshing-vendors","6.data-ops\u002Fdata-management\u002Frefreshing-vendors",{"title":341,"path":342,"stem":343},"Reviewing Draft Vendors","\u002Fdata-ops\u002Fdata-management\u002Freviewing-draft-vendors","6.data-ops\u002Fdata-management\u002Freviewing-draft-vendors",{"title":345,"path":346,"stem":347,"children":348,"page":67},"LLM Ops","\u002Fdata-ops\u002Fllm-ops","6.data-ops\u002Fllm-ops",[349,353,357],{"title":350,"path":351,"stem":352},"Agents","\u002Fdata-ops\u002Fllm-ops\u002Fagents","6.data-ops\u002Fllm-ops\u002F1.agents",{"title":354,"path":355,"stem":356},"ESPi Architecture & Query Flow","\u002Fdata-ops\u002Fllm-ops\u002Fespi-architecture","6.data-ops\u002Fllm-ops\u002F2.espi-architecture",{"title":358,"path":359,"stem":360},"Evaluating Agents","\u002Fdata-ops\u002Fllm-ops\u002Fevaluations","6.data-ops\u002Fllm-ops\u002F3.evaluations",{"title":362,"path":363,"stem":364},"Message Queues","\u002Fdata-ops\u002Fmessage-queues","6.data-ops\u002Fmessage-queues",{"title":366,"path":367,"stem":368},"Glossary","\u002Fglossary","glossary",{"id":370,"title":185,"body":371,"description":826,"extension":929,"links":930,"meta":931,"navigation":712,"path":186,"seo":932,"stem":187,"__hash__":933},"docs\u002F3.engineering\u002Fgithub\u002Fpersonal-access-token.md",{"type":372,"value":373,"toc":910},"minimark",[374,379,383,386,389,393,402,405,439,442,453,470,472,479,486,491,552,556,559,619,640,642,646,651,701,713,715,719,765,767,771,774,807,811,817,827,831,835,841,845,864,866,870],[375,376,378],"h2",{"id":377},"personal-access-tokens-pats","Personal Access Tokens (PATs)",[380,381,382],"p",{},"A Personal Access Token (PAT) is used to authenticate with GitHub in place of a password — for example, when pulling private packages, publishing packages, or using the GitHub API from scripts and CI\u002FCD pipelines.",[380,384,385],{},"GitHub offers two types of PATs:",[387,388],"hr",{},[375,390,392],{"id":391},"token-types","Token Types",[394,395,397,398],"h3",{"id":396},"fine-grained-tokens-recommended-for-most-tasks","Fine-grained Tokens ",[399,400,401],"em",{},"(recommended for most tasks)",[380,403,404],{},"Fine-grained tokens are the newer, more secure token format introduced by GitHub. They offer:",[406,407,408,416,427,433],"ul",{},[409,410,411,415],"li",{},[412,413,414],"strong",{},"Repository-scoped access"," — you select exactly which repositories the token can access, rather than granting access to everything.",[409,417,418,421,422,426],{},[412,419,420],{},"Granular permissions"," — instead of broad scopes (e.g. ",[423,424,425],"code",{},"repo","), you choose specific read\u002Fwrite permissions per resource (Issues, Pull Requests, Contents, etc.).",[409,428,429,432],{},[412,430,431],{},"Expiry enforcement"," — fine-grained tokens require an expiry date (maximum 1 year).",[409,434,435,438],{},[412,436,437],{},"Owner approval"," — if your organisation enforces it, tokens may require admin approval before they become active.",[380,440,441],{},"Fine-grained tokens are ideal for:",[406,443,444,447,450],{},[409,445,446],{},"Accessing or cloning specific repositories",[409,448,449],{},"Operating GitHub Actions with least-privilege access",[409,451,452],{},"Anything where limiting blast radius is important",[454,455,456],"blockquote",{},[380,457,458,461,462,465,466,469],{},[412,459,460],{},"Limitation:"," Fine-grained tokens ",[412,463,464],{},"cannot"," currently authenticate against the ",[412,467,468],{},"GitHub Packages \u002F npm registry",". If your task involves installing or publishing packages, you must use a Classic token.",[387,471],{},[394,473,475,476],{"id":474},"classic-tokens-required-for-github-packages","Classic Tokens ",[399,477,478],{},"(required for GitHub Packages)",[380,480,481,482,485],{},"Classic tokens use a broad, scope-based permission model and have been available since GitHub's early API days. While less granular than fine-grained tokens, they are currently the ",[412,483,484],{},"only supported token type"," for GitHub Packages authentication.",[487,488,490],"h4",{"id":489},"when-you-must-use-a-classic-token","When you must use a Classic token",[492,493,494,507],"table",{},[495,496,497],"thead",{},[498,499,500,504],"tr",{},[501,502,503],"th",{},"Use Case",[501,505,506],{},"Classic Token Required?",[508,509,510,526,537,544],"tbody",{},[498,511,512,523],{},[513,514,515,518,519,522],"td",{},[423,516,517],{},"npm install"," \u002F ",[423,520,521],{},"yarn install"," from a private GitHub Package registry",[513,524,525],{},"✅ Yes",[498,527,528,535],{},[513,529,530,531,534],{},"Publishing a package to GitHub Packages (",[423,532,533],{},"npm publish",")",[513,536,525],{},[498,538,539,542],{},[513,540,541],{},"Reading\u002Finstalling packages in CI\u002FCD (e.g. GitHub Actions, local dev)",[513,543,525],{},[498,545,546,549],{},[513,547,548],{},"General GitHub API access or repository operations",[513,550,551],{},"❌ Fine-grained preferred",[487,553,555],{"id":554},"required-scopes-for-package-work","Required scopes for package work",[380,557,558],{},"When creating a Classic token for package consumption or development, select the following scopes:",[492,560,561,571],{},[495,562,563],{},[498,564,565,568],{},[501,566,567],{},"Scope",[501,569,570],{},"Purpose",[508,572,573,583,593,606],{},[498,574,575,580],{},[513,576,577],{},[423,578,579],{},"read:packages",[513,581,582],{},"Download \u002F install packages from the GitHub Package Registry",[498,584,585,590],{},[513,586,587],{},[423,588,589],{},"write:packages",[513,591,592],{},"Publish packages to the GitHub Package Registry",[498,594,595,599],{},[513,596,597],{},[423,598,425],{},[513,600,601,602,605],{},"Required when the package repository is ",[412,603,604],{},"private"," — allows the registry to verify access",[498,607,608,613],{},[513,609,610],{},[423,611,612],{},"delete:packages",[513,614,615,618],{},[399,616,617],{},"(Optional)"," Remove package versions you own",[454,620,621],{},[380,622,623,626,627,630,631,633,634,636,637,639],{},[412,624,625],{},"Tip:"," If you only need to ",[412,628,629],{},"consume"," (install) packages and not publish them, ",[423,632,579],{}," + ",[423,635,425],{}," is sufficient. Only add ",[423,638,589],{}," if you are actively developing and publishing packages.",[387,641],{},[375,643,645],{"id":644},"how-to-create-a-classic-token","How to Create a Classic Token",[454,647,648],{},[380,649,650],{},"This is the token type you will need for local development and CI\u002FCD package access.",[652,653,654,665,680,687,694],"ol",{},[409,655,656,657,664],{},"Go to ",[658,659,663],"a",{"href":660,"rel":661},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Ftokens\u002Fnew",[662],"nofollow","GitHub Tokens (Classic)"," — ensure you are logged into the correct account.",[409,666,667,668,671,672,675,676,679],{},"Give the token a descriptive ",[412,669,670],{},"Note",", e.g. ",[423,673,674],{},"Package Development"," or ",[423,677,678],{},"Package Read-Only",".",[409,681,682,683,686],{},"Set an ",[412,684,685],{},"Expiration"," — choose an appropriate window (e.g. 90 days). Avoid \"No expiration\" for security reasons.",[409,688,689,690,693],{},"Under ",[412,691,692],{},"Select scopes",", tick the scopes relevant to your use case (see table above).",[409,695,696,697,700],{},"Click ",[412,698,699],{},"Generate token"," and copy it immediately — GitHub will not show it again.",[702,703],"iframe",{"width":704,"height":705,"src":706,"className":707,"title":709,"frameBorder":710,"allow":711,"allowFullScreen":712},560,315,"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FWJI2V86zs2A",[708],"mx-auto","YouTube video player","0","accelerometer;",true,[387,714],{},[375,716,718],{"id":717},"how-to-create-a-fine-grained-token","How to Create a Fine-grained Token",[652,720,721,728,733,738,744,754,760],{},[409,722,656,723,664],{},[658,724,727],{"href":725,"rel":726},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Fpersonal-access-tokens\u002Fnew",[662],"GitHub Fine-grained Tokens",[409,729,667,730,679],{},[412,731,732],{},"Token name",[409,734,682,735,737],{},[412,736,685],{}," (required — up to 365 days).",[409,739,689,740,743],{},[412,741,742],{},"Resource owner",", select the organisation or your personal account.",[409,745,689,746,749,750,753],{},[412,747,748],{},"Repository access",", choose ",[399,751,752],{},"Only select repositories"," and pick the repositories needed.",[409,755,689,756,759],{},[412,757,758],{},"Permissions",", expand each section and set only the minimum permissions required.",[409,761,696,762,764],{},[412,763,699],{}," and copy it immediately.",[387,766],{},[375,768,770],{"id":769},"configuring-projects-to-use-tokens","Configuring projects to use tokens",[380,772,773],{},"This setup works for both local development and CI\u002FCD pipelines.",[652,775,776,786],{},[409,777,778,779,675,782,785],{},"Configure projects to use tokens in the ",[423,780,781],{},".npmrc",[423,783,784],{},".yarnrc.yml"," files.",[409,787,788,789,792,793],{},"Set the ",[423,790,791],{},"NODE_AUTH_TOKEN"," environment variable to your Classic token when applicable in:\n",[406,794,795,801],{},[409,796,797,798],{},"GitHub Repository Secrets for ",[412,799,800],{},"CI\u002FCD pipelines",[409,802,803,804,679],{},"User Account System environment variables for ",[412,805,806],{},"local development",[394,808,810],{"id":809},"_1-for-yarn-projects","1. For Yarn Projects",[380,812,813,814,816],{},"Once you have a Classic token, configure npm to authenticate against the GitHub Package Registry by adding the following to the project-level ",[423,815,784],{},":",[818,819,824],"pre",{"className":820,"code":822,"language":823},[821],"language-text","npmScopes:\n  es-profiler:\n    npmAlwaysAuth: false\n    npmAuthToken: ${NODE_AUTH_TOKEN:-}\n    npmRegistryServer: \"https:\u002F\u002Fnpm.pkg.github.com\"\n","text",[423,825,822],{"__ignoreMap":826},"",[394,828,830],{"id":829},"_1-for-npm-projects","1. For NPM Projects",[380,832,813,833,816],{},[423,834,781],{},[818,836,839],{"className":837,"code":838,"language":823},[821],"\u002F\u002Fnpm.pkg.github.com\u002F:_authToken=${NODE_AUTH_TOKEN}\n@es-profiler:registry=https:\u002F\u002Fnpm.pkg.github.com\n",[423,840,838],{"__ignoreMap":826},[394,842,844],{"id":843},"_2-for-local-development","2. For Local Development",[454,846,847],{},[380,848,849,852,853,856,857,860,861,679],{},[412,850,851],{},"Never commit your token to source control."," Use environment variables or secrets management instead. In CI\u002FCD pipelines, store the token as a secret (e.g. ",[423,854,855],{},"GITHUB_TOKEN"," or a custom secret) and reference it in your ",[423,858,859],{},"npmrc"," via ",[423,862,863],{},"${TOKEN_ENV_VAR}",[387,865],{},[375,867,869],{"id":868},"best-practices","Best Practices",[406,871,872,878,887,898,904],{},[409,873,874,877],{},[412,875,876],{},"Rotate tokens regularly"," — set a calendar reminder before your token expires.",[409,879,880,883,884,886],{},[412,881,882],{},"Use the minimum required scopes"," — avoid ",[423,885,425],{}," on Classic tokens unless the package repository is private.",[409,888,889,892,893,679],{},[412,890,891],{},"Revoke unused tokens"," — audit your tokens periodically at ",[658,894,897],{"href":895,"rel":896},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Ftokens",[662],"github.com\u002Fsettings\u002Ftokens",[409,899,900,903],{},[412,901,902],{},"Never share tokens"," — each developer and each CI\u002FCD pipeline should have its own token.",[409,905,906,909],{},[412,907,908],{},"Prefer fine-grained tokens"," for any non-package GitHub API usage.",{"title":826,"searchDepth":911,"depth":911,"links":912},2,[913,914,921,922,923,928],{"id":377,"depth":911,"text":378},{"id":391,"depth":911,"text":392,"children":915},[916,919],{"id":396,"depth":917,"text":918},3,"Fine-grained Tokens (recommended for most tasks)",{"id":474,"depth":917,"text":920},"Classic Tokens (required for GitHub Packages)",{"id":644,"depth":911,"text":645},{"id":717,"depth":911,"text":718},{"id":769,"depth":911,"text":770,"children":924},[925,926,927],{"id":809,"depth":917,"text":810},{"id":829,"depth":917,"text":830},{"id":843,"depth":917,"text":844},{"id":868,"depth":911,"text":869},"md",null,{},{"description":826},"mV45VhJHcUtyhT5mLV2CMK-EPx1m4TKfPDuvFtYUnGI",[935,936],{"title":181,"path":182,"stem":183,"description":826,"children":-1},{"title":189,"path":190,"stem":191,"description":937,"children":-1},"Troubleshooting guide for GitHub issues.",1790076749491]