Stateless GitHub App Installation Tokens Fully Rolled Out
All newly minted GitHub App installation tokens now use a stateless, longer JWT format. Legacy format assumptions will break. Developers must review integrations, storage, and validation logic ahead of header deprecation on November 30, 2026.
What changed?
GitHub’s staged rollout of stateless installation tokens for GitHub Apps is complete. All newly issued installation tokens now use the stateless format (prefix ghs_APPID_JWT) and are approximately 520 characters long, replacing the previous 40-character format. The temporary opt-in X-GitHub-Stateless-S2S-Token header will be deprecated and unsupported after November 30, 2026.

Why does it matter to an everyday developer?
Any system that interacts with GitHub App installation tokens—and expects the old 40-character format—may now break. Typical issues include hardcoded length checks, fixed-length database columns or secrets storage, log scrubbing patterns, and middlewares that reject or truncate long headers. Reliability and speed for token operations may improve, but the developer’s primary concern is compatibility. Token permissions, scoping, and expiration are unchanged.
What can the developer do now?
Checklist for Developers
- 1
Review integration code
Update any validation or logic that assumes tokens are exactly 40 characters or follow the legacy pattern. Tokens must be treated as opaque strings.
- 2
Audit storage limits
