Evidence-backed facts
- Some GitHub REST endpoints expose public information without authentication, while authenticated requests can access additional endpoints and rate limits. informative
- Write operations require the endpoint's declared token permissions and remain separate from repository, organization, branch, or environment policy. informative
- GitHub supports personal access tokens, GitHub App tokens, and workflow GITHUB_TOKEN credentials; fine-grained tokens are recommended where supported. informative
- A token is an identity-bearing secret, and endpoint documentation plus accepted permissions must be checked before every read or mutation is exposed. informative