[metadata]
description: Your tokens can expire and can also be revoked by you, applications you have authorized, and GitHub itself.
google-site-verification: c1kuD-K2HIVF635lypcsWPoD4kilo5-jA_wBFyT4uMY
og:image: https://docs.github.com/assets/cb-345/images/social-cards/authentication.png
og:site_name: GitHub Docs
og:title: Token expiration and revocation - GitHub Docs
og:type: article
og:url: https://docs-internal.github.com/en/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation
page-document-type: article
path-article: authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation
path-language: en
path-product: authentication
path-version: free-pro-team@latest
status: 200
twitter:card: summary
twitter:description: Your tokens can expire and can also be revoked by you, applications you have authorized, and GitHub itself.
twitter:domain: docs-internal.github.com
twitter:image: https://docs.github.com/assets/cb-345/images/social-cards/authentication.png
twitter:title: Token expiration and revocation - GitHub Docs
twitter:url: https://docs-internal.github.com/en/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation
viewport: width=device-width, initial-scale=1

[document-links]
About 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/about-two-factor-authentication
About SSH: /en/authentication/connecting-to-github-with-ssh/about-ssh
About anonymized URLs: /en/authentication/keeping-your-account-and-data-secure/about-anonymized-urls
About mandatory 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/about-mandatory-two-factor-authentication
About passkeys: /en/authentication/authenticating-with-a-passkey/about-passkeys
Access GitHub with 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/accessing-github-using-two-factor-authentication
Account security: /en/authentication/keeping-your-account-and-data-secure
Activating optional features for GitHub Apps: /en/apps/maintaining-github-apps/activating-optional-features-for-github-apps
Add a GPG key: /en/authentication/managing-commit-signature-verification/adding-a-gpg-key-to-your-github-account
Add a new SSH key: /en/authentication/connecting-to-github-with-ssh/adding-a-new-ssh-key-to-your-github-account
Agent failure to sign: /en/authentication/troubleshooting-ssh/error-agent-admitted-failure-to-sign
Ask the GitHub community: https://github.com/orgs/community/discussions
Associate email with GPG key: /en/authentication/managing-commit-signature-verification/associating-an-email-with-your-gpg-key
Authentication to GitHub: /en/authentication/keeping-your-account-and-data-secure/about-authentication-to-github
Authentication: /en/authentication
Blog: https://github.blog
Change 2FA method: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/changing-your-two-factor-authentication-method
Check for existing SSH key: /en/authentication/connecting-to-github-with-ssh/checking-for-existing-ssh-keys
Check verification status: /en/authentication/troubleshooting-commit-signature-verification/checking-your-commit-and-tag-signature-verification-status
Commit signature verification: /en/authentication/managing-commit-signature-verification/about-commit-signature-verification
Configure 2FA recovery: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication-recovery-methods
Configure 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/configuring-two-factor-authentication
Contact support: https://support.github.com
Countries supporting SMS: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/countries-where-sms-authentication-is-supported
Create a strong password: /en/authentication/keeping-your-account-and-data-secure/creating-a-strong-password
Deleted or missing SSH keys: /en/authentication/troubleshooting-ssh/deleted-or-missing-ssh-keys
Deploy keys: /en/authentication/keeping-your-account-and-data-secure/reviewing-your-deploy-keys
Disable 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/disabling-two-factor-authentication-for-your-personal-account
Displaying verification for all commits: /en/authentication/managing-commit-signature-verification/displaying-verification-statuses-for-all-of-your-commits
Error: Bad file number: /en/authentication/troubleshooting-ssh/error-bad-file-number
Error: Host key verification failed: /en/authentication/troubleshooting-ssh/error-host-key-verification-failed
Error: Key already in use: /en/authentication/troubleshooting-ssh/error-key-already-in-use
Error: Unknown key type: /en/authentication/troubleshooting-ssh/error-unknown-key-type
Existing GPG keys: /en/authentication/managing-commit-signature-verification/checking-for-existing-gpg-keys
Expert services: https://services.github.com
Generate new SSH key: /en/authentication/connecting-to-github-with-ssh/generating-a-new-ssh-key-and-adding-it-to-the-ssh-agent
Generating a new GPG key: /en/authentication/managing-commit-signature-verification/generating-a-new-gpg-key
GitHub Docs: /en
GitHub's IP addresses: /en/authentication/keeping-your-account-and-data-secure/about-githubs-ip-addresses
Home: /en
Learn how to contribute: /contributing
Make a contribution: https://github.com/github/docs/blob/main/content/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation.md
Manage personal access tokens: /en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens
Manage your passkeys: /en/authentication/authenticating-with-a-passkey/managing-your-passkeys
Managing deploy keys: /en/authentication/connecting-to-github-with-ssh/managing-deploy-keys
Managing your personal access tokens: /en/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens
Permission denied (publickey): /en/authentication/troubleshooting-ssh/error-permission-denied-publickey
Permission denied other-repo: /en/authentication/troubleshooting-ssh/error-permission-to-userrepo-denied-to-userother-repo
Permission denied other-user: /en/authentication/troubleshooting-ssh/error-permission-to-userrepo-denied-to-other-user
Pricing: https://github.com/pricing
Privacy policy: /en/site-policy/privacy-policies/github-privacy-statement
Privacy: /en/site-policy/privacy-policies/github-privacy-statement
REST API endpoints for OAuth authorizations: /en/rest/apps/oauth-applications#delete-an-app-authorization
REST API endpoints for OAuth authorizations: /en/rest/apps/oauth-applications#delete-an-app-token
Recover SSH key passphrase: /en/authentication/troubleshooting-ssh/recovering-your-ssh-key-passphrase
Recover an account with 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/recovering-your-account-if-you-lose-your-2fa-credentials
Remove sensitive data: /en/authentication/keeping-your-account-and-data-secure/removing-sensitive-data-from-a-repository
Review security log: /en/authentication/keeping-your-account-and-data-secure/reviewing-your-security-log
Reviewing and revoking authorization of GitHub Apps: /en/apps/using-github-apps/reviewing-and-revoking-authorization-of-github-apps
Reviewing your SSH keys: /en/authentication/keeping-your-account-and-data-secure/reviewing-your-ssh-keys
Reviewing your authorized OAuth apps: /en/apps/oauth-apps/using-oauth-apps/reviewing-your-authorized-oauth-apps
Reviewing your security log: /en/authentication/keeping-your-account-and-data-secure/reviewing-your-security-log
Revocation: /en/rest/credentials/revoke#revoke-a-list-of-credentials
Revoke your credentials: /en/authentication/keeping-your-account-and-data-secure/revoking-your-credentials
Revoking SSO authorizations or deleting credentials in your enterprise: /en/enterprise-cloud@latest/admin/managing-iam/respond-to-incidents/revoke-authorizations-or-tokens
Revoking your credentials: /en/authentication/keeping-your-account-and-data-secure/revoking-your-credentials
SSH agent forwarding: /en/authentication/connecting-to-github-with-ssh/using-ssh-agent-forwarding
SSH key audit: /en/authentication/troubleshooting-ssh/error-were-doing-an-ssh-key-audit
SSH key fingerprints: /en/authentication/keeping-your-account-and-data-secure/githubs-ssh-key-fingerprints
SSH key passphrases: /en/authentication/connecting-to-github-with-ssh/working-with-ssh-key-passphrases
SSL certificate problem: /en/authentication/troubleshooting-ssh/error-ssl-certificate-problem-verify-that-the-ca-cert-is-ok
Security log events: /en/authentication/keeping-your-account-and-data-secure/security-log-events
Sign in with a passkey: /en/authentication/authenticating-with-a-passkey/signing-in-with-a-passkey
Signing commits: /en/authentication/managing-commit-signature-verification/signing-commits
Signing tags: /en/authentication/managing-commit-signature-verification/signing-tags
Status: https://www.githubstatus.com/
Sudo mode: /en/authentication/keeping-your-account-and-data-secure/sudo-mode
Switching between accounts: /en/authentication/keeping-your-account-and-data-secure/switching-between-accounts
Tell Git about your signing key: /en/authentication/managing-commit-signature-verification/telling-git-about-your-signing-key
Terms: /en/site-policy/github-terms/github-terms-of-service
Test your SSH connection: /en/authentication/connecting-to-github-with-ssh/testing-your-ssh-connection
Token expiration: /en/authentication/keeping-your-account-and-data-secure/token-expiration-and-revocation
Troubleshooting 2FA: /en/authentication/securing-your-account-with-two-factor-authentication-2fa/troubleshooting-two-factor-authentication-issues
Unauthorized access: /en/authentication/keeping-your-account-and-data-secure/preventing-unauthorized-access
Update access credentials: /en/authentication/keeping-your-account-and-data-secure/updating-your-github-access-credentials
Use SSH over HTTPS port: /en/authentication/troubleshooting-ssh/using-ssh-over-the-https-port
Use verified email in GPG key: /en/authentication/troubleshooting-commit-signature-verification/using-a-verified-email-address-in-your-gpg-key
Verifying devices on sign in: /en/authentication/keeping-your-account-and-data-secure/verifying-new-devices-when-signing-in
Viewing and managing sessions: /en/authentication/keeping-your-account-and-data-secure/viewing-and-managing-your-sessions
ssh-add "illegal option" error: /en/authentication/troubleshooting-ssh/error-ssh-add-illegal-option----apple-use-keychain

[content]
Token expiration and revocation - GitHub Docs
Skip to main content
GitHub Docs
Version:
Free, Pro, & Team
Search or ask Copilot
Search or ask
Copilot
Select language: current language is English
Search or ask Copilot
Search or ask
Copilot
Open menu
Collapse sidebar
Expand sidebar
Scroll breadcrumbs left
Home
Authentication
Account security
Token expiration
Scroll breadcrumbs right
Authentication
Account security
Authentication to GitHub
Create a strong password
Switching between accounts
Verifying devices on sign in
Update access credentials
Manage personal access tokens
Reviewing your SSH keys
Deploy keys
Token expiration
Revoke your credentials
Review security log
Security log events
Remove sensitive data
About anonymized URLs
GitHub's IP addresses
SSH key fingerprints
Sudo mode
Unauthorized access
Viewing and managing sessions
Secure your account with 2FA
About 2FA
About mandatory 2FA
Configure 2FA
Configure 2FA recovery
Access GitHub with 2FA
Countries supporting SMS
Change 2FA method
Troubleshooting 2FA
Recover an account with 2FA
Disable 2FA
Authenticate with a passkey
About passkeys
Manage your passkeys
Sign in with a passkey
Connect with SSH
About SSH
Check for existing SSH key
Generate new SSH key
Add a new SSH key
Test your SSH connection
SSH key passphrases
SSH agent forwarding
Managing deploy keys
Troubleshooting SSH
Use SSH over HTTPS port
Recover SSH key passphrase
Deleted or missing SSH keys
Error: Host key verification failed
Permission denied (publickey)
Error: Bad file number
Error: Key already in use
Permission denied other-user
Permission denied other-repo
Agent failure to sign
ssh-add "illegal option" error
SSL certificate problem
Error: Unknown key type
SSH key audit
Verify commit signatures
Commit signature verification
Existing GPG keys
Generating a new GPG key
Add a GPG key
Tell Git about your signing key
Associate email with GPG key
Signing commits
Signing tags
Displaying verification for all commits
Troubleshoot verification
Check verification status
Use verified email in GPG key
Token expiration and revocation
Your tokens can expire and can also be revoked by you, applications you have authorized, and GitHub itself.
Copy as Markdown
In this article
Token revoked after reaching its expiration date
Token revoked when pushed to a public repository or public gist
Token expired due to lack of use
Token revoked by the user
Token revoked by a third party
Token revoked by the OAuth app
Token revoked due to excess of tokens for an OAuth app with the same scope
User token expired due to GitHub App configuration
Token revoked by enterprise owners
When a token has expired or has been revoked, it can no longer be used to authenticate Git and API requests. It is not possible to restore an expired or revoked token, you or the application will need to create a new token.
This article explains the possible reasons your GitHub token might be revoked or expire.
Note
When a personal access token, OAuth app token, or GitHub App token expires or is revoked, you may see an
oauth_authorization.destroy
action in your security log. For more information, see
Reviewing your security log
.
Token revoked after reaching its expiration date
When you create a personal access token, we recommend that you set an expiration for your token. Upon reaching your token's expiration date, the token is automatically revoked. For more information, see
Managing your personal access tokens
.
Token revoked when pushed to a public repository or public gist
If a valid OAuth token, GitHub App token, or personal access token is pushed to a public repository or public gist, the token will be automatically revoked.
Token expired due to lack of use
GitHub will automatically revoke an OAuth token or personal access token when the token hasn't been used in one year.
Token revoked by the user
You can revoke your authorization of a GitHub App or OAuth app from your account settings which will revoke any tokens associated with the app. For more information, see
Reviewing and revoking authorization of GitHub Apps
and
Reviewing your authorized OAuth apps
.
Once an authorization is revoked, any tokens associated with the authorization will be revoked as well. To reauthorize an application, follow the instructions from the third-party application or website to connect your account on GitHub again.
You can also revoke all your credentials at once from your account settings. This is useful if you believe your account may be compromised or your hardware was lost or stolen. For more information, see
Revoking your credentials
.
Token revoked by a third party
To prevent unauthorized access using exposed tokens, GitHub recommends token revocation to ensure that a token can no longer be used to authenticate to GitHub. The credential revocation API supports revoking the following token types:
Personal access tokens (classic) with the
ghp_
prefix
Fine-grained personal access tokens with the
github_pat_
prefix
OAuth app tokens with the
gho_
prefix
GitHub App user-to-server tokens with the
ghu_
prefix
GitHub App refresh tokens with the
ghr_
prefix
If you find any of these tokens leaked on GitHub or elsewhere, you can submit a revocation request through the REST API. See
Revocation
for the complete and authoritative list of supported token types.
When a valid token is submitted to GitHub's credential revocation API, the token will be automatically revoked. This API allows a third party to revoke a token they do not own and helps protect the data associated with this token from unauthorized access, limiting the impact of exposed tokens.
To encourage reports and ensure that exposed tokens can be quickly and easily revoked, we do not require authentication for the revocation requests submitted through the API. As a result, GitHub is unable to provide further information about the source of the reported token.
Token revoked by the OAuth app
The owner of an OAuth app can revoke an account's authorization of their app, this will also revoke any tokens associated with the authorization. For more information about revoking authorizations of your OAuth app, see
REST API endpoints for OAuth authorizations
.
OAuth app owners can also revoke individual tokens associated with an authorization. For more information about revoking individual tokens for your OAuth app, see
REST API endpoints for OAuth authorizations
.
Token revoked due to excess of tokens for an OAuth app with the same scope
There is a limit of ten tokens that are issued per user/application/scope combination, and a rate limit of ten tokens created per hour. If an application creates more than ten tokens for the same user and the same scopes, GitHub revokes one of the existing tokens with the same user/application/scope combination, chosen in this order:
The oldest token that has never been used and that was created more than one minute ago. Tokens created within the last minute are usually protected, so that an application has time to use a token it has just created.
If there is no such token, but at least one token has been used, the token that was least recently used.
If no token has ever been used, the oldest token, even if it was created within the last minute.
Hitting the hourly rate limit will not revoke your oldest token. Instead, it will trigger a re-authorization prompt within the browser, asking the user to double check the permissions they're granting your app. This prompt is intended to give a break to any potential infinite loop the app is stuck in, since there's little to no reason for an app to request ten tokens from the user within an hour.
User token expired due to GitHub App configuration
User access tokens created by a GitHub App will expire after eight hours by default, and then must be regenerated using the included refresh token. Owners of GitHub Apps can optionally configure these tokens to never expire instead, but this is not recommended due to the security implications. For more information about configuring your GitHub App's user access tokens, see
Activating optional features for GitHub Apps
.
Token revoked by enterprise owners
Enterprise owners on GitHub Enterprise Cloud can revoke SSO authorizations or delete credentials for individual users or in bulk when responding to security incidents. Revoking SSO authorizations removes access to SSO-protected organization resources, while deleting credentials (available for Enterprise Managed Users only) removes the credentials entirely.
For more information, see
Revoking SSO authorizations or deleting credentials in your enterprise
.
Help and support
Did you find what you needed?
Yes
No
Privacy policy
Help us make these docs great!
All GitHub docs are open source. See something that's wrong or unclear? Submit a pull request.
Make a contribution
Learn how to contribute
Still need help?
Ask the GitHub community
Contact support
Legal
©
2026
GitHub, Inc.
Terms
Privacy
Status
Pricing
Expert services
Blog
