API · SDK · runtime · authentication lifecycle intelligence

Last updated · 3 October 2026

SchemaTrace

Breaking changes, enforcement dates and migration requirements.

ST-2026-272 · Authentication & identity

GitHub completes stateless App installation-token rollout

GitHub completed the stateless installation-token rollout on 2 October 2026 and retains a temporary override header until 30 November 2026.

GitHub Appsinstallation tokenstateless tokenauthentication

Previous state

GitHub App installations used the prior token implementation and could rely on its associated behavior.

Current state

Stateless installation access tokens are rolled out; a temporary compatibility override remains until 30 November 2026.

Who needs to care

GitHub Apps and automation that create or validate installation access tokens.

What to do

Validate integrations against stateless tokens and remove dependence on the temporary override before 30 November.

What the source does not prove

This is a bounded chronology update to the installation-token transition and does not change unrelated GitHub authentication methods.

Lifecycle history

Dated event sequence

  1. Rollout complete

    GitHub completed the stateless installation-token rollout.

  2. Override retires

    The temporary compatibility override header is scheduled to retire.

Evidence ledger

First-party sources

  1. 01
    GitHub Changelog — Stateless GitHub App installation tokens rolled out

    Official GitHub authentication rollout authority · 2026-10-02

    Open official source ↗