[{"data":1,"prerenderedAt":848},["ShallowReactive",2],{"navigation_docs":3,"-engineering-github-personal-access-token":279,"-engineering-github-personal-access-token-surround":844},[4,8,67,96,162,186,199,216,275],{"title":5,"path":6,"stem":7},"Introduction","\u002Fintroduction","0.introduction",{"title":9,"path":10,"stem":11,"children":12,"page":62},"Company","\u002Fcompany","1.company",[13,17,21,25,29,33,37,41,45,49,63],{"title":14,"path":15,"stem":16},"About","\u002Fcompany\u002Fabout","1.company\u002F0.about",{"title":18,"path":19,"stem":20},"Values","\u002Fcompany\u002Fvalues","1.company\u002F1.values",{"title":22,"path":23,"stem":24},"Communication","\u002Fcompany\u002Fcommunication","1.company\u002Fcommunication",{"title":26,"path":27,"stem":28},"Competition","\u002Fcompany\u002Fcompetition","1.company\u002Fcompetition",{"title":30,"path":31,"stem":32},"Hybrid Working","\u002Fcompany\u002Fhybrid-working","1.company\u002Fhybrid-working",{"title":34,"path":35,"stem":36},"Manchester Office","\u002Fcompany\u002Foffice","1.company\u002Foffice",{"title":38,"path":39,"stem":40},"Operations","\u002Fcompany\u002Foperations","1.company\u002Foperations",{"title":42,"path":43,"stem":44},"Policies","\u002Fcompany\u002Fpolicies","1.company\u002Fpolicies",{"title":46,"path":47,"stem":48},"Product Strategy","\u002Fcompany\u002Fproduct-strategy","1.company\u002Fproduct-strategy",{"title":50,"path":51,"stem":52,"children":53,"page":62},"Products","\u002Fcompany\u002Fproducts","1.company\u002Fproducts",[54,58],{"title":55,"path":56,"stem":57},"Capability Exchange","\u002Fcompany\u002Fproducts\u002Fcapability-exchange","1.company\u002Fproducts\u002Fcapability-exchange",{"title":59,"path":60,"stem":61},"ESProfiler Platform","\u002Fcompany\u002Fproducts\u002Fesprofiler","1.company\u002Fproducts\u002Fesprofiler",false,{"title":64,"path":65,"stem":66},"Security","\u002Fcompany\u002Fsecurity","1.company\u002Fsecurity",{"title":68,"path":69,"stem":70,"children":71,"page":62},"People Ops","\u002Fpeople-ops","2.people-ops",[72,76,80,84,88,92],{"title":73,"path":74,"stem":75},"Compensation","\u002Fpeople-ops\u002Fcompensation","2.people-ops\u002Fcompensation",{"title":77,"path":78,"stem":79},"Education","\u002Fpeople-ops\u002Feducation","2.people-ops\u002Feducation",{"title":81,"path":82,"stem":83},"Expenses","\u002Fpeople-ops\u002Fexpenses","2.people-ops\u002Fexpenses",{"title":85,"path":86,"stem":87},"Holiday & Leave","\u002Fpeople-ops\u002Fleave","2.people-ops\u002Fleave",{"title":89,"path":90,"stem":91},"Onboarding","\u002Fpeople-ops\u002Fonboarding","2.people-ops\u002Fonboarding",{"title":93,"path":94,"stem":95},"Recruitment","\u002Fpeople-ops\u002Frecruitment","2.people-ops\u002Frecruitment",{"title":97,"path":98,"stem":99,"children":100,"page":62},"Engineering","\u002Fengineering","3.engineering",[101,105,109,113,125,146,150,154,158],{"title":102,"path":103,"stem":104},"Development Setup","\u002Fengineering\u002Fdevelopment-setup","3.engineering\u002F1.development-setup",{"title":106,"path":107,"stem":108},"Contributing","\u002Fengineering\u002Fcontributing","3.engineering\u002Fcontributing",{"title":110,"path":111,"stem":112},"Production Database","\u002Fengineering\u002Fdatabase-connection","3.engineering\u002Fdatabase-connection",{"title":114,"path":115,"stem":116,"children":117},"Deployment","\u002Fengineering\u002Fdeployment","3.engineering\u002Fdeployment",[118,121],{"title":55,"path":119,"stem":120},"\u002Fengineering\u002Fdeployment\u002Fcapability-exchange","3.engineering\u002Fdeployment\u002Fcapability-exchange",{"title":122,"path":123,"stem":124},"Platform","\u002Fengineering\u002Fdeployment\u002Fplatform","3.engineering\u002Fdeployment\u002Fplatform",{"title":126,"path":127,"stem":128,"children":129,"page":62},"Github","\u002Fengineering\u002Fgithub","3.engineering\u002Fgithub",[130,134,138,142],{"title":131,"path":132,"stem":133},"Packages","\u002Fengineering\u002Fgithub\u002Fpackages","3.engineering\u002Fgithub\u002Fpackages",{"title":135,"path":136,"stem":137},"Personal Access Token","\u002Fengineering\u002Fgithub\u002Fpersonal-access-token","3.engineering\u002Fgithub\u002Fpersonal-access-token",{"title":139,"path":140,"stem":141},"Troubleshooting","\u002Fengineering\u002Fgithub\u002Ftroubleshooting","3.engineering\u002Fgithub\u002Ftroubleshooting",{"title":143,"path":144,"stem":145},"Workflows","\u002Fengineering\u002Fgithub\u002Fworkflows","3.engineering\u002Fgithub\u002Fworkflows",{"title":147,"path":148,"stem":149},"Platform Ops","\u002Fengineering\u002Fplatform-ops","3.engineering\u002Fplatform-ops",{"title":151,"path":152,"stem":153},"Project Management","\u002Fengineering\u002Fproject-management","3.engineering\u002Fproject-management",{"title":155,"path":156,"stem":157},"Releases","\u002Fengineering\u002Frelease","3.engineering\u002Frelease",{"title":159,"path":160,"stem":161},"Tools","\u002Fengineering\u002Ftools","3.engineering\u002Ftools",{"title":163,"path":164,"stem":165,"children":166,"page":62},"Design","\u002Fdesign","4.design",[167,171,175,179,182],{"title":168,"path":169,"stem":170},"Branding","\u002Fdesign\u002Fbranding","4.design\u002Fbranding",{"title":172,"path":173,"stem":174},"Design Thinking","\u002Fdesign\u002Fdesign-thinking","4.design\u002Fdesign-thinking",{"title":176,"path":177,"stem":178},"Figma","\u002Fdesign\u002Ffigma-structure","4.design\u002Ffigma-structure",{"title":159,"path":180,"stem":181},"\u002Fdesign\u002Ftools","4.design\u002Ftools",{"title":183,"path":184,"stem":185},"Customer Success","\u002Fdesign\u002Fworking-with-customers","4.design\u002Fworking-with-customers",{"title":187,"path":188,"stem":189,"children":190,"page":62},"Sales","\u002Fsales","4.sales",[191,195],{"title":192,"path":193,"stem":194},"Customer Onboarding","\u002Fsales\u002Fonboarding","4.sales\u002Fonboarding",{"title":196,"path":197,"stem":198},"Sales Tools","\u002Fsales\u002Ftools","4.sales\u002Ftools",{"title":200,"path":201,"stem":202,"children":203,"page":62},"Marketing","\u002Fmarketing","5.marketing",[204,208,212],{"title":205,"path":206,"stem":207},"Content","\u002Fmarketing\u002Fcontent","5.marketing\u002Fcontent",{"title":209,"path":210,"stem":211},"Messaging","\u002Fmarketing\u002Fmessaging","5.marketing\u002Fmessaging",{"title":213,"path":214,"stem":215},"Website","\u002Fmarketing\u002Fwebsite","5.marketing\u002Fwebsite",{"title":217,"path":218,"stem":219,"children":220,"page":62},"AI & Data Ops","\u002Fdata-ops","6.data-ops",[221,229,233,258,271],{"title":55,"path":222,"stem":223,"children":224,"page":62},"\u002Fdata-ops\u002Fcapability-exchange","6.data-ops\u002FCapability Exchange",[225],{"title":226,"path":227,"stem":228},"Leaderboard Calculation","\u002Fdata-ops\u002Fcapability-exchange\u002Fleaderboard-calculation","6.data-ops\u002FCapability Exchange\u002Fleaderboard-calculation",{"title":230,"path":231,"stem":232},"Account Portal (CAS)","\u002Fdata-ops\u002Faccount-portal","6.data-ops\u002Faccount-portal",{"title":234,"path":235,"stem":236,"children":237,"page":62},"Data Management","\u002Fdata-ops\u002Fdata-management","6.data-ops\u002Fdata-management",[238,242,246,250,254],{"title":239,"path":240,"stem":241},"Adding Products","\u002Fdata-ops\u002Fdata-management\u002Fadding-products","6.data-ops\u002Fdata-management\u002Fadding-products",{"title":243,"path":244,"stem":245},"Adding Vendors","\u002Fdata-ops\u002Fdata-management\u002Fadding-vendors","6.data-ops\u002Fdata-management\u002Fadding-vendors",{"title":247,"path":248,"stem":249},"Framework Mapping","\u002Fdata-ops\u002Fdata-management\u002Fframework-mapping","6.data-ops\u002Fdata-management\u002Fframework-mapping",{"title":251,"path":252,"stem":253},"Refreshing Vendors","\u002Fdata-ops\u002Fdata-management\u002Frefreshing-vendors","6.data-ops\u002Fdata-management\u002Frefreshing-vendors",{"title":255,"path":256,"stem":257},"Reviewing Draft Vendors","\u002Fdata-ops\u002Fdata-management\u002Freviewing-draft-vendors","6.data-ops\u002Fdata-management\u002Freviewing-draft-vendors",{"title":259,"path":260,"stem":261,"children":262,"page":62},"LLM Ops","\u002Fdata-ops\u002Fllm-ops","6.data-ops\u002Fllm-ops",[263,267],{"title":264,"path":265,"stem":266},"Agents","\u002Fdata-ops\u002Fllm-ops\u002Fagents","6.data-ops\u002Fllm-ops\u002F1.agents",{"title":268,"path":269,"stem":270},"ESPi Architecture & Query Flow","\u002Fdata-ops\u002Fllm-ops\u002Fespi-architecture","6.data-ops\u002Fllm-ops\u002F2.espi-architecture",{"title":272,"path":273,"stem":274},"Message Queues","\u002Fdata-ops\u002Fmessage-queues","6.data-ops\u002Fmessage-queues",{"title":276,"path":277,"stem":278},"Glossary","\u002Fglossary","glossary",{"id":280,"title":135,"body":281,"description":736,"extension":839,"links":840,"meta":841,"navigation":622,"path":136,"seo":842,"stem":137,"__hash__":843},"docs\u002F3.engineering\u002Fgithub\u002Fpersonal-access-token.md",{"type":282,"value":283,"toc":820},"minimark",[284,289,293,296,299,303,312,315,349,352,363,380,382,389,396,401,462,466,469,529,550,552,556,561,611,623,625,629,675,677,681,684,717,721,727,737,741,745,751,755,774,776,780],[285,286,288],"h2",{"id":287},"personal-access-tokens-pats","Personal Access Tokens (PATs)",[290,291,292],"p",{},"A Personal Access Token (PAT) is used to authenticate with GitHub in place of a password — for example, when pulling private packages, publishing packages, or using the GitHub API from scripts and CI\u002FCD pipelines.",[290,294,295],{},"GitHub offers two types of PATs:",[297,298],"hr",{},[285,300,302],{"id":301},"token-types","Token Types",[304,305,307,308],"h3",{"id":306},"fine-grained-tokens-recommended-for-most-tasks","Fine-grained Tokens ",[309,310,311],"em",{},"(recommended for most tasks)",[290,313,314],{},"Fine-grained tokens are the newer, more secure token format introduced by GitHub. They offer:",[316,317,318,326,337,343],"ul",{},[319,320,321,325],"li",{},[322,323,324],"strong",{},"Repository-scoped access"," — you select exactly which repositories the token can access, rather than granting access to everything.",[319,327,328,331,332,336],{},[322,329,330],{},"Granular permissions"," — instead of broad scopes (e.g. ",[333,334,335],"code",{},"repo","), you choose specific read\u002Fwrite permissions per resource (Issues, Pull Requests, Contents, etc.).",[319,338,339,342],{},[322,340,341],{},"Expiry enforcement"," — fine-grained tokens require an expiry date (maximum 1 year).",[319,344,345,348],{},[322,346,347],{},"Owner approval"," — if your organisation enforces it, tokens may require admin approval before they become active.",[290,350,351],{},"Fine-grained tokens are ideal for:",[316,353,354,357,360],{},[319,355,356],{},"Accessing or cloning specific repositories",[319,358,359],{},"Operating GitHub Actions with least-privilege access",[319,361,362],{},"Anything where limiting blast radius is important",[364,365,366],"blockquote",{},[290,367,368,371,372,375,376,379],{},[322,369,370],{},"Limitation:"," Fine-grained tokens ",[322,373,374],{},"cannot"," currently authenticate against the ",[322,377,378],{},"GitHub Packages \u002F npm registry",". If your task involves installing or publishing packages, you must use a Classic token.",[297,381],{},[304,383,385,386],{"id":384},"classic-tokens-required-for-github-packages","Classic Tokens ",[309,387,388],{},"(required for GitHub Packages)",[290,390,391,392,395],{},"Classic tokens use a broad, scope-based permission model and have been available since GitHub's early API days. While less granular than fine-grained tokens, they are currently the ",[322,393,394],{},"only supported token type"," for GitHub Packages authentication.",[397,398,400],"h4",{"id":399},"when-you-must-use-a-classic-token","When you must use a Classic token",[402,403,404,417],"table",{},[405,406,407],"thead",{},[408,409,410,414],"tr",{},[411,412,413],"th",{},"Use Case",[411,415,416],{},"Classic Token Required?",[418,419,420,436,447,454],"tbody",{},[408,421,422,433],{},[423,424,425,428,429,432],"td",{},[333,426,427],{},"npm install"," \u002F ",[333,430,431],{},"yarn install"," from a private GitHub Package registry",[423,434,435],{},"✅ Yes",[408,437,438,445],{},[423,439,440,441,444],{},"Publishing a package to GitHub Packages (",[333,442,443],{},"npm publish",")",[423,446,435],{},[408,448,449,452],{},[423,450,451],{},"Reading\u002Finstalling packages in CI\u002FCD (e.g. GitHub Actions, local dev)",[423,453,435],{},[408,455,456,459],{},[423,457,458],{},"General GitHub API access or repository operations",[423,460,461],{},"❌ Fine-grained preferred",[397,463,465],{"id":464},"required-scopes-for-package-work","Required scopes for package work",[290,467,468],{},"When creating a Classic token for package consumption or development, select the following scopes:",[402,470,471,481],{},[405,472,473],{},[408,474,475,478],{},[411,476,477],{},"Scope",[411,479,480],{},"Purpose",[418,482,483,493,503,516],{},[408,484,485,490],{},[423,486,487],{},[333,488,489],{},"read:packages",[423,491,492],{},"Download \u002F install packages from the GitHub Package Registry",[408,494,495,500],{},[423,496,497],{},[333,498,499],{},"write:packages",[423,501,502],{},"Publish packages to the GitHub Package Registry",[408,504,505,509],{},[423,506,507],{},[333,508,335],{},[423,510,511,512,515],{},"Required when the package repository is ",[322,513,514],{},"private"," — allows the registry to verify access",[408,517,518,523],{},[423,519,520],{},[333,521,522],{},"delete:packages",[423,524,525,528],{},[309,526,527],{},"(Optional)"," Remove package versions you own",[364,530,531],{},[290,532,533,536,537,540,541,543,544,546,547,549],{},[322,534,535],{},"Tip:"," If you only need to ",[322,538,539],{},"consume"," (install) packages and not publish them, ",[333,542,489],{}," + ",[333,545,335],{}," is sufficient. Only add ",[333,548,499],{}," if you are actively developing and publishing packages.",[297,551],{},[285,553,555],{"id":554},"how-to-create-a-classic-token","How to Create a Classic Token",[364,557,558],{},[290,559,560],{},"This is the token type you will need for local development and CI\u002FCD package access.",[562,563,564,575,590,597,604],"ol",{},[319,565,566,567,574],{},"Go to ",[568,569,573],"a",{"href":570,"rel":571},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Ftokens\u002Fnew",[572],"nofollow","GitHub Tokens (Classic)"," — ensure you are logged into the correct account.",[319,576,577,578,581,582,585,586,589],{},"Give the token a descriptive ",[322,579,580],{},"Note",", e.g. ",[333,583,584],{},"Package Development"," or ",[333,587,588],{},"Package Read-Only",".",[319,591,592,593,596],{},"Set an ",[322,594,595],{},"Expiration"," — choose an appropriate window (e.g. 90 days). Avoid \"No expiration\" for security reasons.",[319,598,599,600,603],{},"Under ",[322,601,602],{},"Select scopes",", tick the scopes relevant to your use case (see table above).",[319,605,606,607,610],{},"Click ",[322,608,609],{},"Generate token"," and copy it immediately — GitHub will not show it again.",[612,613],"iframe",{"width":614,"height":615,"src":616,"className":617,"title":619,"frameBorder":620,"allow":621,"allowFullScreen":622},560,315,"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FWJI2V86zs2A",[618],"mx-auto","YouTube video player","0","accelerometer;",true,[297,624],{},[285,626,628],{"id":627},"how-to-create-a-fine-grained-token","How to Create a Fine-grained Token",[562,630,631,638,643,648,654,664,670],{},[319,632,566,633,574],{},[568,634,637],{"href":635,"rel":636},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Fpersonal-access-tokens\u002Fnew",[572],"GitHub Fine-grained Tokens",[319,639,577,640,589],{},[322,641,642],{},"Token name",[319,644,592,645,647],{},[322,646,595],{}," (required — up to 365 days).",[319,649,599,650,653],{},[322,651,652],{},"Resource owner",", select the organisation or your personal account.",[319,655,599,656,659,660,663],{},[322,657,658],{},"Repository access",", choose ",[309,661,662],{},"Only select repositories"," and pick the repositories needed.",[319,665,599,666,669],{},[322,667,668],{},"Permissions",", expand each section and set only the minimum permissions required.",[319,671,606,672,674],{},[322,673,609],{}," and copy it immediately.",[297,676],{},[285,678,680],{"id":679},"configuring-projects-to-use-tokens","Configuring projects to use tokens",[290,682,683],{},"This setup works for both local development and CI\u002FCD pipelines.",[562,685,686,696],{},[319,687,688,689,585,692,695],{},"Configure projects to use tokens in the ",[333,690,691],{},".npmrc",[333,693,694],{},".yarnrc.yml"," files.",[319,697,698,699,702,703],{},"Set the ",[333,700,701],{},"NODE_AUTH_TOKEN"," environment variable to your Classic token when applicable in:\n",[316,704,705,711],{},[319,706,707,708],{},"GitHub Repository Secrets for ",[322,709,710],{},"CI\u002FCD pipelines",[319,712,713,714,589],{},"User Account System environment variables for ",[322,715,716],{},"local development",[304,718,720],{"id":719},"_1-for-yarn-projects","1. For Yarn Projects",[290,722,723,724,726],{},"Once you have a Classic token, configure npm to authenticate against the GitHub Package Registry by adding the following to the project-level ",[333,725,694],{},":",[728,729,734],"pre",{"className":730,"code":732,"language":733},[731],"language-text","npmScopes:\n  es-profiler:\n    npmAlwaysAuth: false\n    npmAuthToken: ${NODE_AUTH_TOKEN:-}\n    npmRegistryServer: \"https:\u002F\u002Fnpm.pkg.github.com\"\n","text",[333,735,732],{"__ignoreMap":736},"",[304,738,740],{"id":739},"_1-for-npm-projects","1. For NPM Projects",[290,742,723,743,726],{},[333,744,691],{},[728,746,749],{"className":747,"code":748,"language":733},[731],"\u002F\u002Fnpm.pkg.github.com\u002F:_authToken=${NODE_AUTH_TOKEN}\n@es-profiler:registry=https:\u002F\u002Fnpm.pkg.github.com\n",[333,750,748],{"__ignoreMap":736},[304,752,754],{"id":753},"_2-for-local-development","2. For Local Development",[364,756,757],{},[290,758,759,762,763,766,767,770,771,589],{},[322,760,761],{},"Never commit your token to source control."," Use environment variables or secrets management instead. In CI\u002FCD pipelines, store the token as a secret (e.g. ",[333,764,765],{},"GITHUB_TOKEN"," or a custom secret) and reference it in your ",[333,768,769],{},"npmrc"," via ",[333,772,773],{},"${TOKEN_ENV_VAR}",[297,775],{},[285,777,779],{"id":778},"best-practices","Best Practices",[316,781,782,788,797,808,814],{},[319,783,784,787],{},[322,785,786],{},"Rotate tokens regularly"," — set a calendar reminder before your token expires.",[319,789,790,793,794,796],{},[322,791,792],{},"Use the minimum required scopes"," — avoid ",[333,795,335],{}," on Classic tokens unless the package repository is private.",[319,798,799,802,803,589],{},[322,800,801],{},"Revoke unused tokens"," — audit your tokens periodically at ",[568,804,807],{"href":805,"rel":806},"https:\u002F\u002Fgithub.com\u002Fsettings\u002Ftokens",[572],"github.com\u002Fsettings\u002Ftokens",[319,809,810,813],{},[322,811,812],{},"Never share tokens"," — each developer and each CI\u002FCD pipeline should have its own token.",[319,815,816,819],{},[322,817,818],{},"Prefer fine-grained tokens"," for any non-package GitHub API usage.",{"title":736,"searchDepth":821,"depth":821,"links":822},2,[823,824,831,832,833,838],{"id":287,"depth":821,"text":288},{"id":301,"depth":821,"text":302,"children":825},[826,829],{"id":306,"depth":827,"text":828},3,"Fine-grained Tokens (recommended for most tasks)",{"id":384,"depth":827,"text":830},"Classic Tokens (required for GitHub Packages)",{"id":554,"depth":821,"text":555},{"id":627,"depth":821,"text":628},{"id":679,"depth":821,"text":680,"children":834},[835,836,837],{"id":719,"depth":827,"text":720},{"id":739,"depth":827,"text":740},{"id":753,"depth":827,"text":754},{"id":778,"depth":821,"text":779},"md",null,{},{"description":736},"mV45VhJHcUtyhT5mLV2CMK-EPx1m4TKfPDuvFtYUnGI",[845,846],{"title":131,"path":132,"stem":133,"description":736,"children":-1},{"title":139,"path":140,"stem":141,"description":847,"children":-1},"Troubleshooting guide for GitHub issues.",1784892032370]