Revoke Forgotten OAuth Apps and Kill Never-Expiring GitHub Tokens Before They Leak

eyishazyer · x · 2026-09-17

Part 3 of a GitHub security thread: revoke unrecognized OAuth apps—every authorization persists until manually pulled, and most people have five or six forgotten ones sitting in Settings → Applications. Quoted part 2: delete never-expiring classic PATs sitting in old config files, the typical cause of accounts compromised months later; replace with scoped fine-grained tokens.

Related event: GitHub Security Tips: Revoke Forgotten Apps and Protect Main Branch(2 posts)→

Original post →

More from coding & agent

coding & agent channel →