The official GitHub CLI tool (or desktop app) and authenticate via a web browser, it uses an authentication token that is not visible or revokable anywhere in your account. When I reported this through the bug bounty program, I was told this is by design!
Any application or token with access to the account should appear in the list of account tokens — including for GitHub applications. Each listing should Include the application name, the user agent that added it, UTC timestamps for when the token was created and last used, and a big button to revoke it. An email should also be sent when a token is created.
The official GitHub CLI tool (or desktop app) and authenticate via a web browser, it uses an authentication token that is not visible or revokable anywhere in your account. When I reported this through the bug bounty program, I was told this is by design!
Any application or token with access to the account should appear in the list of account tokens — including for GitHub applications. Each listing should Include the application name, the user agent that added it, UTC timestamps for when the token was created and last used, and a big button to revoke it. An email should also be sent when a token is created.