If you're wiring GitHub access into AI agents, this removes long-lived personal access tokenThe chunk of text a model reads and writes in — roughly three-quarters of a word — and the unit AI usage is billed in.Full definition → from your deployment: the SDK mints short-lived tokens scoped to a preset like code-review or issue-triage, and on Vercel it authenticates via OIDC with no secrets to store. That's a tighter least-privilege story than the usual 'paste a PAT into env vars' approach for AI agentAn AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.Full definition → tools.
Terms in this piece · Glossary
token — The chunk of text a model reads and writes in — roughly three-quarters of a word — and the unit AI usage is billed in.
AI agent — An AI system that doesn't just answer once but works toward a goal in a loop — taking actions, reading the results, and deciding what to do next.
Key quotes
“Instead of storing a long-lived personal access token, your agent mints short-lived, scoped GitHub tokens at runtime from a connector. There is no secret to store, rotate, or leak.”
“Presets such as code-review , issue-triage , and maintainer map to Connect scopes automatically, so tokens carry only the permissions the toolset needs.”