https://github.com/settings/tokens/new
Select only the scopes needed for the task.
repo: Used to access private repositories with a classic token. It includes write access as well as read access, so handle the token carefully.read:org: Select this when organization and team membership must be read.project,write:org: These allow changes to projects or organizations. Do not add them as default permissions merely to read repository source code.
Check the token types supported by your installation and your organization's policy, and set an expiration date.