Share your GitHub rate limit
When mise installs a tool, it often has to ask GitHub for that project's releases and checksums. Without a token GitHub allows only 60 of those requests an hour, which a busy laptop or a shared CI machine can burn through quickly. mise versions answers those questions for everyone instead, so mise users don't have to hit the GitHub API themselves. To do that we need GitHub tokens of our own, and we borrow a little headroom from people who are happy to lend it.
Why we need it
mise's aqua, github and packslip backends install tools straight from GitHub releases. Rather than every mise user calling the GitHub API directly, they ask mise versions, which makes the call once with a pooled token, caches the answer and serves it to everyone. That's what keeps all of mise's users clear of GitHub's rate limits. Anonymous requests get 60 per hour; a token gets 5,000.
The same pool refreshes this site's version lists (mise ls-remote for the 1,055 tools we track, about every 30 minutes) and runs mise's end-to-end tests.
One account can't keep up with all of that. Without other people's tokens, lookups would stall for everyone. Spreading the work across a pool keeps us well clear of the limits and keeps each person's share small enough that you won't notice it. It also means one revoked or busy token doesn't hold things up for anyone else.
Rough numbers
- Tools tracked
- 1,055
- People sharing
- 1,012
- Update runs per day
- ~48
- Tokens lent out, all time
- 13.0m
These figures come live from the token pool and are cached for a few minutes. A “lend” is one time a token was borrowed for a lookup.
How it works
- You click “Sign in with GitHub.” GitHub shows its standard authorization screen. We never see your password.
- GitHub gives us an OAuth token. We store it, with your username, in our database, along with a few timestamps and a usage counter.
- Our servers borrow it. Before each lookup we pick the least recently used token, so the load rotates evenly across everyone. The borrowers are the GitHub mirror that mise uses (releases, checksums and attestations for the
aqua,githubandpackslipbackends), the job that refreshes version lists, and mise's own end-to-end tests. - It's used to read public data. The calls list releases and tags, and fetch release and attestation details, on public repositories. In the update job the token is masked in the logs.
- We leave you plenty. If your token has 4,000 or fewer of its 5,000 hourly requests left, we don't touch it until GitHub resets the hour. That holds no matter who used them up, whether it was us, you, or another app on your account. In practice we use far less than the difference. The one exception is a genuine emergency, when every token in the pool is that low and updates would otherwise stall. Then we may borrow from one that still has more than 1,000 left, and the maintainer gets an alert so it gets sorted out.
Signed in, you also get fresher repository details (stars, license, last push) on tool pages, fetched with your own token.
What we store
- Your GitHub username and display name
- The email on your GitHub profile, only if you've made one public
- Your OAuth token (and its refresh token and expiry, if GitHub issues them)
- When the token was last used, how many times, and whether it is currently rate limited
The token lives in our server-side database and is never sent to your browser or shown on any page. It is sent over HTTPS to the update job so it can call GitHub; apart from that, only our servers use it, and only to call GitHub. Your browser only gets a signed cookie saying who you are. We don't sell, share or email anything.
What the token can do
We ask GitHub for no permissions at all. The authorization screen only says it will read your public profile. A token like that can read public information, the same as anyone browsing GitHub, but with the higher rate limit. It can't change anything, and it can't see your private repositories, organizations, or account settings.
The code is open source if you want to check: the sign-in redirect, the callback, the token endpoint and the update script.
Taking it back
You can stop sharing at any time. Open GitHub → Settings → Applications, find the mise versions app under Authorized OAuth Apps, and choose Revoke. GitHub rejects the token immediately, so it can't be used again.
Note that Sign out on this site only clears the cookie in your browser. To remove the token itself, revoke it on GitHub.