The token needs Projects: read & write (an account permission) and Issues: read & write on the repos it should reach β a classic PAT with project + repo covers both, and only that kind can delete an issue outright. It is stored in this browser's localStorage and sent only to api.github.com. This page is public; the token in your own browser is the only thing that makes it yours.