Then generate API keys on a per project reducing the attack surface in the case of breach?
The granularity of Personal access tokens scopes is focused on what kind of actions you can perform on which kind of objects, but you cannot limit it to one single repository or to one single organization you belong.
~~Although it seems PATs are ~42 bits, which seems a little low~~
https://help.github.com/en/github/authenticating-to-github/c...
Just think of all the online sites that offer to verify or do something else that openssl can do if you paste your cert and private key. Most devs by now know not to do that with a password or API key, but it's the first thing people will do with private keys.
Yet every Github user is expected to generate a ssh keypair and copy/paste the public key when setting up the account.
> Most devs by now know not to do that with a password or API key, but it's the first thing people will do with private keys.
But they can handle submitting the ssh public key without any issue. Also, they most likely are not using online tools to generate their ssh key pair. I don't see why they would do that with openssl.