I'm surprised they are not identifying the service in the token. A lot of services are scanning GitHub for committed tokens, and being able to tell if that token is a fake/testing one or a real one for a specific company would make those scans more useful.
For example, SendGrid tokens start with "SG", Amazon tokens with "AKIA", etc. Why not build that into the URL scheme?
This scheme will have services stick to well-known unformatted prefixes in the token itself, and prevent small actors from being notified by GitHub and other security scanners.