The API keys I’ve used (admittedly not many) all seem to be long random text strings - how does GitHub detect them? By then being used (ie in api code) or do they actually have a known format?
Usually its junk, but occasionally you do get lucky and find tokens.