For accounts without MFA enabled (which are the only ones who were able to use username/password via https in the first place), is the token granted after supplying just username and password, and if so, what's the real improvement?
I see here [0] a few benefits listed:
> Unique – tokens are specific to GitHub and can be generated per use or per device
> Revocable – tokens can can be individually revoked at any time without needing to update unaffected credentials
> Limited – tokens can be narrowly scoped to allow only the access necessary for the use case
> Random – tokens are not subject to the types of dictionary or brute force attempts that simpler passwords that you need to remember or enter regularly might be
...but if you can trivially obtain it by supplying username/password, then it's effectively equivalent anyway.
[0] https://github.blog/2020-12-15-token-authentication-requirem...