GitHub's REST API: Scaling Millions of Webhooks & Scoped Auth
GitHub handles billions of daily API requests across millions of repositories. Learn how they maintain low latencies using fine-grained PAT tokens, conditional caching, and asynchronous webhook delivery.
1. Conditional HTTP Caching with ETags (304 Not Modified)
GitHub returns a cryptographic ETag header on every read response. When client tools (like CI scripts or pollers) request the resource again with If-None-Match: <etag>, GitHub verifies the hash in cache and returns an empty 304 Not Modified status, saving gigabytes of egress bandwidth.
2. Webhook Security: SHA-256 HMAC Signatures
To prevent spoofing, every webhook payload sent by GitHub includes an X-Hub-Signature-256 header. Consumers compute an HMAC digest over the raw request body using their shared webhook secret. If the digests match using constant-time comparison, the event is authentic.
