No user should create a personal access token with full permissions and hand it over to a third party developer. Users of this application essentially trust the developers of this app to do whatever they want with their own permissions. The developers could download the entirety of projects within the organization or even delete/modify them however they see fit. Login should rather go through OAuth consent, thus allowing tenant administrators to consent to their users using this application, e.g. after a background check of the company making this application. Furthermore lack of use of OAuth for sign in has me doubt the effectiveness of the developers; making me trust this app even less.
Show more
Response from developer
Thank you for kind comments.
The token is stored locally on your device. We have no interest in them. Be assured that the token is not misused since itโs stored on your device itself.
Thank you for your kind support.