PAT is stored only in localStorage in this browser (key blog_pat), never committed. Create at GitHub → Settings → Developer settings → Personal access tokens (classic) → repo. For private writes you need repo scope.
Publish will PUT /repos/{repo}/contents/blog/posts/{slug}.md and update blog/posts.json. If file exists, it will be updated (needs SHA). Check Actions for deploy.
Post
Frontmatter will be added automatically on publish. Preview below: