The session
A browser session uses a cookie that isHttpOnly and SameSite=Lax. In production the cookie is also Secure, so the browser sends it only over HTTPS. JavaScript on the page cannot read the cookie.
A request that changes data from the browser also has to present a CSRF token from GET /api/csrf. A request that authenticates with Authorization: Bearer is not a cookie session, so it is not checked with that CSRF token. The token itself is the credential. GitHub webhooks are checked with the signature described on GitHub, not with a session.
Signing out ends that session. A person or an organization that has been removed can no longer sign in. A removed email cannot be registered again.