Skip to content
git-credential-oauth

git-credential-oauth

git-credential-oauth is a Git credential helper. When an HTTPS remote asks for credentials and nothing is stored, it signs you in to the forge with OAuth, in a browser or with a device code, and hands the token to Git. Git then keeps it in whichever storage helper you already use.

[credential]
    helper =
    helper = libsecret
    helper = oauth

The storage helper comes first, so a stored token is used without any prompt. This helper runs only when nothing usable is stored: the first time you use a host, and again when the stored token has expired and cannot be refreshed.

Why OAuth

A personal access token is a long-lived secret you create by hand, paste into a prompt, and rotate yourself. An OAuth token is issued on demand to an application you approved, can be short-lived and refreshed automatically, and is revoked from the forge’s settings like any other authorized app. You never handle the token.

What you need

RequirementDetail
Git2.41 or later; 2.45 or later recommended. See Git versions.
A storage helperlibsecret, osxkeychain, wincred, or cache. See Storage.
An OAuth application on each forgeYou register your own; Gitea and Forgejo need none. See Forges.
A browser, or the device grantGitHub and GitLab support the device grant for machines without a browser.

Quick start

curl -sSfL https://raw.githubusercontent.com/nicholas-fedor/git-credential-oauth/main/scripts/install.sh | sh

The script installs the program and runs git-credential-oauth configure, unless a credential.helper is already set or it is running as root.

Then register an OAuth application on the forge and record it. For GitHub:

git config --global credential.https://github.com.oauthClientId <client id>
git config --global credential.https://github.com.oauthClientSecret <client secret>

Getting started walks through every step.

Documentation

License

AGPL-3.0-or-later. This is an independent implementation of the design of hickford/git-credential-oauth.