Skip to content

Document how to revoke all tokens #10095

Description

@williammartin

Description

gh auth logout help says thus:

➜  ~ gh auth logout --help
Remove authentication for a GitHub account.

This command removes the stored authentication configuration
for an account. The authentication configuration is only
removed locally.

This command does not invalidate authentication tokens.

It's a somewhat common question that people ask about revocation in some form or another:

We should update the help text on gh auth logout to indicate that to revoke CLI generated OAuth tokens they should navigate to https://github.com/settings/applications (or equivalent on their targeted host) and click the Revoke button.

Acceptance Criteria

When I run gh auth logout --help
Then I see directions on how to revoke CLI OAuth tokens, and a warning that it will revoke all the OAuth tokens.


Notes

Should we also consider adding another issue for gh auth revoke-all --really-really-I-mean-it which does this programmatically? I think it's available via an API?

Activity

  1. andyfeller commented on Feb 24, 2025

    @andyfeller
    Contributor

    Should we also consider adding another issue for gh auth revoke-all --really-really-I-mean-it which does this programmatically? I think it's available via an API?

    @williammartin : I'm unsure if the OAuth authorization REST APIs are designed for anyone outside of the OAuth application owner to reset or delete a token, meaning I'm unsure if users can do it themselves. 🤔

  2. BagToad commented on Feb 24, 2025

    @BagToad
    Member

    Should we also consider adding another issue for gh auth revoke-all --really-really-I-mean-it which does this programmatically? I think it's available via an API?

    @williammartin : I'm unsure if the OAuth authorization REST APIs are designed for anyone outside of the OAuth application owner to reset or delete a token, meaning I'm unsure if users can do it themselves. 🤔

    FWIW, my understanding was the same: only the owner can do it from the API and users cannot.

  3. williammartin commented on Feb 25, 2025

    @williammartin
    MemberAuthor

    Good to know, thank you.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementa request to improve CLIgh-authrelating to the gh auth commandneeds-triageneeds to be reviewed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions