Skip to content

Support multiple fine-grained tokens for gh auth switch #12888

Description

@deviantintegral

Describe the feature or problem you’d like to solve

Fine-grained tokens are a great way to limit access to automated tools and AIs by repository and permission. However, each fine-grained token can only be associated with a single GitHub organization. That means that if you want to use a single GitHub CLI instance to interact with multiple organizations, you can't. Since the CLI is limited to a single token, it also means that concurrent processes can't be using the CLI to communicate to different organizations in parallel.

Proposed solution

Add --add-token as an option when using --with-token. When specified, this will add the new token instead of replacing it. As well, add the organization name or ID to the hosts.yaml file for the token so the gh CLI tool can automatically use the right token.

Activity

  1. github-actions commented on Mar 9, 2026

    @github-actions
    Contributor

    Thank you for your issue! We have categorized it as an enhancement (feature or improvement) request, and it has been added to our backlog. In doing so, we are not committing to implementing this feature at this time, but, we will consider it for future releases based on community feedback and our own product roadmap.

    Unless you see the help wanted Contributions welcome label, we are not currently looking for external contributions for this feature.

    If you come across this issue and would like to see it implemented, please add a thumbs up! This will help us prioritize the feature. Please only comment if you have additional information or viewpoints to contribute.

  2. added
    gh-authrelating to the gh auth command
    and removed on Mar 9, 2026
  3. deviantintegral commented on Mar 9, 2026

    @deviantintegral
    Author

    I was able to work around this by using https://direnv.net/. However, it works best when you have project directories or git checkouts for the .envrc or .env file to exist in, which wouldn't help cases where a user is calling gh directly with nothing locally other than the gh args to identify what token to use.

  4. sharptank-au commented on Apr 1, 2026

    @sharptank-au

    Having issues on gh auth switch doesn't pick up second account, it was stuck in the first authentificated account, any suggestions to fix that on mac

  5. rastaman commented on Jul 23, 2026

    @rastaman

    I know it will not be merged but in case it helps i have implemented this branch: rastaman#1 (with Opus and Cursor) to implement what is described here. I have done it, and added a possibility to sync a fork with upstream from 2 auths, because my day-to-day employer disabled PAT and only allowed FAT and it brokes some of my workflows with gh. I really don't say it perfect but it does the job for me.

    HtH, my 2 cents

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementa request to improve CLIgh-authrelating to the gh auth commandstale

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions