Skip to content

gh auth logout does not erase and/or revoke OAuth token in MacOS Keychain #13111

Description

@fproulx-boostsecurity

Describe the bug

On MacOS, using gh with OSX Keychain, gh auth logout does not erase the token from keychain.

Affected version

gh version
gh version 2.89.0 (2026-03-26)
https://github.com/cli/cli/releases/tag/v2.89.0

Steps to reproduce the behavior

❯ printf "protocol=https\nhost=github.com\n" | git credential-osxkeychain erase
❯ printf 'protocol=https\nhost=github.com\n\n' | git credential-osxkeychain get |grep password
❯ gh auth login
? Where do you use GitHub? GitHub.com
? What is your preferred protocol for Git operations on this host? HTTPS
? Authenticate Git with your GitHub credentials? Yes
? How would you like to authenticate GitHub CLI? Login with a web browser

! First copy your one-time code: XXXX-XXXX
Press Enter to open https://github.com/login/device in your browser...
✓ Authentication complete.
- gh config set -h github.com git_protocol https
✓ Configured git protocol
✓ Logged in as xxxxxxxxxx
❯ printf 'protocol=https\nhost=github.com\n\n' | git credential-osxkeychain get |grep password
password=gho_XXXXXXXXXXXXXXXXX
❯ gh auth logout
✓ Logged out of github.com account xxxxxxxxxx
❯ printf 'protocol=https\nhost=github.com\n\n' | git credential-osxkeychain get |grep password
password=gho_XXXXXXXXXXXXXXXXX

Expected vs actual behavior

I expect, at the very least, the OAuth token to be removed from MacOS keychain, ideally revoked using REST API.

Activity

  1. babakks commented on May 11, 2026

    @babakks
    Member

    Thanks for reporting this, @fproulx-boostsecurity! 🙏

    This is a valid bug. When you answer "Yes" to "Authenticate Git with your GitHub credentials?" during gh auth login, we store the token in your configured git credential helper (in your case, osxkeychain) via git credential approve. However, gh auth logout only clears credentials from our own internal storage and never calls git credential reject to clean up what we put in the external helper.

    Interestingly, we already call git credential reject during login (to clear any previously stored credential before writing the new one), so the mechanism is there. We just need to also invoke it on logout.

    One edge case worth noting: git credential reject removes credentials by protocol and host, so if someone manually replaced the credential in the external helper after gh auth login, calling reject on logout would remove that too. In practice though, this is a super unlikely scenario, and since the login flow already overwrites any pre-existing credentials for that slot, it's safer to proceed with the rejection on logout for consistency.

    In the meantime, you can work around this by running gh auth setup-git, which configures gh itself as the credential helper for GitHub hosts. That way, git delegates credential lookups to gh, and logout works as expected because there's nothing stored externally to clean up.

  2. added
    bugSomething isn't working
    priority-3Affects a small number of users or is largely cosmetic
    gh-authrelating to the gh auth command
    on May 11, 2026
  3. added
    authrelated to tokens, authentication state, or oauth
    on May 11, 2026
  4. babakks commented on May 18, 2026

    @babakks
    Member

    I just made a draft PR (#13450) for this. I haven't fully checked it yet, but feel free to review and if it looks sound to you try building gh and test it, @fproulx-boostsecurity.

  5. self-assigned this
    on May 18, 2026
  6. fproulx-boostsecurity commented on May 26, 2026

    @fproulx-boostsecurity
    Author

    Thanks @babakks !

  7. sds commented on Sep 5, 2026

    @sds

    @babakks I opened #14362 to address both revocation and keychain cleanup, but I'm being told it doesn't satisfy requirements since it doesn't reference a help wanted issue. I also referenced #9233 but that also doesn't have help wanted.

    If you can clarify whether that's a hard requirement or something that can be worked around, would really appreciate it. The PR has very clear documentation on how to test.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

authrelated to tokens, authentication state, or oauthbugSomething isn't workinggh-authrelating to the gh auth commandpriority-3Affects a small number of users or is largely cosmeticstale

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions