Skip to content

Allow multiple account credentials #326

Description

@ncmans

Describe the feature or problem you’d like to solve

I have two accounts on github each with access to a different set of private repositories. Currently I use a combination of git's [IncludeIf ...] config and a custom config which overrides the SSH private key I use for certain repositories. E.g.:

In ~/.gitconfig:

[includeIf "gitdir:~/work/"]
  path = ~/work/.gitconfig

and in ~/work/.gitconfig:

[core]
  sshCommand = "ssh -i ~/.ssh/work"

It will be great if the credentials for gh can also be configured per repository as well.

Proposed solution

There are a bunch of options I can think of:

  • Allow overriding gh config by a file in a local clone's .git directory
  • Allow defining rules in the gh config which defines which repos/orgs should use which credential. E.g.
github.com/google:
  - user: gemployee
    oauth_token: ...

github.com/microsoft:
  - user: msemployee
    oauth_token: ...

github.com:
  - user: personal
    oauth_token: ...

How will it benefit CLI and its users?

It will allow Github users with multiple accounts of varying access to seamlessly work on different repositories.

Activity

  1. eXamadeus commented on May 4, 2020

    @eXamadeus

    Is there currently a way to work around this by removing the current authentication? I can't seem to find it.

    Reinstalling seems to work, but it's very cumbersome.

  2. mislav commented on May 4, 2020

    @mislav
    Contributor

    @eXamadeus GitHub CLI currently has no mechanism for switching between multiple GitHub accounts and I don't really have a workaround to suggest for you at this moment, sorry.

    The only approach I could imagine, but would not recommend to anyone, would be to authenticate with 1st account, save a copy of ~/.config/gh/hosts.yml somewhere & delete the original file, authenticate again with the 2nd account, and now you can swap the ~/.config/gh/hosts.yml file with the backup file when you need to switch accounts.

    Since this solution involves using SSH for git protocol, make sure both configuration files include the git_protocol: ssh line.

  3. added
    authrelated to tokens, authentication state, or oauth
    on Aug 13, 2020
  4. aitchkhan commented on Sep 18, 2020

    @aitchkhan

    If we can add two entries or as many entries on every gh auth login. It might become easier with something like this:

    github.com:
        user: aitchkhan
        oauth_token: xxx
        user: haroonKhan-10p
        oauth_token: xxx
        git_protocol: ssh
    

    If the cli can somehow sense which username the current repository is associated to. It would be easy to find the user in the hosts.yml and rest would be magic.

    PS: I have not gone through the codebase. These are my assumptions.

  5. seed-of-apricot commented on Sep 30, 2020

    @seed-of-apricot

    Searched and landed here. This feature would help people with two or more accounts (personal/business/others) and use both of them every day (swapping the config file would be too much for them).

  6. added
    coreThis issue is not accepting PRs from outside contributors
    on Sep 30, 2020
  7. fdm1 commented on Sep 30, 2020

    @fdm1

    It's a bit hacky, but I solved this so that I could evaluate if I want to actually use this cli by using the token auth capabilities, putting this into my dotfiles.

    alias gh_cli=$(which gh)
    function gh() {
      if [[ $(pwd) =~ {PATH_TO_PERSONAL_CODE} ]]; then
        GITHUB_TOKEN=$PERSONAL_GH_CLI_TOKEN
      else
        GITHUB_TOKEN=$WORK_GH_CLI_TOKEN
      fi
    
      GITHUB_TOKEN=$GITHUB_TOKEN gh_cli $@
      unset GITHUB_TOKEN
    }
    
  8. seed-of-apricot commented on Oct 1, 2020

    @seed-of-apricot

    @fdm1 Which config file did you fill that in?

  9. fdm1 commented on Oct 1, 2020

    @fdm1

    @fdm1 Which config file did you fill that in?

    Just in my bash dotfiles

  10. tomholford commented on Dec 15, 2020

    @tomholford

    Now that #2179 has been merged, perhaps it will be less effort to implement this feature?

    Would be nice to have something like how git handles it:
    ~/.gitconfig

    [includeIf "gitdir:~/dev/"]
      path = ~/.gitconfig.personal
    [includeIf "gitdir:~/workspace/"]
      path = ~/.gitconfig.work
    

    ~/.gitconfig.work

    [user]
      name = example-work-user
      email = [email protected]
    

    edit

    Now that I think about it some more, can gh infer which authed account to use from the current git config user.name or email?

  11. chaoticlonghair commented on Feb 4, 2021

    @chaoticlonghair

    Since #2444 has been merged, as an alternative solution, set the environment variable GH_CONFIG_DIR to different directories could allow multiple accounts.

  12. dantonyuk commented on Mar 22, 2021

    @dantonyuk

    I just implemented simple multi-account support based on the remote.origin.url config property (of course GH_HOST is on board as well): #3278

    So having hosts.yml as

    github.com:
        user: personal-account
        oauth_token: personal-token
    github.com/acme:
        user: work-account
        oauth_token: work-token

    we use work credentials for all acme repositories and personal credentials for everything else.

    Unfortunately, gh cli uses global settings for "default" host, so I postponed the implementation of gh auth status which uses several credentials at the same time. Implemented.

  13. jeremy-ww commented on Mar 31, 2021

    @jeremy-ww

    Maybe this is a workaround if u wanna use multi credentials for a specific command. such as pr view

    /usr/local/pr2

    #!/usr/bin/python3
    
    import subprocess
    import json
    import os
    import re
    
    with open(os.path.expanduser('~/.pr-config.json')) as f:
      configs = json.load(f)
    
    command = 'gh pr view --web'
    remote_url = subprocess.check_output(['git', 'config', '--get', 'remote.origin.url']).strip().decode()
    
    for pattern, config in configs.items():
      is_match = re.match(pattern, remote_url)
      if is_match:
        os.system(
          f'GH_HOST={config["host"]} GH_ENTERPRISE_TOKEN={config["token"]} {command}'
        )
        break

    ~/.pr-config.json

    {
      "[email protected]": {
        "host": "enterprise.com",
        "token": ""
      },
      "[email protected]": {
        "host": "enterprise1.com",
        "token": ""
      }
    }
  14. thecharlesjenkins commented on Apr 13, 2021

    @thecharlesjenkins

    I am able to have multiple accounts signed in and that is nice, but one thing that I am trying to do is when I am creating a repository I would like to select my account. Doing something like gh repo create my_name/repo_name doesn't seem to work because one of my accounts is enterprise and one is public. Passing in my enterprise name like this causes HTTP 404: Not Found (https://api.github.com/users/my_enterprise_username) when I am logged into both my personal and enterprise GitHub but trying to create a repo for my private Github. This is not like a first-logged into account gets priority, no matter the order in which I log into my GitHub accounts I will receive this error when trying to create a repo for my enterprise account. Is there a way to force gh repo create to use the enterprise API instead of the public one? Right now I must log out of my personal account to create an enterprise repo unless I am doing something wrong.

  15. 101 remaining items

  16. MiK35402 commented on Jul 22, 2025

    @MiK35402
  17. MSch commented on Jul 26, 2025

    @MSch

    FYI I vibecoded a POC that already works for my needs: #11388

  18. drmercer-lucid commented on Jan 5, 2026

    @drmercer-lucid

    I've tried a few different workarounds for this, and ended up just writing a little script and putting it on my path as gh, overriding the actual gh executable. This way, any other scripts/tools that call gh will first switch the user appropriately. This script sets the user based on the presence of a string in the current path, but you can customize the logic here however you want.

    #!/usr/bin/env bash
    
    # Set the gh user based on the repo being accessed
    
    if [[ "$PWD" == *acme* ]]; then
        # use myusername2 for acme repos
        /usr/bin/gh auth switch -u myusername2 >/dev/null 2>&1
    else
        # otherwise use myusername1
        /usr/bin/gh auth switch -u myusername1  >/dev/null 2>&1
    fi
    
    /usr/bin/gh "$@"
  19. dotnvo commented on Feb 24, 2026

    @dotnvo

    I believe this is supported now with gh auth switch:

    gh --version
    gh version 2.67.0 (2025-02-11)
    https://github.com/cli/cli/releases/tag/v2.67.0

    gh auth switch --help
    Switch the active account for a GitHub host.

    This command changes the authentication configuration that will
    be used when running commands targeting the specified GitHub host.

    If the specified host has two accounts, the active account will be switched
    automatically. If there are more than two accounts, disambiguation will be
    required either through the --user flag or an interactive prompt.

    For a list of authenticated accounts you can run gh auth status.

    USAGE
    gh auth switch [flags]

    FLAGS
    -h, --hostname string The hostname of the GitHub instance to switch account for
    -u, --user string The account to switch to

    INHERITED FLAGS
    --help Show help for command

    EXAMPLES

    Select what host and account to switch to via a prompt

    $ gh auth switch

    Switch the active account on a specific host to a specific user

    $ gh auth switch --hostname enterprise.internal --user monalisa

    LEARN MORE
    Use gh <command> <subcommand> --help for more information about a command.
    Read the manual at https://cli.github.com/manual
    Learn about exit codes using gh help exit-codes
    I was able to login to multiple accounts using gh auth login and then switch between them with gh auth switch.

    Interesting, though when I do this with a Github Enterprise account, switching to the github enterprise, it tells me its now the active account, but when i run gh repo list [owner] it does not pull from my org, and still pulls from github.com.

    gh auth status
    # output shows both accounts logged in one from enterprise url and one from github.com
    gh auth switch --hostname github.xxx.xxx --user xxxxx
    #outputs:
    # ✓ Switched active account for github.xxx.xx to xxxx
    gh repo list
    # outputs personal repos on github.com - the usernames are different as well, but i'm also specifiying the host in the switch.

    Maybe something I'm still doing wrong but feels like this might be a potential issue with gh auth switch.

  20. williammartin commented on Feb 24, 2026

    @williammartin
    Member

    @dotnvo per gh auth switch help:

    This command changes the authentication configuration that will
    be used when running commands targeting the specified GitHub host.
    

    You can target a host with GH_HOST, --hostname (for some commands), or it can be inferred from git remotes in your cwd.

    From gh env:

    `GH_HOST`: specify the GitHub hostname for commands where a hostname has not been provided, or
    cannot be inferred from the context of a local Git repository. If this host was previously
    authenticated with, the stored credentials will be used. Otherwise, setting `GH_TOKEN` or
    `GH_ENTERPRISE_TOKEN` is required, depending on the targeted host.
    

    Hope this helps.

  21. eXamadeus commented on Feb 24, 2026

    @eXamadeus

    FWIW I posted the first comment on this issue nearly 6 years ago. I wanted to loop back in to say my piece. It's been nice to see all the work the GH team has done to address feature requests and customer concerns. Seriously, yall are great.

    I do believe the gh auth switch + some careful scripting would have solved my particular issue. It not fully automatic, but it did get around the awful "uninstall" loop that was the solution of the time.

    BTW, I solved this about 5 years ago. I just moved to a company that let me use one Github account with SSO, so I no longer need to switch auth from personal to work 😆!

  22. dotnvo commented on Feb 24, 2026

    @dotnvo

    @dotnvo per gh auth switch help:

    This command changes the authentication configuration that will
    be used when running commands targeting the specified GitHub host.
    

    You can target a host with GH_HOST, --hostname (for some commands), or it can be inferred from git remotes in your cwd.

    From gh env:

    `GH_HOST`: specify the GitHub hostname for commands where a hostname has not been provided, or
    cannot be inferred from the context of a local Git repository. If this host was previously
    authenticated with, the stored credentials will be used. Otherwise, setting `GH_TOKEN` or
    `GH_ENTERPRISE_TOKEN` is required, depending on the targeted host.
    

    Hope this helps.

    @dotnvo per gh auth switch help:

    This command changes the authentication configuration that will
    be used when running commands targeting the specified GitHub host.
    

    You can target a host with GH_HOST, --hostname (for some commands), or it can be inferred from git remotes in your cwd.

    From gh env:

    `GH_HOST`: specify the GitHub hostname for commands where a hostname has not been provided, or
    cannot be inferred from the context of a local Git repository. If this host was previously
    authenticated with, the stored credentials will be used. Otherwise, setting `GH_TOKEN` or
    `GH_ENTERPRISE_TOKEN` is required, depending on the targeted host.
    

    Hope this helps.

    Yeah that's helpful thank you!

    I guess I'm dense lol - I thought switching to the account gave it the inference it needed using gh auth switch but I see what you mean now.

    I'm switching to GH CLI (was using GitKraken for a long time, but due to budget we are no longer using it).

    From some testing, it seems if I want to do tasks like gh repo list ill just have to set that env var up. No biggie I can easily write wrapper commands to do that.

  23. williammartin commented on Feb 24, 2026

    @williammartin
    Member

    I guess I'm dense lol - I thought switching to the account gave it the inference it needed using gh auth switch but I see what you mean now.

    Pretty understandable tbh, I don't think you're the first person maybe even in this thread that has hit the same issue. Part of the problem is that multi account came long after host targeting so the worlds conflict a little bit. The env var is your best bet for gh repo list indeed.

  24. uncenter commented on Feb 25, 2026

    @uncenter

    I've tried a few different workarounds for this, and ended up just writing a little script and putting it on my path as gh, overriding the actual gh executable. This way, any other scripts/tools that call gh will first switch the user appropriately. This script sets the user based on the presence of a string in the current path, but you can customize the logic here however you want.

    I took this idea and made a version (in Fish — sorry!) that does the same but switches based on the configured Git user.name which is expected to match a/your GitHub account login username. For me, I have my Git config based around includeIf for certain directories, so I just have to set that for my GitHub account to also match my configured Git user.

    function gh
        set user $(git config user.name)
        if command gh auth status --json hosts --jq '.hosts["github.com"].[].login' | grep -Fqx "$user"
            command gh auth switch -u "$user" >/dev/null 2>&1
        else
            echo "gh: matching gh user for git user '$user' not found"
        end
    
        command gh $argv
    end

    Hope this helps :)

  25. caseycs commented on Apr 9, 2026

    @caseycs

    I came up with the workaround for OSX using Seatbelt: https://github.com/caseycs/gh-sandbox-osx

  26. galamdring commented on Apr 10, 2026

    @galamdring

    I came at this problem from a different direction, looking to make it automatic to use my non-personal account for any repo in the non-personal org, and my personal account for everything else. I implemented it in a PR, that was of course automatically closed, but wanted to add it here as a reference as well.
    I set it up so that you can add a mapping of owner -> user, and then any repo with a configured owner will use the mapped user via the factory created http client. If there is not an owner->user match, it will use the globally active one. This allows me to leave it as my personal account in general, but ensures that when I need to interact with a non-personal repo, I'm using the correct credential.

    The solutions suggested here are good solutions if the repos are segregated by directory easily. That wasn't the case for me, so the owner path seemed the most straightforward.

    PR: #13130
    Root Cause Analysis: #12885

    Similar Issues:
    #12145
    #9111
    #11938

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authrelated to tokens, authentication state, or oauthcoreThis issue is not accepting PRs from outside contributorsenhancementa request to improve CLIpitchpitched internally for prioritisation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions