Repository navigation
Improve multi-account git credential support when gh is not configured as git credential helper #8875
Description
Activity
- addedenhancementa request to improve CLIa request to improve CLIgh-authrelating to the gh auth commandrelating to the gh auth command
on Mar 25, 2024 I think a useful step towards making multi-account credential management easier would be to expand the availability of the
--userflag.I often use this flag when I want reliable access to a GH for a particular user.
I would like to add it to my git config (conditionally), such that it would be either
gh auth --user jonathanmorley git-credentialsorgh auth --user JMorley_emu git-credentials, depending on the repository I am trying to clone.This is not currently possible though as the git-credentials command does not support that flag.
Better support for the git config setting
[credential "https://gist.github.com"].usernamewould also be another avenue for improvement. What I have found is that if this is provided, and gh has a different profile active, it prompts for the password for the username provided by git (but doesnt automatically provide it). If gh has that profile active, it does provide the credential.Reacted by William MartinThanks @jonathanmorley, this kind of thing has been mentioned before and seems to have some support. Would you mind creating a new issue so we can prioritise it. I'd like to keep this issue specifically relating to fixing
auth switchfor people not usingghas their credential manager. I'm going to update the title to capture that, at the time I created the issue I just knew there was some issue that I wanted to solve but not sure what so it was a bit vague and I can understand how you ended up here.- changed the title
[-]Improve git credential management story in multi-account world[/-][+]Improve multi-account git credential support when `gh` is not configured as git credential helper[/+]on May 15, 2024 Acceptance Criteria
Two accounts using
https, interactive, no credential helper configuredGiven I am running the CLI interactively
And I have no credential helper configured
And I am logged into two accounts and the host protocol ishttps
When I rungh auth switch
Then I am presented with a prompt to authenticate git with my github credentials
And When I accept it
Then runninggitoperations uses the token of the account I switched to
And When I rungh auth switchagain
Then I am not presented with the same prompt, but my git authentication is updatedNote: The goal here is the same as
auth login, that if you have no credential helper configured we will setghas your credential helper.Two accounts using
https, interactive, nonghcredential helper configuredGiven I am running the CLI interactively
And I have a credential helper configured that is notgh
And I am logged into two accounts and the host protocol ishttps
When I rungh auth switch
Then I am presented with a prompt to authenticate git with my github credentials
And When I accept it
Then runninggitoperations uses the token of the account I switched to
And When I rungh auth switchagain
Then I am presented with the same prompt and postconditions as aboveNote: The goal here is the same as
auth login, that if you a credential helper configured we will inform it of new credentials on your request but we won't setghas your credential helper.Two accounts using
https, non-interactiveGiven I am running the CLI non-interactively
And I have a credential helper configured that is notghor no credential helper configured at all
And I am logged into two accounts both usinghttps
When I rungh auth switch
Then I receive no prompt to authenticate git with my github credentials
And runninggitoperations uses the token of the previously active accountOut of Scope
Two accounts using
https, confirm flag providedGiven I have a credential helper configured that is not
gh
And I am logged into two accounts and the host protocol ishttps
When I rungh auth switch --authenticate-git
Then I receive no prompt to authenticate git with my github credentials
And runninggitoperations uses the token of the account I switched toTwo accounts using
https, reject flag providedGiven I have a credential helper configured that is not
gh
And I am logged into two accounts and the host protocol ishttps
When I rungh auth switch --authenticate-git=no
Then I receive no prompt to authenticate git with my github credentials
And runninggitoperations uses the token of the previously active accountLogging into a new account, non-interactive, flag provided
Given I have a credential helper configured that is not
gh
And I am logged into two accounts and the host protocol ishttps
When I rungh auth switch --authenticate-git
Then I receive no prompt to authenticate git with my github credentials
And runninggitoperations uses the token of the account I switched toTwo accounts, one using
httpsone usingssh, interactiveWarning
It not currently possible to use different protocols for different accounts on the same host. The protocol used will be the last one chosen in an
auth loginflow as documented in the help. We will need to support per-account configuration of git protocol before proceeding with this.Given I am running the CLI interactively
And I have a credential helper configured that is notgh
And I am logged into two accounts, one withhttpsand one withssh
And The currently active account is usinghttps
When I rungh auth switch
Then I receive no prompt to authenticate git with my github credentials
And When I rungh auth switchagain
And I accept it
Then runninggitoperations uses the token of the account I switched toNote: The idea here is that we shouldn't prompt
sshconfigured users to authenticate git with their git credentials.Reacted by Catherine Davie- added a commit that references this issue
on Sep 17, 2026
Describe the feature or problem you’d like to solve
I'm creating this issue as a continuation of #8678 (comment) because we've had a number of issues created where
gh auth switchisn't working as expected.Background Reading
When authenticating a GitHub account with
gh, users expect that the active account token will be used in the following cases:gh issues listghe.g.gh repo clonegit pushDuring
auth login, if the following conditionals are true:httpsghis not the configured credential helper for the targeted hostThen the user is presented with the following prompt:
The purpose of this prompt is to ensure that point
3.above is addressed. Ifghis configured as the credential helper, then when git requests credentials, the token of the active user will always be provided. If the user chooses "Yes" the following things can happen:ghis configured as the credential helper.Additionally, it is possible to set
ghas the credential helper by runninggh auth setup-gitat a later time, and this will override previously configured credential helpers.How does this relate to
gh auth switch?Consider the following case:
ghas my credential managerwilliammartinandnot-williammartinon a single host viagh auth loginnot-williammartinas that is the account I logged into most recently.gh auth switchto change my active account towilliammartingit clone williammartin/private-repoand it is successful because git requests the active token fromgh.However, consdier what happens if we don't have
ghas the configured credential helper:ghas my credential managerwilliammartinandnot-williammartinon a single host viagh auth loginnot-williammartinas that is the account I logged into most recently.gh auth switchto change my active account towilliammartingit clone williammartin/private-repoand it fails because my credential manager has not been updated with the token forwilliammartinand the repository is private.The issue here is that
gh auth switchdoes not offer the opportunity to update the credential helper with the token of the account we are switching to.Workarounds
Currently we suggest that users run
gh auth setup-gitso thatghis their credential manager however this falls short in two places:Proposed solution
At a high level I think the correct thing to do is to interrogate the configured credential helper when
auth switchis called. Ifghis configured as the credential helper than we only need to update the token in the keyring as currently happens today. Ifghis not configured as the credential helper then we should update it in a similar to manner to what we do during auth login. This may require an additional prompt and some consideration to be given between ssh and https.