Over HTTPS, Git 1,932 needs a username and token for each fetch and push (SSH keys come in GitHub), and asks a credential helper for them. git credential drives the helper protocol by hand; here the store helper saves a token for a made-up server, then returns it:
printf 'protocol=https\nhost=git.example.com\nusername=sam\npassword=s3cret-token\n\n' \
| git -c credential.helper="store --file=./creds" credential approve
cat creds
printf 'protocol=https\nhost=git.example.com\n\n' \
| git -c credential.helper="store --file=./creds" credential fillhttps://sam:s3cret-token@git.example.com protocol=https host=git.example.com username=sam password=s3cret-token
The token sits in plain text for any process, backup or dotfiles repository to read. Prefer an encrypted store:
| Helper | Where secrets live | Platform |
|---|---|---|
| manager (GCM) | OS keychain | All platforms |
| osxkeychain, libsecret | Keychain, GNOME Keyring | macOS, Linux |
| cache --timeout=3600 | Memory, with a timeout | macOS, Linux |
| store | Plain-text file | Avoid |
Git Credential Manager 9,326 (github.com/git-ecosystem/git-credential-manager (https://github.com/git-ecosystem/git-credential-manager 9,326 ), MIT), bundled with Git for Windows 47,417 , also handles browser sign-in and two-factor prompts for the major hosts. In WSL2 6 , set Linux Git's credential.helper to the Windows copy, /mnt/c/Program\ Files/Git/mingw64/bin/git-credential-manager.exe (the backslash escapes the space), and both sides share one set of secrets. Never embed a token in a remote URL (https://sam:token@...): Git writes it into .git/config in plain text.