Credential Helpers

Credential Helpers and Storing Passwords Safely

Over HTTPS, Git 1,932 needs a username and token for each fetch and push (SSH keys come in GitHub), and asks a credential helper for them. git credential drives the helper protocol by hand; here the store helper saves a token for a made-up server, then returns it:

What the store helper writes to diskShell
printf 'protocol=https\nhost=git.example.com\nusername=sam\npassword=s3cret-token\n\n' \
  | git -c credential.helper="store --file=./creds" credential approve
cat creds
printf 'protocol=https\nhost=git.example.com\n\n' \
  | git -c credential.helper="store --file=./creds" credential fill
Output
https://sam:s3cret-token@git.example.com
protocol=https
host=git.example.com
username=sam
password=s3cret-token

The token sits in plain text for any process, backup or dotfiles repository to read. Prefer an encrypted store:

Credential helpers compared
Helper Where secrets live Platform
manager (GCM) OS keychain All platforms
osxkeychain, libsecret Keychain, GNOME Keyring macOS, Linux
cache --timeout=3600 Memory, with a timeout macOS, Linux
store Plain-text file Avoid

Git Credential Manager 9,326 (github.com/git-ecosystem/git-credential-manager (https://github.com/git-ecosystem/git-credential-manager 9,326 ), MIT), bundled with Git for Windows 47,417 , also handles browser sign-in and two-factor prompts for the major hosts. In WSL2 6 , set Linux Git's credential.helper to the Windows copy, /mnt/c/Program\ Files/Git/mingw64/bin/git-credential-manager.exe (the backslash escapes the space), and both sides share one set of secrets. Never embed a token in a remote URL (https://sam:token@...): Git writes it into .git/config in plain text.