Your Code. Your Rules.

Git Access (OAuth-PAT)

Authenticate the git CLI on git.eu with the OAuth credential helper, a personal access token, or the headless device flow.

Git Access (OAuth-PAT)

git.eu authenticates the git command-line client with OAuth, not passwords. A credential helper on your machine exchanges a one-time login for short-lived, automatically-refreshed tokens - nothing long-lived is typed or stored in plain text, and a compromised laptop can be revoked from your account without changing a password.

This guide covers two methods plus a headless/Docker fallback:

the recommended setup for interactive use. Install a small helper once, log in through the browser the first time, tokens refresh automatically after that.

  • Method B - PAT: a personal access token used in the clone URL or the HTTPS prompt.

Simple, but the token is a long-lived secret - protect it.

Every snippet uses two placeholders that resolve automatically when you are signed in on this site:

  • <INSTANCE> - your instance slug (for example beta2). In call-to-action links it expands

to the full instance URL.

  • <USERNAME> - your account name on that instance.

Not signed in? The placeholders stay visible as styled literals - swap them for your own values by hand.


Find Your Instance Values

Every snippet below uses the <INSTANCE> and <USERNAME> placeholders above. Settings → Tokens on your instance shows the exact git config block generated for your account, ready to paste.


Method A - OAuth (git-credential-oauth)

git-credential-oauth is a small, dependency-free helper focused specifically on OAuth for Git hosts.

Step 1 - Install

Install the git-credential-oauth helper for your platform, then jump to Step 2.

Git auto-discovers any git-credential-* executable on your PATH.

Windows

Scoop

scoop install git-credential-oauth

winget

winget install hickford.git-credential-oauth

Chocolatey

choco install git-credential-oauth

Download the binary

Download the Windows binary from the releases page and place it anywhere on your PATH.

macOS

Homebrew

brew install git-credential-oauth
Linux

Debian

sudo apt install git-credential-oauth

Ubuntu

sudo apt install git-credential-oauth

Other distributions (Go toolchain, or prebuilt binary)

go install github.com/hickford/git-credential-oauth@latest

Verify with git credential-oauth --version - it should print a version string.

Step 2 - Configure

Add the helper and your instance's OAuth endpoints to your global git config. The client id (giteu-git) and scopes (repo:read repo:write) are the same on every git.eu instance - only the host changes, so <INSTANCE> is the only value that varies:

git config --global --add credential.helper store
git config --global --add credential.helper oauth
git config --global credential.https://<INSTANCE>.git.eu.oauthClientId giteu-git
git config --global credential.https://<INSTANCE>.git.eu.oauthAuthURL https://<INSTANCE>.git.eu/oauth/authorize
git config --global credential.https://<INSTANCE>.git.eu.oauthTokenURL https://<INSTANCE>.git.eu/oauth/token
git config --global credential.https://<INSTANCE>.git.eu.oauthDeviceAuthURL https://<INSTANCE>.git.eu/oauth/device/code
git config --global credential.https://<INSTANCE>.git.eu.oauthScopes "repo:read repo:write"

Step 3 - Use it

Create the empty repository on your instance first (web UI: New repository). Then pick the case that matches you. The first git command opens your browser to sign in and approve; after that the helper transparently refreshes tokens in the background.

Case 1 - Migrate an existing repository

git remote remove origin
git remote add origin https://<INSTANCE>.git.eu/<USERNAME>/REPO_NAME.git
git push --mirror origin

push --mirror pushes every branch, tag, and ref in one operation - all history arrives intact. REPO_NAME is the name you gave the new empty repository.

Case 2 - Start from scratch

git clone https://<INSTANCE>.git.eu/<USERNAME>/REPO_NAME.git
cd REPO_NAME

Then work as usual - git add, git commit, git push. Every operation is signed automatically.

Step 4 - Useful commands

Inspect what is stored

cat ~/.git-credentials

Reject a stored credential for one host

printf 'protocol=https\nhost=<INSTANCE>.git.eu\n\n' | git credential reject

git credential reject erases the stored credential for the given host from the credential store - the next operation for that host asks you to sign in again.

Remove all stored credentials

rm ~/.git-credentials

Method B - PAT

A personal access token (PAT) is a long-lived credential that authenticates as you without a password. It is the right choice for scripts and CI jobs; for interactive daily use, Method A is simpler and safer.

Step 1 - Create a token

Open Settings → Tokens on your instance and create a token with the scopes you need (repo:read, repo:write). Copy the raw value immediately - it is shown exactly once.

Step 2 - Use it in the URL

Embed the token directly in the clone URL. <USERNAME> resolves to your account name; <pat> is the literal token you copied - it never resolves:

git clone https://<USERNAME>:<pat>@<INSTANCE>.git.eu/REPO_NAME.git

Migrate an existing repository the same way, after creating the empty one on your instance:

git remote remove origin
git remote add origin https://<USERNAME>:<pat>@<INSTANCE>.git.eu/REPO_NAME.git
git push --mirror origin

Step 3 - Cache it (optional)

To avoid re-entering the token on every operation, configure the store helper once:

git config --global credential.helper store

The next successful authentication is written to disk and reused from then on.


Headless / Docker

CI runners, containers, and SSH-only sessions have no browser to complete an interactive OAuth login. Method A's helper falls back to the OAuth device flow in this situation - the same flow used by CLIs like the GitHub CLI or docker login.

Step 1 - Trigger the flow

Run your normal git command (clone, fetch, push) inside the headless environment. Instead of opening a browser, the helper prints a verification URL and a short user code, for example:

To authenticate, visit:

  https://<INSTANCE>.git.eu/oauth/device

and enter the code: ABCD-1234

Step 2 - Approve on another device

On any device with a browser - your laptop, your phone - open the printed verification URL, sign in to your instance, and enter the user code when prompted.

Step 3 - Wait for the exchange

The headless process polls in the background and completes automatically once you approve. No further action is needed there.


Troubleshooting


Next Steps

Ready to get started?

Manage your tokens and OAuth apps