Git Access (OAuth-PAT)
Authenticate the git CLI on git.eu with the OAuth credential helper, a personal access token, or the headless device flow.
Git Access (OAuth-PAT)
git.eu authenticates the git command-line client with OAuth, not passwords. A credential
helper on your machine exchanges a one-time login for short-lived, automatically-refreshed
tokens - nothing long-lived is typed or stored in plain text, and a compromised laptop can be
revoked from your account without changing a password.
This guide covers two methods plus a headless/Docker fallback:
- Method A - OAuth (git-credential-oauth):
the recommended setup for interactive use. Install a small helper once, log in through the browser the first time, tokens refresh automatically after that.
- Method B - PAT: a personal access token used in the clone URL or the HTTPS prompt.
Simple, but the token is a long-lived secret - protect it.
Every snippet uses two placeholders that resolve automatically when you are signed in on this site:
<INSTANCE>- your instance slug (for examplebeta2). In call-to-action links it expands
to the full instance URL.
<USERNAME>- your account name on that instance.
Not signed in? The placeholders stay visible as styled literals - swap them for your own values by hand.
Find Your Instance Values
Every snippet below uses the <INSTANCE> and <USERNAME> placeholders above. Settings →
Tokens on your instance shows the exact git config block generated for your account, ready
to paste.
Method A - OAuth (git-credential-oauth)
git-credential-oauth is a small, dependency-free helper focused specifically on OAuth for Git hosts.
Step 1 - Install
Install the git-credential-oauth helper for your platform, then jump to Step 2.
Git auto-discovers any git-credential-* executable on your PATH.
Windows
Scoop
scoop install git-credential-oauth
winget
winget install hickford.git-credential-oauth
Chocolatey
choco install git-credential-oauth
Download the binary
Download the Windows binary from the releases page and place it anywhere on your PATH.
macOS
Homebrew
brew install git-credential-oauth
Linux
Debian
sudo apt install git-credential-oauth
Ubuntu
sudo apt install git-credential-oauth
Other distributions (Go toolchain, or prebuilt binary)
go install github.com/hickford/git-credential-oauth@latest
PATH.
Verify with git credential-oauth --version - it should print a version string.
Step 2 - Configure
Add the helper and your instance's OAuth endpoints to your global git config. The client id
(giteu-git) and scopes (repo:read repo:write) are the same on every git.eu instance - only
the host changes, so <INSTANCE> is the only value that varies:
git config --global --add credential.helper store
git config --global --add credential.helper oauth
git config --global credential.https://<INSTANCE>.git.eu.oauthClientId giteu-git
git config --global credential.https://<INSTANCE>.git.eu.oauthAuthURL https://<INSTANCE>.git.eu/oauth/authorize
git config --global credential.https://<INSTANCE>.git.eu.oauthTokenURL https://<INSTANCE>.git.eu/oauth/token
git config --global credential.https://<INSTANCE>.git.eu.oauthDeviceAuthURL https://<INSTANCE>.git.eu/oauth/device/code
git config --global credential.https://<INSTANCE>.git.eu.oauthScopes "repo:read repo:write"
Step 3 - Use it
Create the empty repository on your instance first (web UI: New repository). Then pick the
case that matches you. The first git command opens your browser to sign in and approve; after
that the helper transparently refreshes tokens in the background.
Case 1 - Migrate an existing repository
git remote remove origin
git remote add origin https://<INSTANCE>.git.eu/<USERNAME>/REPO_NAME.git
git push --mirror origin
push --mirror pushes every branch, tag, and ref in one operation - all history arrives
intact. REPO_NAME is the name you gave the new empty repository.
Case 2 - Start from scratch
git clone https://<INSTANCE>.git.eu/<USERNAME>/REPO_NAME.git
cd REPO_NAME
Then work as usual - git add, git commit, git push. Every operation is signed
automatically.
Step 4 - Useful commands
Inspect what is stored
cat ~/.git-credentials
store helper writes your credentials to ~/.git-credentials
unencrypted. Anyone with read access to your home directory can read them. Prefer your
OS keychain helper when possible, and keep the file readable by your user only.
Reject a stored credential for one host
printf 'protocol=https\nhost=<INSTANCE>.git.eu\n\n' | git credential reject
git credential reject erases the stored credential for the given host from the credential
store - the next operation for that host asks you to sign in again.
Remove all stored credentials
rm ~/.git-credentials
git operation.
Method B - PAT
A personal access token (PAT) is a long-lived credential that authenticates as you without a password. It is the right choice for scripts and CI jobs; for interactive daily use, Method A is simpler and safer.
Step 1 - Create a token
Open Settings → Tokens on your instance and create a token with the scopes you need
(repo:read, repo:write). Copy the raw value immediately - it is shown exactly once.
Step 2 - Use it in the URL
Embed the token directly in the clone URL. <USERNAME> resolves to your account name; <pat>
is the literal token you copied - it never resolves:
git clone https://<USERNAME>:<pat>@<INSTANCE>.git.eu/REPO_NAME.git
Migrate an existing repository the same way, after creating the empty one on your instance:
git remote remove origin
git remote add origin https://<USERNAME>:<pat>@<INSTANCE>.git.eu/REPO_NAME.git
git push --mirror origin
.git/config), and in git error output. Revoke the token from
Settings → Tokens the moment it appears anywhere it should not.
Step 3 - Cache it (optional)
To avoid re-entering the token on every operation, configure the store helper once:
git config --global credential.helper store
The next successful authentication is written to disk and reused from then on.
store helper writes the token to ~/.git-credentials
unencrypted. Use your OS keychain helper (osxkeychain, wincred, libsecret) instead
when available, and revoke the token when the machine is retired or compromised.
Headless / Docker
CI runners, containers, and SSH-only sessions have no browser to complete an interactive OAuth
login. Method A's helper falls back to the OAuth device flow in this situation - the same
flow used by CLIs like the GitHub CLI or docker login.
Step 1 - Trigger the flow
Run your normal git command (clone, fetch, push) inside the headless environment.
Instead of opening a browser, the helper prints a verification URL and a short user
code, for example:
To authenticate, visit:
https://<INSTANCE>.git.eu/oauth/device
and enter the code: ABCD-1234
Step 2 - Approve on another device
On any device with a browser - your laptop, your phone - open the printed verification URL, sign in to your instance, and enter the user code when prompted.
Step 3 - Wait for the exchange
The headless process polls in the background and completes automatically once you approve. No further action is needed there.
Troubleshooting
git config --global --get-all credential.helper and check the
credential.https://<INSTANCE>.git.eu.* keys match your instance exactly (including scheme).
store helper must run before the
oauth helper in the chain (see Method A, Step 2) so refreshed tokens are cached to disk.
git command to get a
fresh code and complete the approval promptly.
Next Steps
Ready to get started?
Manage your tokens and OAuth apps