This guide explains how to authenticate with GitHub over HTTPS using a Personal Access Token (PAT) instead of a password — the recommended way since GitHub deprecated password-based authentication.
- Accessing GitHub over HTTPS (e.g.,
https://github.com/username/repo.git) - Automating scripts and CI/CD workflows
- When SSH is not available or allowed
- Go to: https://github.com/settings/tokens
- Click "Generate new token" (→ select "Fine-grained" or "Classic")
- Set:
- Token name (e.g.,
Git CLI Access) - Expiration (e.g., 90 days)
- Select scopes:
- ✅
repo(for full repo access) - ✅
workflow(for GitHub Actions, if needed)
- ✅
- Token name (e.g.,
- Click "Generate token"
- Copy the token and store it securely — you won't see it again!
When Git prompts for your GitHub password, use the token instead.
git clone https://github.com/yourusername/yourrepo.gitWhen prompted:
Username: yourusername
Password: <paste your token here>
💡 Git will treat the token as your password.
To avoid entering the token every time, you can cache credentials using Git:
git config --global credential.helper cachegit config --global credential.helper store
⚠️ storesaves your credentials in plaintext (~/.git-credentials) — use with caution.
If your remote uses HTTPS and you want to ensure it works with PAT:
git remote -vTo update the remote:
git remote set-url origin https://github.com/yourusername/yourrepo.git- 403 errors → Ensure the token has the right scopes
- Token not accepted → Make sure you're using the token as the password
- Token expired → Revisit GitHub and regenerate a new one
- Treat PATs like passwords — never expose them in code
- Use short expiration and regenerate as needed
- Revoke unused or leaked tokens immediately
- Prefer SSH for personal/dev use, PATs for CI