# Git Credential Manager

Published January 1, 2026 · Updated August 10, 2026

Cross-platform Git credential storage for GitHub, Azure, and more

Category: Developer Tools · Free · [Official website](https://github.com/git-ecosystem/git-credential-manager)

## Install with Homebrew

`brew install --cask git-credential-manager`

## Quick take

Install GCM if you push over HTTPS and your hosts enforce 2FA. After one browser login, token refresh and Keychain storage remove the daily PAT grind. SSH keys still make sense when you want explicit key files or headless boxes, but for day-to-day Mac work against GitHub, GitLab, Bitbucket, or Azure DevOps with MFA, GCM is the practical default. Rate it 4.5/5 for HTTPS Mac workflows that need OAuth and SSO without babysitting tokens. Pair it with SSH only where you already manage keys for servers; do not feel forced to pick a single method for every remote.

Best for: Developers with 2FA-enabled Git accounts, Teams standardizing on HTTPS workflows, Enterprise environments with SSO requirements

## What is Git Credential Manager?

As of August 2026 Git Credential Manager **2.9.1** is the current release. Git Credential Manager (GCM) is a cross-platform credential helper maintained by GitHub (Microsoft) for HTTPS Git authentication. Basic helpers that ship with Git store a username and password; GCM adds multi-factor authentication, OAuth, and native keychain storage so modern Git hosts stay usable without pasting Personal Access Tokens by hand. Mac developers who prefer HTTPS over SSH authenticate once through a browser OAuth handshake. After that, credentials live in the macOS Keychain, encrypted at rest, and GCM refreshes them when tokens expire. GCM covers GitHub (and GitHub Enterprise), GitLab, Bitbucket, and Azure DevOps, picking the provider from the remote URL so you can hit several hosts in one terminal session without fighting config conflicts. The tool started as separate platform builds and later became one .NET codebase that behaves the same on macOS, Windows, or Linux. Teams that require two-factor authentication or Single Sign-On (SSO) for HTTPS workflows usually need GCM because older credential stores cannot run the OAuth device flow. It hooks into your terminal, opens the default browser for the first login, then stays quiet for later pushes and pulls. The project is open-source at github.com/git-ecosystem/git-credential-manager and ships regular releases when providers change auth methods or add features. Homebrew remains the usual Mac install path (`brew install --cask git-credential-manager`), after which `git config --global credential.helper manager` wires Git to call GCM on every HTTPS remote. Legacy search results still mention "Git Credential Manager for Windows"; that Windows-only branding is retired, and the current cross-platform GCM is the supported line.

## Features

- **Native macOS Keychain Integration.** GCM stores Git credentials in the macOS Keychain using Apple's credential storage. Tokens sit encrypted at rest under your system's security settings, and you can inspect or delete them in Keychain Access. Credentials survive terminal sessions and reboots, so you are not asked to log in again every morning. After a successful GitHub login you typically see Keychain entries labeled like `git:https://github.com`, which is useful when you need to revoke access on a shared Mac.
- **Multi-Factor Authentication Support.** Basic credential helpers stall on 2FA-protected accounts. GCM runs MFA through an OAuth device flow instead: a push opens your browser, you finish any MFA challenge there, and the OAuth token is saved. You do not need to mint and paste Personal Access Tokens for routine Git work.
- **Automatic Token Refresh.** OAuth tokens expire, and refreshing them by hand is tedious. GCM watches expiry and renews credentials before they go stale, so Git operations do not fail on dead tokens. The refresh happens in the background while you keep working.
- **Multi-Provider Detection.** GCM reads the remote URL and chooses the right host flow. A push to GitHub, a pull from GitLab, or a clone from Azure DevOps each gets the matching auth path. You can stay in one terminal session across providers without rewriting credential config between projects.
- **Cross-Platform Consistency.** Built on .NET, GCM keeps the same behavior on macOS, Windows, and Linux. Teams that share dotfiles, scripts, or CI settings can point credential.helper at GCM everywhere. Developers who move between operating systems keep the same auth habits.
- **Enterprise SSO Support.** Organizations on SAML or OIDC Single Sign-On with GitHub Enterprise or Azure DevOps can complete SSO challenges inside the browser auth flow. That makes GCM usable in corporate setups that enforce identity governance. If auto-detection misses a custom enterprise hostname, set the provider explicitly (for example `git config --global credential.github.mycompany.com.provider github`).

## Install Git Credential Manager on Mac

Install Git Credential Manager on macOS with Homebrew. It plugs into your existing Git install and needs only a short credential.helper config before the first HTTPS push.

1. **Install Homebrew (if not present).** Open Terminal and run: `/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"` to install the Homebrew package manager.
2. **Install Git Credential Manager.** Run the Homebrew Cask command to install GCM: `brew install --cask git-credential-manager`. Homebrew downloads the current stable release (2.9.1 as of August 2026) and places the helper on your system.
3. **Configure Git to Use GCM.** Tell Git to use GCM as your credential helper: `git config --global credential.helper manager`. This sets GCM as the default for all repositories.
4. **Verify Installation.** Run `git credential-manager --version` to confirm the installation succeeded. You should see the version number printed to your terminal.

## Pros

- Handles 2FA and OAuth flows that break basic credential helpers.
- Stores credentials in the native macOS Keychain with encryption at rest.
- Works with GitHub, GitLab, Bitbucket, and Azure DevOps without extra plugins.
- Refreshes expired tokens without asking you to paste a new PAT.
- Same helper config works across macOS, Windows, and Linux for team standards.

## Cons

- Bundles a .NET runtime, so the install is larger than a tiny native helper.
- Browser-based login is awkward in headless or SSH-only environments.
- Some people still prefer SSH keys for explicit key management and audit trails.

## Closer look: secure HTTPS Git auth on Mac

How Git Credential Manager fits modern Git hosts that expect OAuth and MFA instead of long-lived passwords.

## FAQ

### What is Git Credential Manager used for?

Git Credential Manager stores and renews Git credentials for HTTPS remotes. It runs OAuth login, supports multi-factor authentication, and writes tokens into the OS credential store (macOS Keychain on Mac). You sign in once in a browser; later Git operations reuse the stored token.

### Is Git Credential Manager better than SSH keys?

Neither wins for every setup. GCM fits HTTPS URLs, 2FA-protected accounts, and browser login. SSH keys fit headless servers, automation, and people who want explicit key files. Many developers keep both and pick per machine or repo.

### Does Git Credential Manager work with GitHub 2FA?

Yes. That is one of GCM's main jobs. On a 2FA-protected GitHub push, GCM opens the browser for OAuth, you finish the 2FA step, and the token is stored. You stay signed in until the token expires or you revoke it.

### How do I remove credentials stored by Git Credential Manager?

Open Keychain Access on your Mac and search for entries starting with 'git:' followed by your repository host (for example 'git:https://github.com'). Select the entry and delete it. You can also run `git credential-manager erase` and supply the protocol and host when prompted. Clearing the Keychain entry forces the next Git operation to open a fresh browser login.

### Can I use Git Credential Manager with multiple GitHub accounts?

Yes. Turn on HTTP path matching with `git config --global credential.github.com.useHttpPath true`. GCM then treats each repository path as unique, so work and personal GitHub accounts can keep separate tokens based on the full remote URL rather than sharing one host-wide credential.

### Does Git Credential Manager support GitLab and Bitbucket?

Yes. GCM supports GitLab, Bitbucket, and Bitbucket Server alongside GitHub and Azure DevOps. On HTTPS clone or push, it detects the host from the remote URL and starts the matching OAuth flow. Tokens land in the macOS Keychain, and refresh works across those hosts.

### How do I uninstall Git Credential Manager on macOS?

Unset the helper with `git config --global --unset credential.helper`, then uninstall the cask: `brew uninstall --cask git-credential-manager`. Open Keychain Access, search for entries starting with 'git:', and delete what you no longer need. After that, Git falls back to its default prompting behavior.

### Can Git Credential Manager work alongside GitHub CLI (gh)?

Yes. GitHub CLI covers GitHub-specific tasks such as pull requests and issues, while GCM stores credentials for HTTPS Git across hosts. When both are installed they can share Keychain entries, so a login in one tool often helps the other.

## Sources

- [GCM Releases](https://github.com/git-ecosystem/git-credential-manager/releases)
- [git-credential-manager repository](https://github.com/git-ecosystem/git-credential-manager)
- [Use Git Credential Manager with Azure Repos](https://learn.microsoft.com/en-us/azure/devops/repos/git/set-up-credential-managers?view=azure-devops)
- [Legacy GCM for Windows notice](https://microsoft.github.io/Git-Credential-Manager-for-Windows/)
- [GitHub Blog on GCM Core](https://github.blog/open-source/git/git-credential-manager-core-building-a-universal-authentication-experience/)
- [GCM install docs](https://github.com/git-ecosystem/git-credential-manager/blob/main/docs/install.md)

## Related

- [Cursor](https://bundl.run/apps/cursor)
- [Claude Code](https://bundl.run/apps/claude-code)
- [ChatGPT](https://bundl.run/apps/chatgpt)
- [Claude](https://bundl.run/apps/claude)
- [Codex](https://bundl.run/apps/codex)
- [Windsurf](https://bundl.run/apps/windsurf)

```json
{
  "@context": "https://schema.org",
  "@graph": [
    {
      "@type": "Organization",
      "@id": "https://bundl.run/#organization",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "logo": {
        "@type": "ImageObject",
        "url": "https://bundl.run/og-image.png",
        "width": 1200,
        "height": 630
      },
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "sameAs": [
        "https://github.com/abhiofficial/bundl-mac-setup",
        "https://x.com/bundlrun",
        "https://www.producthunt.com/products/bundl-run"
      ],
      "foundingDate": "2024",
      "contactPoint": {
        "@type": "ContactPoint",
        "contactType": "customer support",
        "url": "https://bundl.run/faq"
      }
    },
    {
      "@type": "WebSite",
      "@id": "https://bundl.run/#website",
      "name": "Bundl.run",
      "url": "https://bundl.run",
      "description": "The Ninite for Mac. Install all your essential Mac apps with one terminal command.",
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@type": "Person",
      "@id": "https://bundl.run/authors/alex-chen#person",
      "name": "Alex Chen",
      "jobTitle": "Senior Developer Tools Specialist",
      "url": "https://bundl.run/authors/alex-chen",
      "worksFor": {
        "@id": "https://bundl.run/#organization"
      },
      "description": "Alex Chen has been evaluating developer tools and productivity software for over 12 years, with deep expertise in code editors, terminal emulators, and development environments. As a former software engineer at several Bay Area startups, Alex brings hands-on experience with the real-world workflows these tools are meant to enhance. Alex tests each application extensively on both Intel and Apple Silicon Macs, documenting performance metrics, integration capabilities, and workflow efficiency. When not reviewing software, Alex contributes to open-source projects and writes technical tutorials for the developer community.",
      "knowsAbout": [
        "Code Editors & IDEs",
        "Terminal Emulators",
        "Version Control Tools",
        "DevOps & CI/CD",
        "API Development",
        "Performance Benchmarking"
      ],
      "image": "https://bundl.run/authors/alex-chen.svg"
    },
    {
      "@type": "BreadcrumbList",
      "@id": "https://bundl.run/apps/git-credential-manager#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://bundl.run"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Apps",
          "item": "https://bundl.run/apps"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Git Credential Manager",
          "item": "https://bundl.run/apps/git-credential-manager"
        }
      ]
    },
    {
      "@type": "WebPage",
      "@id": "https://bundl.run/apps/git-credential-manager",
      "url": "https://bundl.run/apps/git-credential-manager",
      "name": "Git Credential Manager for Mac",
      "description": "Cross-platform Git credential storage for GitHub, Azure, and more",
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "inLanguage": "en-US",
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "author": {
        "@id": "https://bundl.run/authors/alex-chen#person"
      },
      "mainEntity": {
        "@id": "https://bundl.run/apps/git-credential-manager#software"
      },
      "breadcrumb": {
        "@id": "https://bundl.run/apps/git-credential-manager#breadcrumb"
      }
    },
    {
      "@type": "SoftwareApplication",
      "@id": "https://bundl.run/apps/git-credential-manager#software",
      "name": "Git Credential Manager",
      "description": "Cross-platform Git credential storage for GitHub, Azure, and more",
      "applicationCategory": "DeveloperApplication",
      "operatingSystem": "macOS",
      "url": "https://bundl.run/apps/git-credential-manager",
      "image": {
        "@type": "ImageObject",
        "url": "https://img.logo.dev/github.com",
        "caption": "Git Credential Manager app icon for Mac"
      },
      "sameAs": [
        "https://github.com/git-ecosystem/git-credential-manager",
        "https://formulae.brew.sh/cask/git-credential-manager"
      ],
      "review": {
        "@type": "Review",
        "author": {
          "@id": "https://bundl.run/authors/alex-chen#person"
        },
        "reviewBody": "Install GCM if you push over HTTPS and your hosts enforce 2FA. After one browser login, token refresh and Keychain storage remove the daily PAT grind. SSH keys still make sense when you want explicit key files or headless boxes, but for day-to-day Mac work against GitHub, GitLab, Bitbucket, or Azure DevOps with MFA, GCM is the practical default. Rate it 4.5/5 for HTTPS Mac workflows that need OAuth and SSO without babysitting tokens. Pair it with SSH only where you already manage keys for servers; do not feel forced to pick a single method for every remote."
      },
      "about": {
        "@type": "Thing",
        "name": "Git Credential Manager",
        "description": "Cross-platform Git credential storage for GitHub, Azure, and more"
      },
      "isPartOf": {
        "@id": "https://bundl.run/#website"
      }
    },
    {
      "@type": "Article",
      "@id": "https://bundl.run/apps/git-credential-manager#article",
      "headline": "Git Credential Manager for Mac — Full Review & Installation Guide 2026",
      "description": "Install GCM if you push over HTTPS and your hosts enforce 2FA. After one browser login, token refresh and Keychain storage remove the daily PAT grind. SSH keys still make sense when you want explicit key files or headless boxes, but for day-to-day Mac work against GitHub, GitLab, Bitbucket, or Azure DevOps with MFA, GCM is the practical default. Rate it 4.5/5 for HTTPS Mac workflows that need OAuth and SSO without babysitting tokens. Pair it with SSH only where you already manage keys for servers; do not feel forced to pick a single method for every remote.",
      "image": "https://img.logo.dev/github.com",
      "author": {
        "@id": "https://bundl.run/authors/alex-chen#person"
      },
      "publisher": {
        "@id": "https://bundl.run/#organization"
      },
      "datePublished": "2026-01-01T00:00:00Z",
      "dateModified": "2026-08-10T13:34:04.000Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://bundl.run/apps/git-credential-manager"
      },
      "articleSection": "DeveloperApplication",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".key-facts"
        ]
      },
      "about": {
        "@type": "SoftwareApplication",
        "name": "Git Credential Manager",
        "url": "https://bundl.run/apps/git-credential-manager"
      }
    },
    {
      "@type": "FAQPage",
      "@id": "https://bundl.run/apps/git-credential-manager#faq",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is Git Credential Manager used for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Git Credential Manager stores and renews Git credentials for HTTPS remotes. It runs OAuth login, supports multi-factor authentication, and writes tokens into the OS credential store (macOS Keychain on Mac). You sign in once in a browser; later Git operations reuse the stored token."
          }
        },
        {
          "@type": "Question",
          "name": "Is Git Credential Manager better than SSH keys?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Neither wins for every setup. GCM fits HTTPS URLs, 2FA-protected accounts, and browser login. SSH keys fit headless servers, automation, and people who want explicit key files. Many developers keep both and pick per machine or repo."
          }
        },
        {
          "@type": "Question",
          "name": "Does Git Credential Manager work with GitHub 2FA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. That is one of GCM's main jobs. On a 2FA-protected GitHub push, GCM opens the browser for OAuth, you finish the 2FA step, and the token is stored. You stay signed in until the token expires or you revoke it."
          }
        },
        {
          "@type": "Question",
          "name": "How do I remove credentials stored by Git Credential Manager?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Open Keychain Access on your Mac and search for entries starting with 'git:' followed by your repository host (for example 'git:https://github.com'). Select the entry and delete it. You can also run `git credential-manager erase` and supply the protocol and host when prompted. Clearing the Keychain entry forces the next Git operation to open a fresh browser login."
          }
        },
        {
          "@type": "Question",
          "name": "Can I use Git Credential Manager with multiple GitHub accounts?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Turn on HTTP path matching with `git config --global credential.github.com.useHttpPath true`. GCM then treats each repository path as unique, so work and personal GitHub accounts can keep separate tokens based on the full remote URL rather than sharing one host-wide credential."
          }
        },
        {
          "@type": "Question",
          "name": "Does Git Credential Manager support GitLab and Bitbucket?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. GCM supports GitLab, Bitbucket, and Bitbucket Server alongside GitHub and Azure DevOps. On HTTPS clone or push, it detects the host from the remote URL and starts the matching OAuth flow. Tokens land in the macOS Keychain, and refresh works across those hosts."
          }
        },
        {
          "@type": "Question",
          "name": "How do I uninstall Git Credential Manager on macOS?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Unset the helper with `git config --global --unset credential.helper`, then uninstall the cask: `brew uninstall --cask git-credential-manager`. Open Keychain Access, search for entries starting with 'git:', and delete what you no longer need. After that, Git falls back to its default prompting behavior."
          }
        },
        {
          "@type": "Question",
          "name": "Can Git Credential Manager work alongside GitHub CLI (gh)?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. GitHub CLI covers GitHub-specific tasks such as pull requests and issues, while GCM stores credentials for HTTPS Git across hosts. When both are installed they can share Keychain entries, so a login in one tool often helps the other."
          }
        }
      ],
      "isPartOf": {
        "@id": "https://bundl.run/apps/git-credential-manager"
      }
    }
  ]
}
```