GitDBDocs
Getting started

Personal access tokens

Create, use, and revoke personal access tokens for scripts, CI runners, and Git over HTTPS.

A personal access token lets a script, a CI runner, or Git over HTTPS act as you without your password. "Tokens inherit your user permissions, scoped further by the chosen scopes": a token can never do more than your own account can, and you narrow it further with scopes and an expiry date.

Tokens live in Settings → Personal access tokens. You can also get there from New → New access token in the top bar, or Personal access tokens in the account menu.

Create a token

  1. Click Generate new token.
  2. Fill in the Generate new token dialog:
    • Token name: something that tells you later where it's used, for example CI runner — production.
    • Scopes: tick at least one. repo:read and git:read are ticked by default. Pick the narrowest set that fits the use case.
    • Expiration: how long the token stays valid.
  3. Click GENERATE TOKEN →.
  4. The dialog now shows Token … created and the token itself under One-time display. Click COPY TOKEN, store it somewhere safe (for example your CI system's credential store), then click DONE →.

Copy the token before you close the dialog. You will not be able to see it again. If you lose it, revoke it and create a new one.

Scopes

ScopeWhat it allows
repo:readRead repositories and metadata
repo:writeCreate branches, commits, refs
git:readClone via git-over-HTTPS
git:writePush via git-over-HTTPS
user:readRead your account profile

Expiration

OptionToken is valid for
30 days30 days from creation
60 days60 days from creation
90 days (default)90 days from creation
1 year365 days from creation
No expiration (not recommended)Until you revoke it

Once a token expires it's refused, exactly like a revoked token.

Use a token with Git over HTTPS

Every repository can also be reached over HTTPS at https://gitdb.co/{org}/{repo}:

git clone https://gitdb.co/{org}/{repo}

When Git asks for credentials, enter any username and paste your token as the password.

  • To clone and fetch, a token with git:read is the narrowest choice.
  • To push, the token needs git:write (or repo:write). A token without a write scope can clone and fetch but can't push.
  • Branch protection rules apply to HTTPS pushes exactly as they do over SSH. See Branch protection.

Use your operating system's Git credential helper to store the token instead of typing it each time. If you'd rather not handle tokens at all, use SSH keys.

Your token list

Each token in the list shows its name, its scopes, when it was Last used (or "never"), and when it expires (or "no expiration").

Revoke a token

  1. Click the delete icon next to the token.
  2. A confirmation dialog titled with the token's name warns: "Any CLI sessions or scripts using this token will stop working immediately. This cannot be undone."
  3. Click REVOKE TOKEN →.

Revoke a token right away if it may have leaked, and create a new one for whatever used it.

Good practice

  • One token per use (per CI pipeline, per script), so you can revoke one without breaking the others.
  • Pick the narrowest scopes and a real expiry date rather than No expiration (not recommended).
  • Never commit a token to a repository or paste it into chat.

On this page