Home / Alt manpages / gh-auth-logout(1)

  • gh-auth-logout(1)
  • User command
  • linux

Log Out of One GitHub CLI Account Safely

You will remove one stored GitHub CLI login from this machine, check which account was selected, and verify that the local configuration no longer contains it. The examples use GitHub CLI 2.87.3, installed here on 23 September 2026.

Allow about five minutes. You need an ordinary shell and the gh package. No command in this guide needs sudo. Keep another way to authenticate available if scripts, Git or a service depend on this account.

1. Check the installed command

Confirm the executable and read the installed command's help. These are read-only checks:

$ command -v gh
/usr/bin/gh
$ gh --version
gh version 2.87.3 (2026-02-23)
$ gh auth logout --help

The logout command has two selectors: --hostname chooses the GitHub host and --user chooses the account. With neither flag, gh prompts you to select both. The full options are -h and -u respectively.

Checkpoint

You know which gh binary will change its local authentication configuration, and you have not changed anything yet.

2. Record the account before removing it

Ask gh which accounts it can see. Use the host-specific form when you know the host:

$ gh auth status --hostname github.com
github.com
  ✓ Logged in to github.com account ACCOUNT_NAME (...)
  - Active account: true

The account name, credential path and protocol in the output are host-specific. Do not paste a token into a ticket, terminal recording or article. The --show-token option exists, but it is not needed for logout and would print a secret.

If several accounts are stored for one host, identify the exact username you intend to remove. A logout is a local configuration change, so write down the host and username before proceeding.

3. Remove one host and account explicitly

For a non-interactive, reviewable command, replace the placeholders with the values from the previous step:

$ gh auth logout --hostname github.example.com --user ACCOUNT_NAME

The command removes the stored authentication configuration for that account on that host. It does not remove an account at GitHub, alter repositories, delete Git credentials elsewhere, or revoke the token. It also does not need elevated privileges because the configuration belongs to the user running gh.

This is the point of no return for the local configuration. Stop if the host or username is not exactly the one you recorded. If you omit either selector, gh uses a prompt, which is convenient at a terminal but easier to misread in a long session.

Checkpoint

The intended stored account has been selected and only its local gh authentication entry has been targeted.

4. Verify the local result

Run the same host-specific status check again:

$ gh auth status --hostname github.example.com
no authenticated account is reported for this host

The exact wording and exit status depend on whether another account remains and on the installed CLI version. The useful result is that the account you removed is no longer listed as an authenticated account for that host. If another account is still present, check its username rather than assuming logout failed.

If you want to verify a different host, pass that host explicitly:

$ gh auth status --hostname github.com

GitHub CLI can also use a token from environment variables. In particular, GH_TOKEN or GITHUB_TOKEN takes precedence for commands targeting github.com, while the enterprise equivalents apply to an Enterprise Server host. If a command still works after stored credentials are removed, inspect the environment used by that shell or service. Do not print the variable's value.

5. Restore access when needed

Logout has no inverse command that reconstructs the removed credential. To use the host again, authenticate it with the normal login flow:

$ gh auth login --hostname github.example.com

Follow the prompts for that host and account, then verify the result:

$ gh auth status --hostname github.example.com
the restored account is listed here

If automation still needs access, review its token source separately. A token supplied through an environment variable is not made safer or invalid by deleting a stored login entry.

6. Revoke tokens only when that is what you mean

Local logout and token revocation are different operations. If a token may have been exposed, or if you need to invalidate GitHub CLI tokens across devices, use GitHub's authorised-application settings and revoke the GitHub CLI application. That is a security-sensitive change: it can invalidate every token generated by GitHub CLI for the application, not just the entry removed on this machine. Check dependent scripts and hosts before doing it.

Do not try to achieve revocation by deleting a local configuration file or by running logout repeatedly. If you only needed to remove this workstation's stored account, the explicit logout and status check above are sufficient.

Done means

  • You checked the installed GitHub CLI version and selected the intended host and account.
  • You ran gh auth logout without sudo, using explicit selectors where possible.
  • gh auth status no longer reports the removed stored account for that host.
  • You understand that local logout does not revoke tokens or change GitHub itself.
  • You know to inspect GH_TOKEN or the enterprise token variables if access remains.
  • You can restore access with gh auth login when the account is needed again.