Read GitHub CLI Settings Safely with gh config get
gh config get reads one GitHub CLI setting and prints nothing else, which makes it safe to drop straight into a script. This covers reading a value, narrowing it to one GitHub host, and telling a missing key apart from a blank one. Allow about five minutes: you need a shell and the gh command, and authentication is not required merely to read an existing setting, although a later GitHub CLI operation may need it.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide describes GitHub CLI 2.87.3, installed on the reference machine. The command's interface is small: gh config get <key>, with the optional --host flag when the setting is per host. It prints the value to standard output and exits without a normal success message.
1. Confirm the installed command
Check which executable your shell will run and record its version before writing a script or troubleshooting a different machine:
$ command -v gh
/usr/bin/gh
$ gh --version
gh version 2.87.3 (2026-02-23)
Your path and version may differ. The examples below are checked against 2.87.3. Do not use sudo for this read-only operation. Running it as another user would inspect that user's GitHub CLI environment instead.
Checkpoint
If command -v gh prints nothing, stop and use the package or environment's normal installation process. Do not diagnose a missing setting until the intended binary is found.
2. Read a setting without selecting a host
Pass the configuration key as one shell argument. The manual uses git_protocol as its example:
$ gh config get git_protocol
https
The output is the value only, which makes the command useful in a check or a script. Keep the key separate from shell syntax, and quote a key supplied by a variable:
$ GH_KEY='git_protocol'
$ gh config get "$GH_KEY"
https
Do not put an untrusted string into a shell command by interpolating it into a larger command line. Passing it as one quoted argument prevents spaces or shell metacharacters from becoming additional arguments.
3. Select a particular GitHub host
Use --host when the value belongs to one GitHub host. This matters on machines that use both github.com and a GitHub Enterprise host:
$ gh config get git_protocol --host github.com
https
The short form is also documented by the installed command as -h, but --host is easier to recognise in a script:
$ gh config get git_protocol -h github.com
https
Here, -h means host, not help. That is an easy distraction trap because many command-line tools reserve it for help. Use the long spelling when reviewing a command later.
Checkpoint
Confirm the host name before trusting the result. A value read for github.com is not evidence about an Enterprise host, and omitting --host is not a substitute for identifying which configuration scope your workflow needs.
4. Check a key before using its value
A missing key is an error, not an empty successful result. Test that case without changing anything:
$ gh config get clearly-not-a-real-gh-key
could not find key "clearly-not-a-real-gh-key"
$ printf 'exit status: %s\n' "$?"
exit status: 1
The exact diagnostic quotes the key on this version. The useful contract is the non-zero status. In a script, check the status immediately and do not treat captured output as a valid setting:
$ if value=$(gh config get git_protocol --host github.com); then
> printf 'Git protocol: %s\n' "$value"
> else
> printf '%s\n' 'The GitHub CLI setting could not be read.' >&2
> exit 1
> fi
Git protocol: https
This example keeps the value in a shell variable rather than printing it to a log. Apply the same caution to any setting that could reveal an endpoint, preference or other information you do not want copied into a ticket or CI log. If you are unsure what a key contains, read it interactively first.
5. Separate reading from changing configuration
gh config get is a read operation. It does not set, delete or repair a key, and there is no undo step for a successful read. If the value is absent or wrong, stop and inspect the wider gh config documentation before choosing a command that changes state. A correction may affect later GitHub CLI commands, so make a record of the old value when one exists and test the replacement in the same host scope.
Do not add sudo to solve a configuration error. It can switch you to root's environment and make a successful read irrelevant to the account that will run GitHub CLI. Likewise, a non-zero result from a real GitHub operation may indicate authentication, while this subcommand's own documented exit codes include 1 for an error, 2 for cancellation and 4 when authentication is required. Treat the exit status as a signal to investigate, not as permission to guess a default.
Done means
- Binary confirmed. You checked the
ghexecutable and its installed version. - Key read safely. You passed a specific key as one argument and captured its value without exposing it.
- Scope checked. You used
--hostwhen a host-specific result mattered. - Status checked. You distinguished a missing key from an empty value by its exit status.
- Nothing changed. No configuration was written and no sensitive value ended up in a log.