Home / Alt manpages / git-credential-cache--daemon(1)

  • git-credential-cache--daemon(1)
  • User command
  • linux

Keep Git Credentials in Memory with the Cache Daemon

You will configure Git to remember an HTTPS credential in memory for a limited time, verify that the cache is working, and clear it on demand. The installed Git version here is 2.43.0, from Ubuntu package git-man version 1:2.43.0-1ubuntu7.3. Allow about ten minutes, plus the time needed to complete one normal Git operation.

This helper is for credentials that Git would otherwise ask for repeatedly. It is not an encrypted password store. The cache daemon keeps credentials in its own process memory, reachable through a Unix domain socket, and forgets them when they expire or when the daemon exits. A system restart clears the cache, but the helper is not a replacement for a password manager or a safer authentication method such as SSH keys or a limited-scope token.

1. Choose a small cache lifetime

The default lifetime is 900 seconds, or 15 minutes. Set a shorter or longer value deliberately. This example caches credentials for 15 minutes in the current repository:

$ git config credential.helper 'cache --timeout=900'
$ git config --get credential.helper
cache --timeout=900

Use --global on both commands if this is a personal policy for all repositories belonging to your user:

$ git config --global credential.helper 'cache --timeout=900'

Checkpoint: inspect the setting before relying on it. A value such as store is a different helper and writes credentials to disk, while cache uses the daemon described here.

If you are only testing, avoid changing your existing global configuration. The current-repository form is easier to undo:

$ git config --unset credential.helper

If you changed the global setting instead, undo that exact setting with git config --global --unset credential.helper. Do not run an unset command against a scope you did not inspect first.

2. Let Git start the daemon

Run a Git operation that needs an HTTPS credential, using a repository and remote you already trust:

$ git fetch origin
Username for 'https://git.example.test': your-username
Password for 'https://[email protected]': your-token

The first operation supplies the credential to git-credential-cache. That helper starts git-credential-cache--daemon automatically, so you normally do not invoke the daemon directly. It listens on a Unix socket and serves cache clients. The socket is restricted to the current user by filesystem permissions.

Checkpoint: repeat the same operation before 900 seconds have passed:

$ git fetch origin
# no credential prompt; the cached value is supplied

A fetch can still fail for unrelated reasons, such as an unreachable remote or an expired server token. A missing prompt only shows that the helper supplied a cached credential; it does not prove that the remote accepted it.

3. Inspect the socket location safely

The cache helper uses $XDG_CACHE_HOME/git/credential/socket by default. If ~/.git-credential-cache/ already exists, it uses ~/.git-credential-cache/socket instead. You can select another absolute path with --socket, which is useful when a home directory is on a network filesystem.

$ git config --show-origin --get-all credential.helper
$ test -n "$XDG_CACHE_HOME" && printf '%s\n' "$XDG_CACHE_HOME/git/credential/socket"

The printed path is a default, not a guarantee that the daemon is currently running. The socket appears after a client starts the daemon and disappears when it exits. Do not read a socket as if it were a password file, and do not copy it to another machine. It is local IPC for the current user's cache.

For a controlled test, use a private directory and a fake host. This stores only the marked test value, not a real password:

test_dir=$(mktemp -d)
chmod 700 "$test_dir"
socket="$test_dir/socket"
printf '%s\n' \
  'protocol=https' \
  'host=example.invalid' \
  'username=demo-user' \
  'password=REPLACE_WITH_TEST_VALUE' \
  | git credential-cache --timeout=30 --socket="$socket" store
git credential-cache --socket="$socket" get <<'EOF'
protocol=https
host=example.invalid

EOF

Expected output contains the stored fields:

username=demo-user
password=REPLACE_WITH_TEST_VALUE

Do not paste a real secret into a terminal recording, shell history, issue tracker or article. The get example prints the password deliberately, so use it only with a disposable test value.

4. Forget cached credentials immediately

To clear all credentials held by the cache daemon before their timeout, issue the exit action:

$ git credential-cache exit

This tells the daemon to exit and forget its in-memory credentials. It does not remove your Git configuration and it does not revoke a token already issued by a hosting service. If a token may have been exposed, revoke or rotate it at that service separately.

For a daemon using an explicit socket, name that socket:

$ git credential-cache --socket="$socket" exit

After an exit request, a later Git operation can start a new daemon and ask again. The daemon also exits by itself once no credentials remain held, and a client-supplied timeout controls when each credential expires.

5. Understand the daemon boundary

The direct interface is git credential-cache--daemon [--debug] <socket-path>. It accepts one socket path and an optional --debug flag. This is normally an implementation detail of the cache helper, not a service to enable at boot.

--debug keeps standard error open and may write extra diagnostics after the daemon begins listening. Use it only for a short local investigation. Diagnostic output can reveal socket paths and timing, and a manually managed daemon is another process to clean up.

The socket path must be absolute when supplied to the helper. If Git refuses to start because the directory is accessible to other users, create a private directory with mode 700 or fix its permissions. Elevated privileges are not normally required. Running the helper with sudo would create a root-owned cache that your ordinary Git process cannot use.

Done means

  • The intended scope contains a cache helper with an explicit timeout.
  • A normal HTTPS operation prompted once, then reused the cache during the timeout.
  • You know which socket default applies and understand that it is local IPC, not a password file.
  • git credential-cache exit clears the daemon's in-memory credentials when needed.
  • No real password or token was placed in a test command, log, history entry or shared document.