Home / Alt manpages / git-credential-cache(1)

  • git-credential-cache(1)
  • User command
  • linux

Cache Git Credentials Temporarily Without Writing Them to Disk

By the end of this guide, Git will remember credentials in a short-lived per-user daemon, so repeated HTTPS operations do not prompt every time. The cache is held in process memory rather than a credentials file, and it disappears when its timeout expires or the daemon stops. Allow about five minutes for setup and a quick verification.

This guide targets the git-credential-cache helper from Git 2.43.0, installed here by the Debian git-man package version 1:2.43.0-1ubuntu7.3. The documented defaults used below are a 900-second timeout and a Unix socket under $XDG_CACHE_HOME/git/credential/socket, with a legacy home-directory location selected when ~/.git-credential-cache/ already exists.

1. Check the installed helper

Run this as your normal user. No elevated privileges are needed, and using sudo would create a separate root-owned cache that your ordinary Git commands cannot use.

$ git --version
git version 2.43.0
$ command -v git-credential-cache
/usr/lib/git-core/git-credential-cache

The exact helper path can differ between distributions. The important check is that Git is installed and the helper is available to the same user who will run the repository commands.

2. Enable the default temporary cache

Configure the helper in your Git configuration:

$ git config --global credential.helper cache

This changes your user-level Git configuration. It does not store a credential immediately. The cache daemon starts when a Git operation needs to store or retrieve one.

Confirm the effective setting before relying on it:

$ git config --global --get-all credential.helper
cache

Checkpoint: if the output is empty, you configured a different scope or a different Git configuration file. If it prints another helper as well, Git may consult multiple helpers in order. Inspect all active entries with git config --show-origin --get-all credential.helper before assuming this cache is the only credential store.

3. Use it with an HTTPS remote

Run a normal Git operation against your HTTPS remote. The first operation that needs authentication prompts for the username and password or token. Git then passes the credential to the cache helper.

$ git push https://git.example.invalid/team/project.git
Username for 'https://git.example.invalid': your-user
Password for 'https://[email protected]': [type the credential]

Use your real host and repository in practice. The example host is deliberately invalid, so do not paste it into a production command. On a later Git operation to the same credential scope, the helper can answer from memory and Git should not prompt again while the cache entry is alive.

Do not paste a token into a command line or place it in a remote URL. Shell history, process listings and logs can expose it. Let Git prompt, or use the host's supported secure authentication helper when you need longer-lived access.

4. Set a deliberate timeout

The default cache lifetime is 900 seconds, or 15 minutes. If a short maintenance session needs an hour, set the timeout as an option on the helper value:

$ git config --global credential.helper 'cache --timeout=3600'
$ git config --global --get-all credential.helper
cache --timeout=3600

The number is seconds. This is still temporary storage, not a promise that the credential will survive a restart. The cache daemon can die sooner, including when the system restarts, and its credentials are then forgotten.

Common trap: setting credential.helper to cache in one command and later setting it to cache --timeout=3600 at the same scope replaces the earlier value. That is normally what you want. If several values exist, use --get-all and review them rather than guessing which one will run first.

5. Check the socket boundary

The daemon communicates through a Unix domain socket. The default is:

$ printf '%s\n' "${XDG_CACHE_HOME:-$HOME/.cache}/git/credential/socket"
/home/your-user/.cache/git/credential/socket

The helper's documented fallback is ~/.git-credential-cache/socket when the directory ~/.git-credential-cache/ exists. A custom socket must be an absolute path. If your home directory is on a network-mounted filesystem, choose a suitable local path and configure it explicitly:

$ git config --global credential.helper 'cache --socket=/run/user/1000/git-credential-cache/socket --timeout=900'

Replace 1000 with your user ID, found with id -u. The parent directory must exist and be writable by your user. This option changes where the client contacts the daemon; it does not make the cache persistent.

6. Clear cached credentials when finished

When the work is complete, explicitly stop the daemon and forget the cached credentials:

$ git credential-cache exit

The command normally produces no output. It is safe to run when no daemon is running. Afterward, the next operation that needs authentication should prompt again. This is the recovery command if you cached the wrong account or accidentally used a credential with the wrong remote.

To remove the configuration as well, run:

$ git config --global --unset-all credential.helper

That command changes your global Git configuration. It may return a non-zero status if no matching entry exists. Removing the configuration does not itself guarantee that an already-running daemon has forgotten its entries, so use git credential-cache exit first.

7. Know when this helper is the wrong fit

This helper is useful for a short interactive session, but it is deliberately not persistent. It is also only as private as the local user's Unix permissions and machine access. Anyone who can run code as your user may be able to use the cache through its socket.

For a credential that must survive a reboot, choose a persistent helper with an appropriate security model, such as an operating-system keyring or an OAuth helper supported by your Git host. Do not replace the in-memory cache with git-credential-store casually: that helper writes credentials to disk in a form that may not meet your security requirements.

Done means

  • git config --global --get-all credential.helper shows the intended cache setting.
  • An HTTPS Git operation can reuse a credential during the configured timeout.
  • You know the cache expires after the timeout or daemon failure, including a restart.
  • git credential-cache exit clears the session when you finish.
  • No credential is present in a remote URL, shell history or pasted command.