# New github authentication

**URL:** <https://discourse.julialang.org/t/new-github-authentication/52234>\
**Category:** Offtopic\
**Tags:** github, ssh\
**Created:** [December 22, 2020, 5:23pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234 "2020-12-22T17:23:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![lmiq](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/lmiq/32/18314_2.png) [@lmiq](https://discourse.julialang.org/u/lmiq)\
**Post date:** [December 22, 2020, 5:23pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/1 "2020-12-22T17:23:11Z")

</div>

I am receiving emails from github warning me that password access will be disabled.

Following the docs links they send me, it seems that I have to generate a “token” and use that as a password from now on. That is a long string, that I will obviously have to store non-protected in my computer. On one side, having to find, copy and paste the token every time I commit something is very annoying. One the other side, that does not seem more secure that a password, since I have to store it in my machine.

What it the reasonable way to proceed here? Any tips?

---

<div class="post-metadata">

**Author:** ![pbayer](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/pbayer/32/11675_2.png) [@pbayer](https://discourse.julialang.org/u/pbayer)\
**Post date:** [December 22, 2020, 5:29pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/2 "2020-12-22T17:29:02Z")

</div>

I use Enpass for my passwords and put my GitHub PAT there. Still in case I have to copy it from there. But this is safe and convenient.

---

<div class="post-metadata">

**Author:** ![Skoffer](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/skoffer/32/378_2.png) [@Skoffer](https://discourse.julialang.org/u/Skoffer)\
**Post date:** [December 22, 2020, 5:37pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/3 "2020-12-22T17:37:02Z")

</div>

If it is for commits, then why don’t you want to use common ssh keys? You can password protect them if you want too. They’ve been around for a very long time and secure and reliable.

---

<div class="post-metadata">

**Author:** ![lmiq](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/lmiq/32/18314_2.png) [@lmiq](https://discourse.julialang.org/u/lmiq)\
**Post date:** [December 22, 2020, 5:40pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/4 "2020-12-22T17:40:51Z")

</div>

Yes, I am trying that now. But I am struggling a bit to find out how to clone, commit, push, etc, using the ssh key. I have added the public key to the account, but the docs on what to do next are not very clear.

I found a clear tutorial now, and cloning the repo using this makes the ssh work:

```julia
git clone git@github.com:NAME/package.jl

```

(the tutorial, this one very clear, is here, but in portuguese: [Usando chaves SSH com o Git - Linux Kamarada](https://kamarada.github.io/pt/2017/04/09/usando-chaves-ssh-com-o-git/#.X-IwBNZ7ldM))

---

<div class="post-metadata">

**Author:** ![aramirezreyes](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/aramirezreyes/32/42573_2.png) [@aramirezreyes](https://discourse.julialang.org/u/aramirezreyes)\
**Post date:** [December 22, 2020, 5:45pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/5 "2020-12-22T17:45:26Z")

</div>

I think that after doing that you only need to change your repository’s remote url to use ssh instead of https. After that, you just push commit and pull the way you have been doing it.

You can see if you are using https by doing:

`git remote -v` in your repo. If the urls start with https, then you can change it to ssh.

from [here](https://docs.github.com/en/free-pro-team@latest/github/using-git/changing-a-remotes-url#switching-remote-urls-from-https-to-ssh):

### [Switching remote URLs from HTTPS to SSH](https://docs.github.com/en/free-pro-team@latest/github/using-git/changing-a-remotes-url#switching-remote-urls-from-https-to-ssh)

1. Open Terminal.
2. Change the current working directory to your local project.
3. List your existing remotes in order to get the name of the remote you want to change.

```julia-auto
$ git remote -v
> origin https://github.com/USERNAME/REPOSITORY.git (fetch)
> origin https://github.com/USERNAME/REPOSITORY.git (push)

```

1. Change your remote’s URL from HTTPS to SSH with the `git remote set-url` command.

```julia-auto
$ git remote set-url origin git@github.com:USERNAME/REPOSITORY.git

```

1. Verify that the remote URL has changed.

```julia-auto
$ git remote -v
# Verify new remote URL
> origin git@github.com:USERNAME/REPOSITORY.git (fetch)
> origin git@github.com:USERNAME/REPOSITORY.git (push)

```

---

<div class="post-metadata">

**Author:** ![oxinabox](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oxinabox/32/206603_2.png) [@oxinabox](https://discourse.julialang.org/u/oxinabox)\
**Post date:** [December 22, 2020, 5:52pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/6 "2020-12-22T17:52:42Z")

</div>

> [@lmiq](#):
>
> I am receiving emails from github warning me that password access will be disabled.

AFAIK they are only disabling Username + Password for API Access  
Not for their website, nor for making commits.

> **[Deprecated APIs and authentication](https://developer.github.com/changes/2019-11-05-deprecated-passwords-and-authorizations-api/#authenticating-using-passwords)**
>
> Get started with one of our guides, or jump straight into the API documentation.

I didn’t even know that github let your auth for the API using password and username,  
and i have been using github API since long before November 2019.

Instead of doing passoword you do the OATH process with a token – like every other web API.  
Storing these tokens is always a bit annoying, i generally put them in a little bash-script that stores them into enviroment variables. Which is hella insecure, but also since they are tokens (and not my actual credentials) I have them created with restricted permissions – read only, no write.  
And i can (and occationally do) redactly them when i am finished with them.

It would be really nice to have a OAuth package for julia that can do the full OAth flow, and that started up a locally HTTP.jl server to accept the token etc, and has some built in encyption so you can have it hidden behind a user provided password.

---

<div class="post-metadata">

**Author:** ![lmiq](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/lmiq/32/18314_2.png) [@lmiq](https://discourse.julialang.org/u/lmiq)\
**Post date:** [December 22, 2020, 6:04pm UTC](https://discourse.julialang.org/t/new-github-authentication/52234/7 "2020-12-22T18:04:15Z")

</div>

> [@oxinabox](#):
>
> API Access

Probably it doesn’t help the fact that I do not know what exactly the API is ☹ . I get those messages and my reaction is: what can I do to be sure I won’t loose access to my account? And following their links one gets into a spiral of options, with me having to install applications in the phone between them. I start to feel like my father, who is an active computer scientist and is incapable of printing a pdf file. Time to start training my baby to help me with the new technologies.

---

<div class="post-metadata">

**Author:** ![dilumaluthge](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/dilumaluthge/32/29283_2.png) [@dilumaluthge](https://discourse.julialang.org/u/dilumaluthge)\
**Post date:** [December 23, 2020, 1:31am UTC](https://discourse.julialang.org/t/new-github-authentication/52234/8 "2020-12-23T01:31:38Z")

</div>

> Additionally, today we are announcing our intent to similarly require the use of a personal access token, OAuth token, or SSH key for all authenticated Git operations at a future date.

IIUC, “Git operations” means command-line Git operations.

> **[Token authentication requirements for API and Git operations](https://github.blog/2020-07-30-token-authentication-requirements-for-api-and-git-operations/)**
>
> Beginning November 13th, 2020, we will no longer accept account passwords when authenticating with the GitHub REST API. In the future, we will similarly no longer accept account passwords when authenticating Git operations.
