Skip to content

Token updates, cleanup, and batch maintenance

Goal Command Scope
Refresh the repository value from current configuration chatgh set-token --from-config One repository Git token item
Remove the previously configured value chatgh unset-token The same target and key as set
Update repositories from a maintenance file chatgh set-token --from-config --file repositories.json Validated targets in that file

Set and unset operate on the same configuration item

set-token writes or updates the repository HTTPS token configuration. unset-token uses the same origin-first GitHub remote selection and deletes that exact item. Tracking a different upstream does not make unset remove another remote's value.

Unset does not decode, inspect, or validate a token. Expired, malformed, or empty values are removed as the same configuration item. It does not resolve a default credential, scan other keys, or operate on other repositories. An absent item succeeds with removed_count=0.

chatgh set-token --from-config
chatgh unset-token

These commands modify repository Git configuration, not GitHub token revocation. Existing API and transport precedence remains explicit value, matching repository configuration, then current typed configuration.

Refresh from configuration

--from-config reads the current typed GitHub configuration rather than reusing an old repository token. It is mutually exclusive with --token. Without the flag, the existing interactive and selection behavior remains available.

chatgh set-token --from-config --dry-run --json-output
chatgh set-token --from-config --json-output

Neither a token nor its encoded authorization header enters Git child-process arguments or result output. On POSIX, the repository configuration is made user-private before secret writes, while unrelated Git values remain unchanged.

JSON/YAML repository maintenance file

The file contains targets, never credentials. Relative paths are resolved from the manifest directory. Optional repo asserts that the checkout still points to the expected repository. Replace these paths with real checkouts.

{
  "version": 1,
  "repositories": [
    {"path": "./first-repo", "repo": "example/first-repo"},
    {"path": "./second-repo"}
  ]
}

Equivalent YAML:

version: 1
repositories:
  - path: ./first-repo
    repo: example/first-repo
  - path: ./second-repo

Preview, then apply:

chatgh set-token --from-config --file repositories.json --dry-run --json-output
chatgh set-token --from-config --file repositories.json --json-output
chatgh set-token --from-config --file repositories.yaml --json-output

Batch mode requires --from-config or an explicit --token, and cannot use --save-env. Every target is preflighted before token resolution or writes; invalid paths, mismatched repository assertions, and unsupported fields fail the whole preflight. Duplicate paths or worktrees sharing the same Git config and key are updated once.

Apply processes targets individually and reads their values back. Results include requested, total, duplicates_skipped, configured, failed, and per-target status. Any write failure gives a nonzero exit status; partial success is never reported as complete success. Dry runs do not write configuration.

Python API

from chatgh.github.commands import set_token
from chatgh.github.transport import unset_token

plan = set_token(None, False, from_config=True,
                 repo_file="repositories.json", dry_run=True)
result = set_token(None, False, from_config=True,
                   repo_file="repositories.json")
removed = unset_token(cwd="./first-repo")

Keep maintenance files in the operator's private configuration directory; do not commit real machine paths or credentials to public repositories. Unset has no broad cleanup mode. Other released commands retain their behavior.