Tokens + Two factor authentication #29220

Aug 12, 2022 · 1 answer
Can we have the option to require two-factor authentication when using tokens?

Seems unlikely, it'd be hard to do automation with Git over HTTPS otherwise (at least without major changes to all clients). And the token requirement was introduced somewhat recently, it's mandatory since about a year ago. 😅

For stronger authentication, look at using Git over SSH. That way you do public key authentication (your private key never needs to leave your machine) instead of a token that's basically a shared secret. The key file can be stored encrypted, or you can even use a key stored in a hardware token (the sk-* key types).

