ADSSPEED

GitHub

GitHub Keeps Logging Me Out and Asking to Verify My Device: Causes and Fixes

By ADSSPEED Team · Published · Updated · 6 min read

Why does GitHub keep asking me to verify my device or sign me out?

Usually because GitHub sees a sign-in it does not recognise, or because a session has run out. According to GitHub Docs (read 3 October 2026), the check applies to accounts without two-factor authentication (2FA): the first time you sign in from a device GitHub does not recognise, it may ask for extra verification. The page's examples are "a new computer or phone, a new browser, or new browser profile". A verified device normally stays verified, but wiping its cookies or opening a different browser on it can trigger the check again.

On a computer that holds several accounts, this is easy to meet: each new browser profile you open for another account can look like a new device to GitHub. GitHub describes the prompt as extra verification to confirm that it is you signing in.

What does each screen mean, and what does GitHub suggest?

What you seeCause according to GitHubWhat to do
Email with a verification codeNew or unrecognised device, 2FA not enabledEnter the code within one hour; it goes to every primary and backup address on the account
A code you did not requestGitHub says your password may have been compromisedChange your password at once and secure the account
Asked for a 2FA code againYou logged out, are using a new device, are performing a sensitive action, or your session expiredUse your authenticator app, security key or GitHub Mobile
Password prompt before a settings changeSudo mode, with a two-hour timeoutConfirm with your password, or a passkey, security key, GitHub Mobile or 2FA code
No Switch account optionAll saved sessions have expiredClick See all accounts and sign in again
Saved accounts gone after a breakSaved sessions end after two weeks without activity; SSO often ends after 1 or 24 hoursSign in again, and re-authenticate with your identity provider if SSO applies
Profile or search visibility limitedGitHub may restrict an account after suspicious activityFollow the restriction steps further down

How do you work through a device verification?

  1. Check that the page is github.com and that you are in the browser profile you meant to use.
  2. Open the email GitHub sent. The code is valid for one hour.
  3. If nothing arrives, remember that GitHub only sends it to the primary and backup addresses on the account. Make sure that mailbox can receive mail from GitHub, and wait a few minutes.
  4. If you have the GitHub Mobile app installed, GitHub sends a verification request to the phone instead of an email.
  5. Enter the code. You should not need to repeat it for that device unless its cookies are cleared or you use a different browser.
  6. Consider a stronger sign-in method. GitHub's page says that with 2FA enabled, or when you sign in with a passkey, it does not use this email verification, and that device verification cannot be switched off entirely without 2FA.

What if you cannot get the code or have lost your second factor?

  • No access to the email address. GitHub's page says you cannot verify the new device without the code. It suggests signing in from a device you have used before and adding an email address you can reach.
  • Lost 2FA credentials. At github.com/login, sign in with your username and password, choose 2FA recovery code under More options, and enter one of your recovery codes. GitHub's recovery page also describes routes that use a verified device, an SSH key or a personal access token; regaining access by authenticating with a one-time password can take up to three business days, and a password-reset link that GitHub emails you must be used within 3 hours.
  • Nothing works. GitHub says Support will not be able to restore access to a 2FA-protected account if you lose your 2FA credentials or your account recovery methods. The Account Recovery Policy adds that if no recovery method works, access is permanently lost, and that staff offer no social or ID verification route.

What if GitHub restricts or suspends the account?

GitHub's security page says suspicious activity can lead to a temporary restriction on your personal account, during which you can still sign in. Features such as your profile URL, contribution graph, search visibility and sensitive account actions may be switched off for a while, and in some cases GitHub suspends the account for security reasons instead. For a restricted account it lists these steps:

  1. Change your GitHub password.
  2. Look through your security settings and remove any apps, keys or other credentials you do not recognise.
  3. Make sure you can reach, and have secured, the email account tied to GitHub.
  4. Read the security emails GitHub sent, spam folder included, and follow their instructions.

If the restrictions stay after that, contact GitHub Support. If you were told to change the email address on the account, a separate page lists the steps: add a different, non-disposable address, verify it, make it primary, remove the old one, then ask Support to review the restriction.

If you disagree with a policy decision, use the Appeal and Reinstatement form. GitHub says you can seek reinstatement or appeal for up to six months after the decision. A replacement account is not a route any of these pages describe, and it would run into the one-free-account sentence explained in the rules guide.

How do you keep several accounts' sign-ins steady?

  • One profile per account. GitHub ties repeat prompts to cleared cookies and different browsers, so a profile that keeps its own cookies is verified once rather than again and again. See how to separate accounts with profiles.
  • Check Settings, then Sessions. GitHub lists active web sessions and GitHub Mobile sessions there. Revoke session ends a web session, and revoking a mobile session signs the app out and removes it as a second-factor option.
  • Read the security log. Under Settings, Security log lists actions from the last 90 days, including the country each one took place in.
  • Keep recovery details current. Recovery codes come as a set of 16, each usable once, and GitHub recommends saving them in a password manager.
  • After you change a password, GitHub's security page lists turning on 2FA, adding a passkey, reviewing SSH keys, deploy keys and authorised apps, verifying email addresses and reviewing the security log.

For the account switcher itself, see signing in to two accounts on one computer.

Where ADSSPEED fits

ADSSPEED is a desktop app for Windows and macOS that manages many browser profiles. Each profile keeps its own cookies, local data and browser settings, so every account you own or are authorised to manage stays signed in inside its own profile, without signing the others out. A new profile is a new browser profile, so GitHub may ask for the first-sign-in verification described above. Profile data stays on your own computer. ADSSPEED does not change GitHub's checks or rules and is not affiliated with GitHub.

Frequently asked questions

Why does GitHub keep logging me out?

A session may have expired. GitHub Docs (read 3 October 2026) says it asks for your 2FA code again only if you logged out, use a new device, perform a sensitive action or your session expires. The changelog on multi-account support adds that a saved session ends after two weeks without activity, and that single sign-on often ends after 1 or 24 hours.

Why does GitHub say please verify your device?

GitHub may ask for extra verification the first time you sign in from a new or unrecognised device when 2FA is not enabled. Its page lists a new computer or phone, a new browser or a new browser profile as examples, and says clearing cookies or using a different browser can trigger it again.

What can I do when GitHub cannot verify this device?

Check that the code went to the right place: GitHub sends it only to the primary and backup email addresses on the account, and it is valid for one hour. If you cannot reach that mailbox, GitHub suggests signing in from a device you have used before and adding an email address you can access.

How do I log out of GitHub on all devices?

Open Settings, then Sessions, where GitHub lists web sessions and GitHub Mobile sessions. Use Revoke session for a web session and Revoke for a mobile device. If you use the account switcher, Sign out from all accounts removes every saved account from it.

What should I do if my GitHub account is suspended?

Use GitHub's Appeal and Reinstatement form. According to that page, you can seek reinstatement or appeal a moderation decision for up to six months after the decision, and GitHub staff review what you submit. A replacement account is not a route the page describes.

Why is my GitHub verification or 2FA code not working?

Verification codes sent by email are valid for one hour. For authenticator-app codes, GitHub's troubleshooting page says the code is invalid if the clock on your phone or computer is out of sync with GitHub's server, so check the date and time and wait for a new code.

Sources

  1. GitHub Docs: Verifying new devices when signing in
  2. GitHub Docs: Viewing and managing your sessions
  3. GitHub Docs: Accessing GitHub using two-factor authentication
  4. GitHub Docs: Sudo mode
  5. GitHub Docs: Switching between accounts
  6. GitHub Changelog: Multi-account support on GitHub.com (3 November 2023)
  7. GitHub Docs: Recovering your account if you lose your 2FA credentials
  8. GitHub Docs: Configuring two-factor authentication recovery methods
  9. GitHub Docs: Troubleshooting two-factor authentication issues
  10. GitHub Account Recovery Policy
  11. GitHub Docs: Preventing unauthorized access
  12. GitHub Docs: Troubleshooting email verification
  13. GitHub Docs: Reviewing your security log
  14. GitHub Appeal and Reinstatement

Related guides

Run Android devices and browser profiles on your own PC

ADSSPEED manages many browser profiles and Android phone profiles from one app, each with its own device configuration, proxy and automation.