ADSSPEED

GitHub

How to Give a Team or a Client Access to GitHub Without Sharing a Login

By ADSSPEED Team · Published · Updated · 6 min read

Can a team use GitHub without sharing one login?

Yes. GitHub's model gives each person their own login and puts the shared work in an organization. According to GitHub Docs (read 3 October 2026), an organization is a shared account where many people collaborate across many projects, but you cannot sign in to an organization: each person signs in to their own personal account. The Terms of Service back this up: each login is for one person, and sharing a single login among several people is not allowed.

GitHub also says you cannot create personal accounts on behalf of another person, so each teammate or client creates their own and you invite them. Enterprises that use Enterprise Managed Users work differently: members are provisioned and managed through the company's identity provider.

Which roles can you give people?

Organization owners assign roles to individuals and teams. These are the organization-level roles GitHub describes:

RoleWhat GitHub says
OwnerFull administrative control; keep the group small, but never fewer than two people
MemberThe standard non-administrative role; by default members can create repositories and projects
ModeratorA member with extra moderation tools: blocking and unblocking contributors from outside the organization, interaction limits, and hiding comments in public repositories
Billing managerHandles billing settings such as payment details
Security managerA role at organization level that an owner can give to any member or team
GitHub App managerA user or team an owner designates to manage the settings of some or all GitHub App registrations the organization owns; it does not grant access to install or uninstall apps
Outside collaboratorWorks in one or more of the organization's repositories without being a member, for example a consultant or temporary staff

Repository access has its own ladder. GitHub recommends Read for non-code contributors who want to view or discuss the project, Triage for people who manage issues, discussions and pull requests without write access, Write for contributors who push, Maintain for project managers who need no sensitive or destructive actions, and Admin for people who need full access. Custom repository roles need GitHub Enterprise Cloud.

How do you set up access for a client or a contractor?

GitHub's page on creating an organization for a client lists these steps among others:

  1. From your own personal account, create the organization.
  2. Open the People tab, click Invite member, search for the client's username and select Owner. You cannot go on until the client accepts.
  3. When the client is listed as an owner, use Manage, then Remove from organization next to your own name.
  4. If you still need a role, the page suggests asking the client to add you as a billing manager.

For a contractor who should touch only some repositories, use an outside collaborator instead. GitHub says outside collaborators cannot be added to teams, and that if the organization requires two-factor authentication they must enable it before accepting. Invitations by username or email expire after seven days, and an invitation by email can only be accepted if it matches a verified email address on the invitee's account.

How do you protect shared access: 2FA, SSO and bots?

  • Require 2FA. Owners can make it mandatory for members, outside collaborators and billing managers. Members and billing managers who have not enabled it are locked out of the organization's resources until they do. Outside collaborators who have not are removed and lose access, and GitHub says you can reinstate those collaborators within three months if they enable 2FA. A sole owner cannot turn off 2FA on their own account without also turning off the requirement.
  • Use SSO where you have it. GitHub's SSO page (in the Enterprise Cloud edition of its docs) says members are redirected to the organization's identity provider, must re-authenticate periodically (24 hours unless the provider says otherwise), and must authorize any personal access token or SSH key before using it with the organization.
  • Give automation its own identity. The Terms allow machine accounts, and GitHub's deploy-keys page lists deploy keys (access to a single repository), GitHub App installation tokens and machine users as options. For a shared bot account that requires 2FA, GitHub suggests a mailing list of account owners as the verified email, the authenticator secret kept in the organization's password manager, and password resets instead of a stored password.
  • Treat tokens like passwords. GitHub says personal access tokens are tied to the user who made them and become inactive if that user loses access to the resource.

How do you off-board someone?

  1. In the organization, open People, select the person, open the selected-members menu and choose Remove from organization.
  2. Expect these effects, per GitHub: private forks of the organization's private repositories stop being accessible to the person, though copies already on their computer remain; their membership data is saved for three months; and under volume license billing the paid license count does not downgrade by itself.
  3. For an outside collaborator, use Outside collaborators in the People sidebar, then Remove from all repositories. GitHub notes that you remain responsible for making sure people who lost access delete confidential material.
  4. With SAML single sign-on, open the member's SAML identity linked page to revoke the linked identity or an active session. Revoking a credential cancels only its SAML authorization; the token or key itself stays.
  5. Check ownership before an owner leaves: owners can change other people's roles but not their own.

What if something goes wrong?

  • The only owner is unreachable. GitHub says the organization's projects can become inaccessible, so keep at least two owners.
  • An invitation was never accepted. It expires after seven days; the invitation page has a section on retrying or cancelling expired invitations.
  • Someone returns after leaving. Within three months you can reinstate their role, private forks, team memberships and permissions, provided a license is free on a paid per-user plan.
  • Someone asks for your password. Do not hand it over. Invite them with their own account instead; the rules guide covers what GitHub's Terms and impersonation policy say about shared logins and borrowed credentials.

Where ADSSPEED fits

ADSSPEED does not replace organization roles, and it does not change what GitHub allows. It is a desktop app for Windows and macOS that manages many browser profiles. Each profile keeps its own cookies, local data and browser settings, so a person who works across several accounts they own or are authorised to manage, such as a personal account and a work account, can keep each signed in side by side. Profiles can be opened, stopped and organised in bulk. See also the profiles guide. ADSSPEED is not affiliated with GitHub.

Frequently asked questions

How do I log in to a GitHub organization?

You do not. According to GitHub Docs (read 3 October 2026), you cannot sign in to an organization; each person signs in to their own personal account, and the roles and repository permissions on that account decide what they can reach inside the organization.

What is the difference between a GitHub organization and an enterprise?

GitHub describes organizations as shared accounts where many people collaborate across many projects. Enterprise accounts, part of GitHub Enterprise Cloud and GitHub Enterprise Server, let administrators centrally manage policy and billing for multiple organizations.

Can multiple users share one GitHub account on the same computer?

No. The Terms of Service reserve each login for one person and rule out sharing a single login among several people. Machine accounts for automation are the exception: several people may direct one, but its owner remains responsible for what it does.

How do I add a client or freelancer to a GitHub organization?

Invite them as an outside collaborator, which GitHub describes as someone with access to one or more organization repositories who is not a member, such as a consultant. They cannot be added to teams, and they must enable 2FA before accepting the invitation if the organization requires it.

How many owners should a GitHub organization have?

At least two. GitHub says an organization with only one owner can become inaccessible if that owner is unreachable, and its role page says the owner role should be limited but to no fewer than two people. Owners can change other people's roles but not their own.

What happens when I remove a member from a GitHub organization?

GitHub says removed members lose access to private forks of the organization's private repositories, though they may keep local copies. Their membership data is saved for three months, so you can restore it if you invite them back within that time.

Can I create GitHub accounts for my employees?

Not personal accounts. GitHub says you cannot create personal accounts on behalf of another person, so each team member creates their own and you invite them. With Enterprise Managed Users, members are instead provisioned and managed through your identity provider.

Sources

  1. GitHub Docs: Types of GitHub accounts
  2. GitHub Docs: Can I create accounts for people in my organization?
  3. GitHub Terms of Service (effective date shown: 27 April 2026)
  4. GitHub Docs: Roles in an organization
  5. GitHub Docs: Repository roles for an organization
  6. GitHub Docs: Maintaining ownership continuity for your organization
  7. GitHub Docs: Creating and paying for an organization for a client
  8. GitHub Docs: Inviting users to join your organization
  9. GitHub Docs: Adding outside collaborators to repositories in your organization
  10. GitHub Docs: Requiring two-factor authentication in your organization
  11. GitHub Docs: Managing bots and service accounts with two-factor authentication
  12. GitHub Docs: About authentication with single sign-on (Enterprise Cloud)
  13. GitHub Docs: Viewing and managing a member's SAML access to your organization (Enterprise Cloud)
  14. GitHub Docs: Removing a member from your organization
  15. GitHub Docs: Removing an outside collaborator from an organization repository
  16. GitHub Docs: Managing deploy keys
  17. GitHub Docs: Managing your personal access tokens

Related guides

Run Android devices and browser profiles on your own PC

ADSSPEED manages many browser profiles and Android phone profiles from one app, each with its own device configuration, proxy and automation.