Skip to main content

Authentication

The plugin requires authentication to access the GitLab API. You can sign in with OAuth2 (GitLab SaaS only) or with a personal access token (any instance).

OAuth2 (GitLab SaaS)​

  1. When prompted to authenticate, your default browser opens a GitLab authorization page.
  2. Log in to your GitLab account (if not already logged in) and authorize the plugin.
  3. Close the browser tab and return to the IDE — the credentials are stored automatically.

The plugin automatically refreshes your OAuth2 token in the background. If the refresh fails, you will be prompted to re-authenticate.

Completing Authorization Manually​

If the local callback cannot be reached (for example, it is blocked by a firewall, or you are signing in on a different machine), select Retrieve Auth Code Manually when prompted. The plugin then guides you through the following steps:

  1. The authorization link is copied to your clipboard. Paste it into any browser.
  2. Sign in and authorize the plugin.
  3. The browser redirects to a localhost page that shows an error — this is expected.
  4. Copy the entire URL from the browser's address bar and paste it back into the plugin.

Personal Access Token​

A personal access token is the only method for self-managed instances, and an alternative to OAuth2 on GitLab SaaS.

  1. In GitLab, open Edit profile → Access → Personal access tokens.
  2. Create a token with the api scope.
  3. Copy the generated token.
  4. When the plugin prompts for authentication, paste the token.

Changing Account​

To switch to a different GitLab account or change the authentication method, use the Change Account action in the GitLab Merge Requests tool window toolbar.

Default Account​

Check Use this account for other projects by default when logging in to reuse these credentials in any new project that connects to the same GitLab instance.

Credential Storage​

All credentials are stored securely in the IDE's built-in credential store (Settings | Appearance & Behavior | System Settings | Passwords). No passwords or tokens are stored in plain text or in project files.