Skip to main content

Signing Git Commits in VS Code and Visual Studio

· 2 min read
Mark Burton
Software Engineer & Technical Writer
Outdated guidance (2023)

This post focuses on GPG commit signing and is kept for historical reference.

For my current recommendation, read Migrating from GPG to SSH-Signed Git Commits (Forgejo, Codeberg, GitHub), where I explain why I now prefer SSH signing.

Install GnuPG​

Install GnuPG with Chocolatey:

choco install gnupg

Or download from Gpg4win.

Generate a New Key​

In PowerShell, run:

gpg --full-generate-key

You will be asked several questions. Based on the GitHub documentation at the time, choose:

  • 1 for RSA and RSA
  • 4096 for key length
  • 0 for no expiry

Example prompts:

Please select what kind of key you want:
(1) RSA and RSA
(2) DSA and Elgamal
(3) DSA (sign only)
(4) RSA (sign only)
(9) ECC (sign and encrypt)
(10) ECC (sign only)
(14) Existing key from card
Your selection?
RSA keys may be between 1024 and 4096 bits long.
What keysize do you want? (3072) 4096
Requested keysize is 4096 bits
Please specify how long the key should be valid.
0 = key does not expire
<n> = key expires in n days
<n>w = key expires in n weeks
<n>m = key expires in n months
<n>y = key expires in n years
Key is valid for? (0)

Use an email address that matches your Git identity.

Final Git Config​

Verify your global Git settings:

git config --global -l

Typical relevant entries:

user.signingkey=<your key id>
gpg.program=C:/Program Files (x86)/GnuPG/bin/gpg.exe
commit.gpgsign=true

Usage in VS Code​

Commit as normal in VS Code. You should be prompted for your GPG passphrase when required.

gpg prompt in VS Code

How Often to Sign Commits​

Signing every commit can feel tedious. GPG agent cache settings control how often you re-enter your passphrase.

Check current values:

gpgconf.exe --list-options gpg-agent

Look for values like:

default-cache-ttl:...:600::
max-cache-ttl:...:7200::

To sign less frequently, increase default-cache-ttl and max-cache-ttl to match your security posture.

Notes​

  • You may have two GPG installations on Windows (for example, Git-for-Windows plus Gpg4win).
  • A practical cache value for some workflows is 14400 seconds (4 hours).