GitHub
Rule | GitHub |
|---|---|
Min length | 1 |
Max length | 39 |
Allowed characters | Letters (a-z, A-Z), numbers (0-9), hyphen ( |
Case-sensitive | No |
Numbers allowed | Yes |
Can change later | Yes, at any time, no cooldown, but the old username is released for anyone to claim |
How handles work on GitHub
The username is the primary identifier and it's structural, not cosmetic: it's the first path segment of every repository URL (github.com/username/repo), every profile link, every git clone command, and every @mention in an issue or pull request. GitHub does have a separate, optional display "Name" field shown alongside the username on the profile, but it never substitutes for the username anywhere functional, so GitHub sits closer to X's handle-as-primary pattern than to Instagram's handle-secondary one.
GitHub pushes the username further into "infrastructure" territory than any other platform in this set: a repository named exactly username.github.io is auto-published as a live website at https://username.github.io, per GitHub's Pages quickstart, so the handle doubles as a free subdomain the moment it's claimed. The username is also baked into the private commit-email GitHub issues by default, in the form [email protected], per GitHub's email address docs, meaning a username change silently changes the email address tied to past commits too (see Naming requirements below for what that breaks).
Usage culture leans toward real names or close variants, more than TikTok or X. Because a GitHub profile doubles as a public work history and a link people put on resumes, a large share of individual accounts use a real name, a real-name variant, or a stable professional handle carried across other developer platforms. Organization accounts (repos owned by a company or project rather than a person) sit in the same namespace and follow the same naming rules, which is why a personal username and a company name can collide.
A handle like bundy2038933 reads as unusual here specifically because GitHub doesn't auto-append digits the way some signup flows do; a long numeric tail on GitHub more often signals a throwaway or bot account than "the short version was taken." bundyfit reads as a normal individual or small-project handle. real-bundy is the natural GitHub-flavored version of that idea, since GitHub allows hyphens but not periods or underscores in usernames (see Naming requirements below), so a "real" prefix has to be hyphen-joined here rather than period-joined the way it might be on Instagram.
The username can be changed at any time with no cooldown, but the mechanics carry more real risk than on most platforms: GitHub auto-redirects most repository and profile links to the new username, but only until someone else claims the old username and creates a repository with the same name, at which point that redirect breaks permanently and old links, clone URLs, and git remote configs pointing at the previous name will 404, per GitHub's own username-change docs. @mentions and gist links using the old username don't redirect at all, per GitHub's username reference, and commits signed with the old auto-generated noreply email lose their "Verified" badge and can drop out of the contribution graph once the username changes.
Because the old name becomes available immediately, changing a well-known GitHub username also opens a window for someone else to register it, which is a squatting/impersonation risk unique to how central the username is on this platform. GitHub does give its most-cloned repositories a permanent shield against exactly this: an owner/repository combination is "retired" forever, blocking anyone from recreating it, if it had more than 100 clones or 100 GitHub Actions uses in the week before the rename, or if it hosts a Marketplace-listed Action, per GitHub's username reference. Everything under that popularity bar is unprotected, which is precisely the gap security researchers at Checkmarx used in 2021 to demonstrate "RepoJacking": re-registering a renamed account's old username, recreating its repository, and hijacking traffic from over 10,000 downstream packages across Packagist, Go, and Swift that still pointed at the old namespace, per SecurityWeek's coverage. GitHub shipped a full fix in September 2022, but the underlying lesson holds for any account below the 100-clone threshold: a rename is not a clean break, it's a namespace up for grabs.
Naming requirements
app.services has no row for github (service_id = 2004) with a name_policy_expression set; the column is null, which per the schema means Coiner26 does not enforce a mandatory format for this platform beyond the generic availability check. The specifics below are GitHub's own published rules, sourced directly from GitHub's documentation rather than the live rules engine:
Minimum length: 1 character
Maximum length: 39 characters
Allowed characters: letters (a-z, A-Z), numbers (0-9), and hyphens (
-); no periods, underscores, or spacesDisallowed patterns: can't start or end with a hyphen; can't contain two consecutive hyphens, per GitHub's username format rules
Case sensitivity: case-insensitive for uniqueness and routing, but the case you set is preserved for display
Mutability: can be changed at any time with no fixed cooldown, but the old username is released immediately and can be claimed by anyone else, breaking any redirect
FAQ
Can I change my GitHub username later?
Yes, at any time, with no cooldown period. The catch is that your old username is released immediately and can be claimed by someone else, which permanently breaks GitHub's redirect for your old links and clone URLs once that happens.
Does GitHub allow numbers/hyphens in usernames?
Yes to both, but not periods or underscores. GitHub usernames are limited to letters, numbers, and hyphens, and a hyphen can't lead, trail, or repeat consecutively.
What happens to inactive GitHub usernames?
GitHub does not release inactive usernames on request. Its username policy states plainly that it does not accept requests to release, transfer, or reclaim a username on the basis that it appears inactive, since activity on GitHub isn't all publicly visible.
Is GitHub username case-sensitive?
No, not for uniqueness or routing (github.com/BundyFit and github.com/bundyfit resolve to the same account), though the capitalization you set displays as-is on your profile and in links.
What's the difference between a GitHub username and the display name?
The username is the unique identifier used in every URL, clone command, and @mention, capped at 39 characters and limited to letters, numbers, and hyphens. The optional display "Name" field shown on the profile doesn't have to be unique, can contain spaces and most characters, and is never used in links or mentions.
Do GitHub organizations follow the same username rules?
Yes. Personal accounts and organization accounts share one global namespace and the same format rules, which is why a company or project name can be unavailable simply because an individual already holds it as a personal username.
Does my GitHub username double as a website address?
Yes. A repository named exactly username.github.io publishes automatically as a live site at https://username.github.io through GitHub Pages, so claiming the username also claims a free subdomain, something none of the other platforms in this series do.
Is it safe to reuse a GitHub username after someone else changes theirs away from it?
Mostly, but not always right away. GitHub permanently "retires" an old owner/repository combination, blocking anyone from recreating it, when the repository had over 100 clones or Actions uses the week before the rename, or hosted a Marketplace-listed Action. Below that popularity threshold, the old username and repo name are free to reclaim, which is the exact mechanism security researchers used in 2021 to demonstrate the "RepoJacking" supply-chain attack before GitHub closed the gap in September 2022.
Reserved names & impersonation policy
GitHub reserves a set of system and special-purpose names (examples cited in GitHub's own reserved-names documentation include terms like admin, enterprise, login, staff, and support), which can't be registered as a personal or organization account name regardless of length or character validity.
GitHub's Username Policy explicitly prohibits name squatting: usernames "may not be reserved or inactively held for future use," and GitHub states it "may remove or rename" accounts that violate this, as well as suspend accounts that attempt to sell, buy, or solicit payment for a username. For a name that collides with an existing trademark, GitHub's Trademark Policy is explicit that usernames are first-come, first-served and that holding a name matching a registered trademark isn't automatically a violation; GitHub only acts when there's clear intent to mislead users into thinking the account represents the trademark holder, in which case it may suspend the account or release the username to the trademark owner. GitHub does not offer a verified-badge system tied to name protection the way consumer social platforms do; its identity signals are tied to the account's actual contribution history and, for organizations, domain/email verification rather than a checkmark.
What happens if it's taken
GitHub's stated policy is that it does not release, transfer, or reclaim a username on the basis of apparent inactivity: as of GitHub's own username policy page, it is "no longer accepting requests to release dormant usernames," full stop, regardless of how long the account has been silent.
The only route GitHub reviews for releasing an already-claimed username is a valid trademark complaint filed through its Trademark Policy process, and even then GitHub's stated preference is to first give the account holder a chance to clear up any confusion before it suspends the account or reassigns the name. There's no separate impersonation-report fast path the way there is on consumer platforms; trademark is the mechanism.
Realistically, waiting out a dormant GitHub username is not a viable strategy, and there's no marketplace or request queue to speed it up. If you don't hold the trademark and the account isn't actively impersonating you, picking a hyphenated variant is the practical path.
Tips for landing a good handle
Use a hyphen where you might use a period or underscore elsewhere (
bundy-fitinstead ofbundy.fitorbundy_fit), since GitHub is the one major platform in this set that allows hyphens but not periods or underscoresKeep it inside the 39-character ceiling, which is generous compared to X or TikTok, so a full name or a name-plus-role combination (
bundy-dev,bundyfit-labs) is often still workable here even when it's cramped elsewhereIf you plan to register both a personal account and an organization for the same project, check both up front: personal and organization names share one namespace, so claiming one doesn't reserve the other
Since GitHub won't release a dormant name on request, don't build a plan around waiting; a close hyphenated variant is more reliable than a trademark complaint unless you actually hold the mark
Check the name across every platform at once before settling on a GitHub-specific hyphenated variant, so it stays as consistent as possible with your handle elsewhere
Treat a rename as a migration, not a toggle: update remote URLs, re-point CI/package-manager references, and expect signed commits under the old noreply email to lose their "Verified" badge, since GitHub's redirect and namespace-retirement protections only cover part of what breaks
Check if your username survived the clone-URL rush on GitHub