# Add an email address

> Add an email address to your account. g1t emails it a link to confirm it; until then it cannot be primary and does not sign you in.

<div class="g1t-endpoint"><span class="g1t-method" data-method="post">POST</span><code>/user/emails</code></div>

Adding an address you added before and have not confirmed sends the link again. An address another account has confirmed cannot be added. An account has at most 10. Needs your account `password`; your confirmed addresses are told. People only.

Answers `403` with code `reauth_required` when `password` is missing or wrong, and `409` when another account has confirmed the address. The new address stays unconfirmed until its link is followed.

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`account`](/reference/mcp/#account) with `action` `add_email`, and the same inputs
- **Scope:** An access token needs [`account:write`](/guides/authentication/#scopes).

## Body parameters

Send a JSON object. Names are `snake_case`, as in responses; the `camelCase` spelling is accepted too.

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `email` | string | Yes | The address to add. |
| `password` | string | Yes | Your account password, to confirm it is you. An account that signs in only with GitHub changes its addresses on g1t.sh. |

## Example request

```sh
curl -X POST https://api.g1t.sh/user/emails \
  -H "Authorization: Bearer $G1T_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "email": "ada.l@example.org",
    "password": "…"
  }'
```

## Example response

A successful request answers `200` with:

```json
{
  "emails": [
    {
      "email": "ada@example.com",
      "verified": true,
      "primary": true,
      "backup": false,
      "created_at": "2026-09-01T10:00:00.000Z",
      "verified_at": "2026-09-01T10:02:11.000Z"
    },
    {
      "email": "ada@acme.com",
      "verified": true,
      "primary": false,
      "backup": true,
      "created_at": "2026-10-02T09:30:00.000Z",
      "verified_at": "2026-10-02T09:31:40.000Z"
    },
    {
      "email": "ada.l@example.org",
      "verified": false,
      "primary": false,
      "backup": false,
      "created_at": "2026-10-05T14:12:03.000Z",
      "verified_at": null
    }
  ],
  "private_email": true,
  "block_private_pushes": false,
  "noreply": "6c1d0efg+ada@users.noreply.g1t.sh",
  "commit_email": "6c1d0efg+ada@users.noreply.g1t.sh",
  "limit": 10
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 409 | `conflict` | The request conflicts with the current state. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
