# Change your email settings

> Change what your addresses do; only the fields given change.

<div class="g1t-endpoint"><span class="g1t-method" data-method="patch">PATCH</span><code>/user/email-settings</code></div>

`primary` is a confirmed address to make primary: account mail and password resets go there. `backup` is a confirmed address that also gets security notices, or an empty string for the primary only. Changing either needs your account `password`, and every confirmed address is told. `private_email` keeps your address off commits g1t makes for you (merges and changes made on the web, and agents' commits for you), which use your noreply address instead; `block_private_pushes` refuses pushes whose commits carry one of your addresses while it is private. People only.

Only the fields given change. `primary` and `backup` need `password`; `private_email` and `block_private_pushes` do not.

- **Authentication:** Required. Send an [access token](/reference/api/#authentication) as `Authorization: Bearer`.
- **MCP tool:** [`account`](/reference/mcp/#account) with `action` `update_email_settings`, and the same inputs
- **Scope:** An access token needs [`account:write`](/guides/authentication/#scopes).

## Body parameters

Send a JSON object. Names are `snake_case`, as in responses; the `camelCase` spelling is accepted too.

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `primary` | string | No | A confirmed address to make primary. |
| `backup` | string | No | A confirmed address that also gets security notices; an empty string for the primary only. |
| `private_email` | boolean | No | Use your noreply address on commits g1t makes for you. |
| `block_private_pushes` | boolean | No | Refuse pushes whose commits carry one of your addresses while it is private. |
| `password` | string | No | Your account password, to confirm it is you. An account that signs in only with GitHub changes its addresses on g1t.sh. |

## Example request

```sh
curl -X PATCH https://api.g1t.sh/user/email-settings \
  -H "Authorization: Bearer $G1T_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "primary": "ada@acme.com",
    "password": "…"
  }'
```

## Example response

A successful request answers `200` with:

```json
{
  "emails": [
    {
      "email": "ada@example.com",
      "verified": true,
      "primary": true,
      "backup": false,
      "created_at": "2026-09-01T10:00:00.000Z",
      "verified_at": "2026-09-01T10:02:11.000Z"
    },
    {
      "email": "ada@acme.com",
      "verified": true,
      "primary": false,
      "backup": true,
      "created_at": "2026-10-02T09:30:00.000Z",
      "verified_at": "2026-10-02T09:31:40.000Z"
    },
    {
      "email": "ada.l@example.org",
      "verified": false,
      "primary": false,
      "backup": false,
      "created_at": "2026-10-05T14:12:03.000Z",
      "verified_at": null
    }
  ],
  "private_email": true,
  "block_private_pushes": false,
  "noreply": "6c1d0efg+ada@users.noreply.g1t.sh",
  "commit_email": "6c1d0efg+ada@users.noreply.g1t.sh",
  "limit": 10
}
```

## Errors

A failed request answers with one of these statuses and a body like `{"error": {"code": "not_found", "message": "Repository not found."}}`. See [errors](/reference/api/#errors).

| Status | Code | When |
| --- | --- | --- |
| 401 | `unauthenticated` | A token is required, or the one sent is not valid. |
| 403 | `forbidden` | The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository. |
| 404 | `not_found` | It does not exist, or you cannot see it. |
| 409 | `conflict` | The request conflicts with the current state. |
| 422 | `invalid` | The input is not valid. `message` says which field and why. |
