OAuth Tokens
Last updated
Where Copilot, Codex, and Grok tokens are stored, how to log in, and how refresh works.
Keychain storage
Tokens for the three OAuth providers are stored by go-pkg/filesystem/keychain in the system keychain (macOS Keychain, Linux secret-tool).
| Provider | Keychain key | Login |
|---|---|---|
| Copilot | COPILOT_OAUTH_TOKEN |
Device flow; LoginWithCallback yields a *DeviceCode to display |
| Codex | CODEX_OAUTH_TOKEN |
PKCE; LoginWithCallback yields the authorization URL |
| Grok | GROK_OAUTH_TOKEN |
PKCE, same shape |
All three fall back to the legacy key agenvoy.<provider>.token on read, so existing installs need no new login.
Using a stored token
token, err := codex.Load()
if err != nil {
return err
}
agent, err := router.New(router.Config{Name: "codex@gpt-5.1-codex", Token: token})
Refresh
EnsureFresh (EnsureFreshSession for Copilot) refreshes within 60 seconds of expiry and runs every time an agent builds its auth header, so a long-running process needs no refresh scheduler of its own.
Related
- OAuth Functions: signatures for
Load,LoginWithCallback,EnsureFresh