v0.8.4

OAuth Tokens

Last updated

Where Copilot, Codex, and Grok tokens are stored, how to log in, and how refresh works.

Keychain storage

Tokens for the three OAuth providers are stored by go-pkg/filesystem/keychain in the system keychain (macOS Keychain, Linux secret-tool).

Provider Keychain key Login
Copilot COPILOT_OAUTH_TOKEN Device flow; LoginWithCallback yields a *DeviceCode to display
Codex CODEX_OAUTH_TOKEN PKCE; LoginWithCallback yields the authorization URL
Grok GROK_OAUTH_TOKEN PKCE, same shape

All three fall back to the legacy key agenvoy.<provider>.token on read, so existing installs need no new login.

Using a stored token

token, err := codex.Load()
if err != nil {
    return err
}
agent, err := router.New(router.Config{Name: "codex@gpt-5.1-codex", Token: token})

Refresh

EnsureFresh (EnsureFreshSession for Copilot) refreshes within 60 seconds of expiry and runs every time an agent builds its auth header, so a long-running process needs no refresh scheduler of its own.

中文