# OAuth Tokens

Where Copilot, Codex, and Grok tokens are stored, how to log in, and how refresh works.

## Keychain storage

Tokens for the three OAuth providers are stored by `go-pkg/filesystem/keychain` in the system keychain (macOS Keychain, Linux `secret-tool`).

| Provider | Keychain key | Login |
|---|---|---|
| Copilot | `COPILOT_OAUTH_TOKEN` | Device flow; `LoginWithCallback` yields a `*DeviceCode` to display |
| Codex | `CODEX_OAUTH_TOKEN` | PKCE; `LoginWithCallback` yields the authorization URL |
| Grok | `GROK_OAUTH_TOKEN` | PKCE, same shape |

All three fall back to the legacy key `agenvoy.<provider>.token` on read, so existing installs need no new login.

## Using a stored token

```go
token, err := codex.Load()
if err != nil {
	return err
}
agent, err := router.New(router.Config{Name: "codex@gpt-5.1-codex", Token: token})
```

## Refresh

`EnsureFresh` (`EnsureFreshSession` for Copilot) refreshes within 60 seconds of expiry and runs every time an agent builds its auth header, so a long-running process needs no refresh scheduler of its own.

## Related

- [OAuth Functions](/api-reference-oauth): signatures for `Load`, `LoginWithCallback`, `EnsureFresh`
