Expand description
Provider auth flows: device-code/browser OAuth for the agent and PM providers, token extraction from vendor CLI artifacts, and store-direct persistence into lfdb provider tokens.
Shared home — called in-process by lf op auth and wrapped by the daemon’s
HTTP routes. Must not depend on daemon (lfd) types; auth lifecycle
notifications go through AuthEventSink, which the daemon maps onto its
EventHub and the CLI ignores.
Modules§
Structs§
- Auth
Flow Handle - Auth
Flow Response - Claude
Auth Broker - Codex
Auth Broker - Doppler
Auth Broker - GhAuth
Broker - Open
Code ZenBroker - Parse
Provider Error - Provider
Auth Service - Provider
Auth Snapshot - Socket
Auth Broker
Enums§
- Auth
Error - Auth
Event - Auth lifecycle notifications. The daemon maps these onto its EventHub; the CLI drops them — for a CLI caller the store write is the record.
- Auth
Status - Provider
- Token
Refresh Error
Traits§
Functions§
- api_
key_ env_ allowed_ for_ program - api_
key_ env_ names - env_
var_ for_ token - Return the env var name and value for a given provider token, based on its credential_type. This is the single decision point for executors.
- is_
api_ key_ env_ name - no_
event_ sink - provider_
env_ allowed_ for_ program - provider_
env_ vars - Build env vars for all stored provider tokens. Used by executors to inject credentials into agent processes. The env var chosen depends on the token’s credential_type (oauth vs apikey).
- refresh_
pm_ oauth_ token - Exchange a stored refresh token for a fresh access token via the PM provider’s
OAuth
grant_type=refresh_tokenendpoint. Linear is the supported PM provider; client credentials are read from the provider’s*_CLIENT_ID/*_CLIENT_SECRETenv vars. - refresh_
provider_ token