Skip to main content

Module provider_auth

Module provider_auth 

Source
Expand description

Provider auth flows: device-code/browser OAuth for the agent and PM providers, token extraction from vendor CLI artifacts, and store-direct persistence into lfdb provider tokens.

Shared home — called in-process by lf op auth and wrapped by the daemon’s HTTP routes. Must not depend on daemon (lfd) types; auth lifecycle notifications go through AuthEventSink, which the daemon maps onto its EventHub and the CLI ignores.

Modules§

credential_socket

Structs§

AuthFlowHandle
AuthFlowResponse
ClaudeAuthBroker
CodexAuthBroker
DopplerAuthBroker
GhAuthBroker
OpenCodeZenBroker
ParseProviderError
ProviderAuthService
ProviderAuthSnapshot
SocketAuthBroker

Enums§

AuthError
AuthEvent
Auth lifecycle notifications. The daemon maps these onto its EventHub; the CLI drops them — for a CLI caller the store write is the record.
AuthStatus
Provider
TokenRefreshError

Traits§

AuthBroker

Functions§

api_key_env_allowed_for_program
api_key_env_names
env_var_for_token
Return the env var name and value for a given provider token, based on its credential_type. This is the single decision point for executors.
is_api_key_env_name
no_event_sink
provider_env_allowed_for_program
provider_env_vars
Build env vars for all stored provider tokens. Used by executors to inject credentials into agent processes. The env var chosen depends on the token’s credential_type (oauth vs apikey).
refresh_pm_oauth_token
Exchange a stored refresh token for a fresh access token via the PM provider’s OAuth grant_type=refresh_token endpoint. Linear is the supported PM provider; client credentials are read from the provider’s *_CLIENT_ID/*_CLIENT_SECRET env vars.
refresh_provider_token

Type Aliases§

AuthEventSink