Skip to content

fix(claude): prefer current macOS Keychain credential - #6093

Open
AgentWrapper wants to merge 1 commit into
mainfrom
ao/agent-orchestrator-89/claude-keychain-auth
Open

AgentWrapper wants to merge 1 commit into
mainfrom
ao/agent-orchestrator-89/claude-keychain-auth

Conversation

@AgentWrapper

@AgentWrapper AgentWrapper commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Code changes: +21 -24
Tests: +54 -0
Others: +0 -0

Related issue: #6105. This fixes the reproduced Keychain credential-selection failure; the affected Mac’s Keychain state is unverified.

Summary

  • Prefer the current Claude Code macOS Keychain service when resolving a local Claude credential. Keep Claude Code-credentials as a fallback for older installations.
  • Reproduce a false signed-out result with both entries present: an obsolete OAuth credential gets HTTP 401 while the managed key succeeds. Before the change, AO selects the obsolete entry and marks Claude unauthorized; after the change, its provider probe accepts the managed key.

Validation

  • go test -race -count=1 ./pkg/agentcreds ./internal/adapters/agent/claudecode ./internal/service/agent — passed.
  • go build ./..., go vet ./..., golangci-lint v2.13.2 — passed.
  • go test -tags e2e -v ./internal/cli/... — passed with the AO session environment removed.
  • npm run sqlc and npm run api — passed with no generated-file drift.
  • Full go test -race -count=1 -timeout=20m ./... ran locally. The changed packages passed. Goose, tmux, CLI, and system-check failures cleared in a clean-environment rerun. Codex protocol conformance still fails against this machine's installed Codex version; it is unrelated to this change. Remote CI remains the full-suite gate.
  • The Docker fresh-install check and native Linux/Windows jobs were unavailable locally; verify their CI results.

Scope and risk

This proves one code path that can produce the reported mismatch; the reporter's Keychain contents have not been inspected. A stale Claude Code entry on a machine actively using an older Claude version and its legacy entry could cause the reverse mismatch. Environment-supplied credentials and differing Claude binaries are outside this fix.

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

🏆 Review leaderboard

Sep 24, 2026–Oct 1, 2026 · UTC

Rank Reviewer PRs reviewed Review rounds PR comments
🥇 @nikhilachale @nikhilachale 26 54 8
🥈 @illegalcall @illegalcall 24 47 8
🥉 @ronishrohan @ronishrohan 23 33 9
4 @Prasad-D-Ware @Prasad-D-Ware 15 33 3
5 @codebanditssss @codebanditssss 13 21 1
6 @mohakchakraborty2004 @mohakchakraborty2004 8 8 4
7 @Annieeeee11 @Annieeeee11 6 14 5
8 @harshitsinghbhandari @harshitsinghbhandari 5 7 0
9 @neversettle17-101 @neversettle17-101 5 6 4
10 @Vaibhaav-Tiwari @Vaibhaav-Tiwari 5 5 2

Ranked by distinct external PRs reviewed, then review rounds, then PR comments. Self-activity and bot activity are excluded.

Show 9 more reviewers
Rank Reviewer PRs reviewed Review rounds PR comments
11 @Rishet11 @Rishet11 2 2 9
12 @Pritom14 @Pritom14 2 2 2
13 @Pulkit7070 @Pulkit7070 2 2 1
14 @somewherelostt @somewherelostt 1 3 2
15 @ApexYash11 @ApexYash11 1 2 2
16 @AgentWrapper @AgentWrapper 1 1 0
17 @aprv10 @aprv10 1 1 0
18 @Ayash-Bera @Ayash-Bera 1 1 0
19 @LaibaFirdouse @LaibaFirdouse 1 1 0

@i-trytoohard i-trytoohard added bug Something isn't working comp/daemon Go daemon, process lifecycle, and backend control plane. labels Oct 1, 2026
@i-trytoohard i-trytoohard added this to the Agents & orchestration milestone Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working comp/daemon Go daemon, process lifecycle, and backend control plane.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants