Skip to content

Refreshable tokens (5/7): gh auth status short-lived token details - #14454

Open
babakks wants to merge 1 commit into
babakks/refresh-token-c2-auth-tokenfrom
babakks/refresh-token-c3-auth-status
Open

babakks wants to merge 1 commit into
babakks/refresh-token-c2-auth-tokenfrom
babakks/refresh-token-c3-auth-status

Conversation

@babakks

@babakks babakks commented Sep 15, 2026 •

Copy link
Copy Markdown
Member

Part of #14449. Based on #14453 (auth token).

Description

Teaches gh auth status to show short-lived token details and to refresh the token as part of reporting status, so what it displays reflects a currently valid credential rather than a stale or expired one.

How did you test this change?

This feature is verified end to end as a whole rather than per PR. End-to-end tests should pass.

Key points

  • Status now surfaces the expiry information that a short-lived token carries and a non-expiring token does not. This makes the difference between a permanent and a refreshable credential visible to the user at a glance.
  • Reporting status resolves the active token, so it goes through the same refresh path as the other consumers (HTTP transport, gh auth token, the git credential helper). That means a short-lived token whose access token has expired is refreshed and reported as valid, rather than being surfaced as broken. Status reflects the credential gh would actually use, not a stale snapshot.
  • Because the refresh goes through the shared serialized path from PR 2, running gh auth status concurrently with another gh process cannot double-spend the refresh token.

Notes for reviewers

Focus on the status output formatting for the refreshable case and the point where resolving status triggers a refresh. Confirm the non-refreshable path is unchanged.

Commit:

  • fix(auth status): show and refresh short-lived token details

Authorship and follow-up

Who wrote this:

  • A human wrote it.
  • An agent wrote it under close human direction.
  • An agent wrote it independently, and no human has guided the implementation beyond the initial prompt.

Who answers review comments:

  • @babakks will read and reply directly.
  • An agent will draft replies and @username will read them before they are posted.
  • Nobody has explicitly committed to replying.

Refresh an expired or near-expiry refreshable token while reporting status,
unless --no-refresh is given, and show whether the token is short-lived, when it
expires, and whether it was just refreshed. Expose the refreshable and expiry
fields through the JSON output.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2dc3f23c-61a6-43a7-85cd-90aa872a7fc6

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant