Skip to content

Name unsupported Claude OAuth token in CLI secret setup - #66669

Merged
pelikhan merged 4 commits into
mainfrom
copilot/deep-report-name-unsupported-clause-code-oauth-tok
Oct 7, 2026
Merged

pelikhan merged 4 commits into
mainfrom
copilot/deep-report-name-unsupported-clause-code-oauth-tok

Conversation

Copilot AI commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Claude Code users with only CLAUDE_CODE_OAUTH_TOKEN receive an unclear authentication failure because gh-aw does not support that credential.

  • Credential diagnosis: When Claude secret setup finds only that token, report it as unsupported and point to ANTHROPIC_API_KEY or Anthropic Workload Identity Federation. Never include the token value in the error.
  • Credential precedence: Continue accepting a supported API key from the environment or an existing repository secret.
  • Coverage: Add focused tests for interactive and trial-run secret setup.

Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Add support for CLAUDE_CODE_OAUTH_TOKEN authentication Name unsupported Claude OAuth token in CLI secret setup Oct 7, 2026
Copilot AI requested a review from pelikhan October 7, 2026 19:53
@pelikhan
pelikhan marked this pull request as ready for review October 7, 2026 20:09
Copilot AI balanced review requested due to automatic review settings October 7, 2026 20:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

An existing credential-resolution test becomes dependent on the developer’s ambient Claude OAuth environment.

1 open finding
What changed in this PR

Adds explicit diagnostics when Claude secret setup encounters only the unsupported OAuth token.

Changes:

  • Detects CLAUDE_CODE_OAUTH_TOKEN without exposing its value.
  • Preserves supported API-key and repository-secret precedence.
  • Adds interactive and secret-resolution tests.
File Description
pkg/​cli/​engine_secrets.go Adds unsupported-token detection and guidance.
pkg/​cli/​engine_secrets_test.go Tests detection and credential precedence.
pkg/​cli/​add_interactive_secrets_test.go Tests interactive setup diagnostics.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread pkg/cli/engine_secrets.go
Comment on lines +714 to +715
if engine == string(constants.ClaudeEngine) && value == "" && os.Getenv("CLAUDE_CODE_OAUTH_TOKEN") != "" { //nolint:osgetenvlibrary
return "", "", false, errUnsupportedClaudeOAuthToken

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in 324e108: TestGetEngineSecretNameAndValue now clears CLAUDE_CODE_OAUTH_TOKEN at setup; the focused OAuth test still sets it explicitly.

@gh-aw-bot

Copy link
Copy Markdown
Collaborator

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes.
  2. Review (pkg/cli/engine_secrets.go:715): This new ambient-environment branch makes the pre-existing TestGetEngineSecretNameAndValue/no alternative secret in repo host-dependent: that subtest clears ANTHROPIC_API_KEY but not CLAUDE_CODE_OAUTH_TOKEN, so developers with a normal Claude login will now get this error instead of the asserted empty credential. Please clear CLAUDE_CODE_OAUTH_TOKEN at the start of TestGetEngineSecretNameAndValue (and let the focused test set it explicitly) so the package tests remain deterministic. - Name unsupported Claude OAuth token in CLI secret setup #66669 (comment)

Push the necessary fixes, reply to each listed review thread and resolve it when addressed. Ignore feedback already answered or resolved. Use the pr-finisher skill and stop when only human review or CI remains; do not trigger CI.

Sous-chef head: 9bd7c88
Sous-chef work: 47a4325d485558d69d0d8870d32a35c91ddc0d6a86f89863d68ede3cabfd7898
Sous-chef state: 84d7b7b6d50b72f8a01603f88ca8236a5556d44e2959867ddcb887a9080df016

Generated by 👨‍🍳 PR Sous Chef · pi · haiku45 · 5.6 AIC · ⌖ 10.7 AIC · ⊞ 1K · ◷
Comment /souschef to run again

Copilot AI and others added 2 commits October 7, 2026 20:51
…ame-unsupported-clause-code-oauth-tok

Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>
Co-authored-by: gh-aw-bot <259018956+gh-aw-bot@users.noreply.github.com>

Copilot AI commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

@copilot address the following outstanding work in one pass:

  1. Update this branch with the latest main using make merge-main, resolving any conflicts and preserving the intended changes....

Merged the latest main and committed the deterministic test setup fix in 324e108. The focused test and impacted tests passed; make agent-report-progress also reported five pre-existing custom-linter findings in unchanged sections of pkg/cli/engine_secrets.go. No CI was triggered.

Copilot AI requested a review from gh-aw-bot October 7, 2026 20:59
@pelikhan
pelikhan merged commit 3bafb7d into main Oct 7, 2026
4 checks passed
@pelikhan
pelikhan deleted the copilot/deep-report-name-unsupported-clause-code-oauth-tok branch October 7, 2026 22:11
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.6

github-actions Bot added a commit that referenced this pull request Oct 8, 2026
PR #66669 changed the gh aw CLI secret setup path to detect
CLAUDE_CODE_OAUTH_TOKEN and fail with an explicit error naming the
token and the supported alternatives, instead of silently ignoring
it. Update the two docs call out sites that still described the old
silent-ignore / unnamed-error behavior.

Closes #66656
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[deep-report] Name the unsupported CLAUDE_CODE_OAUTH_TOKEN instead of silently failing auth

4 participants