Documentation
¶
Overview ¶
Package auth implements the ChatGPT sign-in used by the Codex CLI: device-code login, token refresh and revocation against auth.openai.com.
Index ¶
- Constants
- Variables
- func TokenExpiry(token string) (time.Time, bool)
- type Client
- func (c *Client) CompleteDeviceLogin(ctx context.Context, dc *DeviceCode) (*Tokens, error)
- func (c *Client) Refresh(ctx context.Context, refreshToken string) (*Tokens, error)
- func (c *Client) RequestDeviceCode(ctx context.Context) (*DeviceCode, error)
- func (c *Client) Revoke(ctx context.Context, refreshToken string) error
- type DeviceCode
- type Identity
- type RefreshError
- type Tokens
Constants ¶
const ( // DefaultIssuer is the OpenAI auth server. DefaultIssuer = "https://auth.openai.com" // ClientID is the public OAuth client of the Codex CLI. ClientID = "app_EMoamEEZ73f0CkXaXp7hrann" )
Variables ¶
var ( // ErrDeviceAuthDisabled is returned when the server does not offer device-code login. ErrDeviceAuthDisabled = errors.New(deviceDisabledMessage) // ErrDeviceCodeExpired is returned when the code was not approved in time. ErrDeviceCodeExpired = errors.New("the sign-in code expired before it was approved; run login again") )
Functions ¶
Types ¶
type Client ¶
Client talks to the auth server.
func (*Client) CompleteDeviceLogin ¶
CompleteDeviceLogin waits for the user to approve the code, then exchanges the resulting authorization code for tokens.
func (*Client) Refresh ¶
Refresh exchanges a refresh token for new tokens. Any returned field may be empty, meaning the stored value stays current. Refresh tokens rotate, so a returned RefreshToken must be persisted before the old one is used again.
func (*Client) RequestDeviceCode ¶
func (c *Client) RequestDeviceCode(ctx context.Context) (*DeviceCode, error)
RequestDeviceCode starts a device-code login.
type DeviceCode ¶
type DeviceCode struct {
VerificationURL string
UserCode string
ExpiresAt time.Time
// contains filtered or unexported fields
}
DeviceCode is a pending device-code login.
type Identity ¶
type Identity struct {
Email string
PlanType string
UserID string
AccountID string // ChatGPT workspace
FedRAMP bool
}
Identity is the account information carried in a ChatGPT ID token.
func ParseIdentity ¶
ParseIdentity reads the identity claims from an ID token. The signature is not verified: the claims are only used for display and bookkeeping.
type RefreshError ¶
RefreshError is a failed token refresh. Permanent errors mean the refresh token is no longer usable and the account has to sign in again.
func (*RefreshError) Error ¶
func (e *RefreshError) Error() string