auth

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: MIT Imports: 12 Imported by: 0

Documentation

Overview

Package auth implements the ChatGPT sign-in used by the Codex CLI: device-code login, token refresh and revocation against auth.openai.com.

Index

Constants

View Source
const (
	// DefaultIssuer is the OpenAI auth server.
	DefaultIssuer = "https://auth.openai.com"
	// ClientID is the public OAuth client of the Codex CLI.
	ClientID = "app_EMoamEEZ73f0CkXaXp7hrann"
)

Variables

View Source
var (
	// ErrDeviceAuthDisabled is returned when the server does not offer device-code login.
	ErrDeviceAuthDisabled = errors.New(deviceDisabledMessage)
	// ErrDeviceCodeExpired is returned when the code was not approved in time.
	ErrDeviceCodeExpired = errors.New("the sign-in code expired before it was approved; run login again")
)

Functions

func TokenExpiry

func TokenExpiry(token string) (time.Time, bool)

TokenExpiry returns the exp claim of a JWT, if it has one.

Types

type Client

type Client struct {
	Issuer    string
	ClientID  string
	HTTP      *http.Client
	UserAgent string
}

Client talks to the auth server.

func NewClient

func NewClient(issuer string, httpClient *http.Client, userAgent string) *Client

NewClient returns a Client for issuer, falling back to DefaultIssuer.

func (*Client) CompleteDeviceLogin

func (c *Client) CompleteDeviceLogin(ctx context.Context, dc *DeviceCode) (*Tokens, error)

CompleteDeviceLogin waits for the user to approve the code, then exchanges the resulting authorization code for tokens.

func (*Client) Refresh

func (c *Client) Refresh(ctx context.Context, refreshToken string) (*Tokens, error)

Refresh exchanges a refresh token for new tokens. Any returned field may be empty, meaning the stored value stays current. Refresh tokens rotate, so a returned RefreshToken must be persisted before the old one is used again.

func (*Client) RequestDeviceCode

func (c *Client) RequestDeviceCode(ctx context.Context) (*DeviceCode, error)

RequestDeviceCode starts a device-code login.

func (*Client) Revoke

func (c *Client) Revoke(ctx context.Context, refreshToken string) error

Revoke invalidates a refresh token on the server.

type DeviceCode

type DeviceCode struct {
	VerificationURL string
	UserCode        string
	ExpiresAt       time.Time
	// contains filtered or unexported fields
}

DeviceCode is a pending device-code login.

type Identity

type Identity struct {
	Email     string
	PlanType  string
	UserID    string
	AccountID string // ChatGPT workspace
	FedRAMP   bool
}

Identity is the account information carried in a ChatGPT ID token.

func ParseIdentity

func ParseIdentity(idToken string) (Identity, error)

ParseIdentity reads the identity claims from an ID token. The signature is not verified: the claims are only used for display and bookkeeping.

type RefreshError

type RefreshError struct {
	Status    int
	Code      string
	Message   string
	Permanent bool
}

RefreshError is a failed token refresh. Permanent errors mean the refresh token is no longer usable and the account has to sign in again.

func (*RefreshError) Error

func (e *RefreshError) Error() string

type Tokens

type Tokens struct {
	IDToken      string `json:"id_token"`
	AccessToken  string `json:"access_token"`
	RefreshToken string `json:"refresh_token"`
}

Tokens is the credential set issued by the auth server.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL