Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Process-local auth token stops refreshing; all prompts fail until restart

Open
#4,929 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
45/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
github

Research direction

Retest the failure on the current stable version using a long-running resumed CLI process, then compare the /ask and /login behavior with the recorded MCP and Copilot Tasks API 401 timeline. Done means service and MCP tokens refresh during the active workflow, or /login reloads usable credentials so prompts recover without restarting the process.

Written by the indexing model from the issue text.

Description

triage
Describe the bug

A long-running Copilot CLI process permanently loses authentication. After the failure, every normal prompt and /ask immediately returns an authorization error. Running /login does not recover the process. Restarting and resuming the same session restores operation immediately.

The failure is process-local: several older concurrent CLI processes remained usable, and a newly launched process authenticated successfully. No COPILOT_GITHUB_TOKEN, GH_TOKEN, or GITHUB_TOKEN override was present.

The failing process first logged an expired/rejected GitHub MCP token almost exactly one hour after startup. It later logged 401 AuthenticateToken failed from the Copilot Tasks API. OAuth recovery attempted discovery against the enterprise Copilot endpoint but failed, leaving the process permanently unable to submit prompts.

Affected version

GitHub Copilot CLI 1.0.85 on Windows 11. The process was launched by a host application with --no-auto-update, --resume, and an additional MCP configuration.

Steps to reproduce
  1. Start an interactive Copilot CLI session and keep it open while performing a long-running workflow.
  2. Keep several other CLI sessions running concurrently.
  3. After approximately one hour or longer, submit another prompt.
  4. Observe that every prompt and /ask reports an authorization error.
  5. Run /login; observe that the process remains broken.
  6. Start a new CLI process; observe that it works immediately.
  7. Restart/resume the failed process; observe that authentication works again.
Expected behavior

Short-lived service and MCP tokens should refresh automatically without interrupting the active workflow. If refresh fails, /login should reload the new credentials into the current process.

Actual behavior

The process retains unusable authentication state indefinitely and all model turns fail until the process is restarted.

Timeline and log evidence

A sanitized diagnostic excerpt is available. Raw conversation history and credentials have been excluded.

Related issues
  • #3763 — session token expiry stops workflows
  • #4203 — expired MCP OAuth token does not silently refresh
  • #4842 — MCP OAuth refresh/reconnect concurrency
  • #2818 — earlier one-hour session-token expiry issue, reported fixed in 1.0.35-3
Additional context

Current stable is newer than the affected installation. I will retest on the current stable version and update this issue, but this report captures a repeatable failure seen multiple times on 1.0.85.

Dominant language
Shell
Stars
11.2k
Forks
1.9k
Avg merge
14h 16m
Merged PRs (30d)
6

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/copilot-cli

All issues in github/copilot-cli

Similar issues

More Shell/Bash issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.