Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Kiro: dead refresh token (400 invalid_request) never flags needsReauth — dashboard keeps "Logged in" with no re-auth button

Chiusa
#6,701 1 commento 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
Mezza giornata
Idoneità per principianti
78/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
typescript

Direzione di ricerca

Start in src/oauth/kiro.ts at KIRO_TERMINAL_REFRESH_ERRORS, then read terminal() and publicOAuthAuthenticationErrorMessage() in src/oauth/index.ts to see why a 400 invalid_request never marks the account. Add the error classification so a dead Kiro refresh token sets needsReauth (or maps to the verify_account reauth reason), and check the provider overview rendering driven by GET /api/oauth/status so an expired expiresAt is not shown as green "Logged in". Done when replaying the 400 invalid_request refresh flips the dashboard to "Needs attention" with a Re-authenticate button; locate the existing terminal refresh-error tests first and run them.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

account-pool bug gui
Client or integration

OpenCodex dashboard

Area

Authentication and account pool

Summary

When a Kiro refresh token becomes irredeemable (AWS SSO OIDC no longer accepts it), the account is never flagged needsReauth. The dashboard keeps showing Kiro as Ready / Connected / Logged in with no Re-authenticate button, and every request fails 401 with the generic fallback message. I expected the provider card to flip to "Needs attention" with the Re-authenticate button (or at least the specific "Not logged in to kiro. Run: ocx login kiro" message), like the terminal refresh-error path already produces.

Likely root cause (read from the installed 2.78.0 package):

  • KIRO_TERMINAL_REFRESH_ERRORS in src/oauth/kiro.ts covers only invalid_grant, refresh_token_reused, revoked, revoked_token, refresh_token_revoked, access_denied, expired_token.
  • The dead credential gets a consistent HTTP 400 from oidc..amazonaws.com/token with not in that set.
    {"error":"invalid_request","error_description":"Invalid request","location":null,"reason":null}
    
  • terminal() in src/oauth/index.ts treats KiroTokenRefreshError as terminal only when a 400/401 carries one of the known oauthError values, so the account is never marked; the raw error then surfaces through publicOAuthAuthenticationErrorMessage() as the generic "OAuth authentication failed." text.

Evidence:

  • Stored credential expired at 2026-10-06T10:50:38Z; tested at 2026-10-07T03:34Z.

  • GET /api/oauth/status?provider=kiro still returns loggedIn: true with that expired expiresAt and no needsReauth flag.

  • Client error on every request: "unexpected status 401 Unauthorized: OAuth authentication failed. Check the OpenCodex account status and retry."

  • Replaying the exact refresh request the proxy sends (same registered clientId/clientSecret, same refreshToken) returns HTTP 400 invalid_request.

  • The stored refresh token is identical to the local kiro-cli session token, whose access token is also expired. Only a fresh browser login restores access; no refresh path can.

Reproduction
  1. Import/complete a Kiro login (kiro-cli device/Builder ID flow), then let both the access token and the refresh grant go stale (e.g. leave it idle for a day).
  2. Send any request routed to the kiro provider, e.g. POST /v1/responses with model: kiro/.
  3. Observe the 401 generic OAuth message; dashboard Providers -> Kiro still shows Connected / Logged in with no Re-authenticate button, and Current account usage shows "Failed to refresh quotas".
  4. Manually POST the same refresh payload (grantType: refresh_token, clientId, clientSecret, refreshToken) to https://oidc.<region>.amazonaws.com/token and observe 400 invalid_request.
Version

2.78.0

Operating system

Ubuntu 26.04.1 LTS

Provider and model

kiro / claude-opus-5.5 (any Kiro model; the failure happens at the auth/token-resolution stage)

Logs or error output
[opencodex] OAuth refresh started provider=kiro account=account-…55fe

That line repeats roughly 40 times over an hour (request failures and quota probes keep re-attempting refresh); the credential never rotates and the account is never flagged.

ocx logs --provider kiro --limit 3 --json (redacted row fields):

    {
      "status": 401,
      "durationMs": 40,
      "errorCode": "invalid_api_key",
      "failureStage": "headers-only",
      "failureCause": "credential-rejected",
      "resendPermission": "permitted-after-repair",
      "upstreamError": "OAuth authentication failed. Check the OpenCodex account status and retry."
    }

AWS token endpoint replay (same registered client + stored refresh token as the proxy uses):

    HTTP 400
    {"error":"invalid_request","error_description":"Invalid request","location":null,"reason":null}
Screenshots and supporting files

Dashboard screenshot showing Kiro "Connected / Logged in" plus "Failed to refresh quotas" while all Kiro requests 401; client screenshot of the generic 401 error.

Redacted configuration
{
  "providers": {
    "kiro": {
      "adapter": "kiro",
      "authMode": "oauth",
      "baseUrl": "https://runtime.us-east-1.kiro.dev",
      "defaultModel": "kiro-auto"
    }
  },
  "tokenGuardian": null
}

Note: tokenGuardian is unset (defaults off) and Kiro's default refresh policy is lazy-only, so nothing proactively probes. But even a manual request never sets needsReauth either, because the 400 invalid_request response is not classified as terminal. A UI-level fix would also work: /api/oauth/status already returns expiresAt, and still renders a green "Logged in" for tokens that expired a day+ ago.

Suggested fix (either or both): treat the Kiro SSO 400 invalid_request refresh rejection as terminal (or map it to the verify_account reauth reason), and/or render token-expired state from expiresAt in the provider overview instead of a permanent healthy "Logged in".

Redacted configuration

Checks
  • I searched existing issues and documentation.
  • I removed secrets, tokens, account details, request credentials, and personal data.
Lingua principale
TypeScript
Stelle
16.9k
Fork
1.3k
Merge medio
4h 52m
PR unite (30g)
609

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di lidge-jun/opencodex

Tutte le issue di lidge-jun/opencodex

Issue simili

Altre issue su TypeScript

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.