Repository navigation
feat(cli): move bench auth onto the OAuth provider device flow - #488
Merged
Merged
Conversation
bench auth login now calls /api/auth/device/code (client_id +
resource=${origin}/api/v1 + scope) and redeems/polls at
/api/auth/oauth2/token with the device_code and refresh_token grants,
logging in as the narrowed benchsdk-runner client. Saved credentials
stay in ~/.benchsdk/credentials.json; pre-OAuth entries (HS256 /
bcs_ refresh tokens) are detected, cleared, and the user is told to
run bench auth login again.
Co-authored-by: Devin <devin@cognition.ai>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Contributor
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
Contributor License AgreementAll contributors are covered by a CLA. |
compute login (PR C) runs the same device flow but for the benchsdk-cli client with the full first-party scope set, sharing the same ~/.benchsdk/credentials.json store. Co-authored-by: Devin <devin@cognition.ai> Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Contributor
There was a problem hiding this comment.
✅ Devin resolved all 2 findings on 9d29f68
Fixed by Devin (2)
- Access-only sessions never expire locally
- API-prefixed URLs break device login
devin-ai-integration
Bot
force-pushed
the
devin/1791269072-cli-oauth-consolidation
branch
2 times, most recently
from
October 6, 2026 06:50
31ee84b to
c5d8900
Compare
…login - resolveAuth now runs the expiry check on any stored OAuth token, not only ones carrying a refresh token — an access-only session reports 'session expired' instead of sending a dead token forever. - oauthLogin builds its endpoints via getAuthBaseUrl/getApiBaseUrl so a base URL already ending in /api/v1 doesn't get the suffix doubled. Co-authored-by: Devin <devin@cognition.ai> Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
devin-ai-integration
Bot
force-pushed
the
devin/1791269072-cli-oauth-consolidation
branch
from
October 6, 2026 06:51
c5d8900 to
5d4c72f
Compare
bench auth login now uses the benchsdk-cli client with the full first-party scope set — the same login compute uses — so the two CLIs no longer overwrite each other's narrower/wider grants in ~/.benchsdk/credentials.json. insufficient_scope API errors get a re-login hint. Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
PR B of the CLI auth consolidation (platform side is benchmarks-platform#597): moves
benchoff the retired HS256/bcs_token endpoints and onto the same@better-auth/oauth-providerdevice flow MCP clients use. Only auth endpoints change — no command changes.Endpoint changes (
packages/benchsdk-cli/src/auth.ts)requestDeviceCode→POST {auth}/device/codewithclient_id,resource=${origin}/api/v1,scope(form-encoded).exchangeDeviceToken/pollDeviceToken→POST {auth}/oauth2/tokenwithgrant_type=urn:ietf:params:oauth:grant-type:device_code.refreshAccessToken→POST {auth}/oauth2/tokenwithgrant_type=refresh_token.refresh_expires_in; refresh-token expiry is now only signalled by a failed refresh grant.Client identity:
benchlogs in asbenchsdk-runnerwithbenchmarks:read benchmarks:write billing:read org:read offline_access(the narrowed per-client set the platform enforces). The mintingclientIdis stored in credentials so the refresh grant sends the rightclient_id— important oncecompute login(PR C,benchsdk-cli) shares~/.benchsdk/credentials.json.Legacy cleanup: entries written by the old system (
bcs_refresh tokens, or a token with nokind/clientId) can't be redeemed against/oauth2/token—resolveAuthdetects them, clearscredentials.json, and throws anAuthErrortelling the user to runbench auth login/compute loginagain.org usekeeps working through/api/v1/organizations; note the endpoint now returnsaccessToken: null, so the stored access token is preserved rather than swapped (active org moves server-side on the consent row).Changeset included: minor bumps of
@benchsdk/cliand@benchsdk/runnerfor release.Link to Devin session: https://app.devin.ai/sessions/b96225cb2aee48aca32ca1fbb0692420
Open in Devin Desktop: https://app.devin.ai/desktop/session/b96225cb2aee48aca32ca1fbb0692420?variant=devin
Requested by: @dtice25