Skip to content

feat(cli): move bench auth onto the OAuth provider device flow - #488

Merged
dtice25 merged 5 commits into
masterfrom
devin/1791269072-cli-oauth-consolidation
Oct 6, 2026
Merged

dtice25 merged 5 commits into
masterfrom
devin/1791269072-cli-oauth-consolidation

Conversation

@dtice25

@dtice25 dtice25 commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

PR B of the CLI auth consolidation (platform side is benchmarks-platform#597): moves bench off the retired HS256/bcs_ token endpoints and onto the same @better-auth/oauth-provider device flow MCP clients use. Only auth endpoints change — no command changes.

Endpoint changes (packages/benchsdk-cli/src/auth.ts)

  • requestDeviceCode → POST {auth}/device/code with client_id, resource=${origin}/api/v1, scope (form-encoded).
  • exchangeDeviceToken / pollDeviceToken → POST {auth}/oauth2/token with grant_type=urn:ietf:params:oauth:grant-type:device_code.
  • refreshAccessToken → POST {auth}/oauth2/token with grant_type=refresh_token.
  • Token responses no longer carry refresh_expires_in; refresh-token expiry is now only signalled by a failed refresh grant.

Client identity: bench logs in as benchsdk-runner with benchmarks:read benchmarks:write billing:read org:read offline_access (the narrowed per-client set the platform enforces). The minting clientId is stored in credentials so the refresh grant sends the right client_id — important once compute login (PR C, benchsdk-cli) shares ~/.benchsdk/credentials.json.

Legacy cleanup: entries written by the old system (bcs_ refresh tokens, or a token with no kind/clientId) can't be redeemed against /oauth2/token — resolveAuth detects them, clears credentials.json, and throws an AuthError telling the user to run bench auth login / compute login again.

org use keeps working through /api/v1/organizations; note the endpoint now returns accessToken: null, so the stored access token is preserved rather than swapped (active org moves server-side on the consent row).

Changeset included: minor bumps of @benchsdk/cli and @benchsdk/runner for release.

Link to Devin session: https://app.devin.ai/sessions/b96225cb2aee48aca32ca1fbb0692420
Open in Devin Desktop: https://app.devin.ai/desktop/session/b96225cb2aee48aca32ca1fbb0692420?variant=devin
Requested by: @dtice25


Devin Review

bench auth login now calls /api/auth/device/code (client_id +
resource=${origin}/api/v1 + scope) and redeems/polls at
/api/auth/oauth2/token with the device_code and refresh_token grants,
logging in as the narrowed benchsdk-runner client. Saved credentials
stay in ~/.benchsdk/credentials.json; pre-OAuth entries (HS256 /
bcs_ refresh tokens) are detected, cleared, and the user is told to
run bench auth login again.

Co-authored-by: Devin <devin@cognition.ai>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor

I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".

  • Disable automatic comment, CI, and merge conflict monitoring

@open-cla

open-cla Bot commented Oct 6, 2026

Copy link
Copy Markdown

Contributor License Agreement

All contributors are covered by a CLA.

compute login (PR C) runs the same device flow but for the benchsdk-cli
client with the full first-party scope set, sharing the same
~/.benchsdk/credentials.json store.

Co-authored-by: Devin <devin@cognition.ai>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>

@devin-ai-integration devin-ai-integration Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin resolved all 2 findings on 9d29f68

Fixed by Devin (2)

  • Access-only sessions never expire locally
  • API-prefixed URLs break device login

View all findings in Devin Review

Devin Review

@devin-ai-integration
devin-ai-integration Bot force-pushed the devin/1791269072-cli-oauth-consolidation branch 2 times, most recently from 31ee84b to c5d8900 Compare October 6, 2026 06:50
…login

- resolveAuth now runs the expiry check on any stored OAuth token, not
  only ones carrying a refresh token — an access-only session reports
  'session expired' instead of sending a dead token forever.
- oauthLogin builds its endpoints via getAuthBaseUrl/getApiBaseUrl so a
  base URL already ending in /api/v1 doesn't get the suffix doubled.

Co-authored-by: Devin <devin@cognition.ai>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
dtice25 and others added 2 commits October 6, 2026 07:28
bench auth login now uses the benchsdk-cli client with the full first-party
scope set — the same login compute uses — so the two CLIs no longer
overwrite each other's narrower/wider grants in ~/.benchsdk/credentials.json.
insufficient_scope API errors get a re-login hint.

Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@dtice25
dtice25 merged commit b56c3f4 into master Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant