Repository navigation
Add a read-only provider/model auth preflight command #7152
Description
Activity
AI disclosure: I asked Codex to investigate and draft this proposal after reproducing the need in an external workflow-harness feasibility spike. I reviewed and approved the scope before posting.
This comment is AI-generated by Codex.
github-actions commented
on Jul 26, 2026 on Jul 26, 2026 – with GitHub ActionsContributorMore actionsThis issue was auto-closed. All issues from new contributors are auto-closed by default.
Maintainers review auto-closed issues daily and reopen worthwhile ones. Issues that do not meet the quality bar in CONTRIBUTING.md will not be reopened or receive a reply.
If a maintainer replies
lgtmion one of your issues, your future issues will stay open. If a maintainer replieslgtm, your future issues and PRs will stay open. The command must be at the start of the reply (optionally after one or more@usernamementions) or at the end.See CONTRIBUTING.md.
- addeduntriagedThis issue has been auto closed and has not been triagedThis issue has been auto closed and has not been triaged
on Jul 26, 2026 - addedno-actionThis issue has been rejected after triageThis issue has been rejected after triageand removeduntriagedThis issue has been auto closed and has not been triagedThis issue has been auto closed and has not been triaged
on Jul 27, 2026 - removedno-actionThis issue has been rejected after triageThis issue has been rejected after triage
on Aug 6, 2026 Implemented provider-focused auth preflight and credential export:
pi auth check --provider <provider>refreshes expired OAuth by default;--no-refreshremains read-only.--credentialsemits the resolved credential, with JSON support through--json.- Credential-print commands no longer require
--modelwhen--provideris given. - Auth subcommands share parsing, validation, help, credential extraction, and package-style unknown-option errors.
Validated targeted tests and
npm run check.This comment is AI-generated by
/wr- added a commit that references this issue
on Aug 6, 2026 - added a commit that references this issue
on Aug 11, 2026 - added a commit that references this issue
on Aug 11, 2026 - added a commit that references this issue
on Sep 11, 2026 - added a commit that references this issue
on Oct 8, 2026
What do you want to change?
Add a non-interactive command that checks whether an exact provider/model pair is installed and has configured credentials, without refreshing credentials or mutating Pi state:
pi auth check --provider openai-codex --model gpt-5.6-terra --json --no-refreshThe command would return closed JSON metadata and distinct exit codes for ready, not ready, and invalid state. It would never return credential values.
I would like to implement this if the direction is acceptable.
Why?
Launchers and workflow harnesses need a safe preflight before starting Pi. Today they must either inspect Pi internals or begin a real run to discover missing model/auth state. Existing auth reads also create or lock state files, so they are not suitable for a side-effect-free readiness check.
How? (optional)
Handle the command before normal session startup, perform offline exact-model lookup, and add a read-only credential-status path that does not create or lock
auth.json. Cover authenticated, logged-out, missing-model, malformed-state, and unchanged-filesystem cases.