Skip to content

Add a read-only provider/model auth preflight command #7152

Description

@chuck-quypto

What do you want to change?

Add a non-interactive command that checks whether an exact provider/model pair is installed and has configured credentials, without refreshing credentials or mutating Pi state:

pi auth check --provider openai-codex --model gpt-5.6-terra --json --no-refresh

The command would return closed JSON metadata and distinct exit codes for ready, not ready, and invalid state. It would never return credential values.

I would like to implement this if the direction is acceptable.

Why?

Launchers and workflow harnesses need a safe preflight before starting Pi. Today they must either inspect Pi internals or begin a real run to discover missing model/auth state. Existing auth reads also create or lock state files, so they are not suitable for a side-effect-free readiness check.

How? (optional)

Handle the command before normal session startup, perform offline exact-model lookup, and add a read-only credential-status path that does not create or lock auth.json. Cover authenticated, logged-out, missing-model, malformed-state, and unchanged-filesystem cases.

Activity

  1. chuck-quypto commented on Jul 26, 2026

    @chuck-quypto
    Author

    AI disclosure: I asked Codex to investigate and draft this proposal after reproducing the need in an external workflow-harness feasibility spike. I reviewed and approved the scope before posting.

    This comment is AI-generated by Codex.

  2. github-actions commented on Jul 26, 2026

    @github-actions
    Contributor

    This issue was auto-closed. All issues from new contributors are auto-closed by default.

    Maintainers review auto-closed issues daily and reopen worthwhile ones. Issues that do not meet the quality bar in CONTRIBUTING.md will not be reopened or receive a reply.

    If a maintainer replies lgtmi on one of your issues, your future issues will stay open. If a maintainer replies lgtm, your future issues and PRs will stay open. The command must be at the start of the reply (optionally after one or more @username mentions) or at the end.

    See CONTRIBUTING.md.

  3. added
    untriagedThis issue has been auto closed and has not been triaged
    on Jul 26, 2026
  4. added
    no-actionThis issue has been rejected after triage
    and removed
    untriagedThis issue has been auto closed and has not been triaged
    on Jul 27, 2026
  5. mitsuhiko commented on Aug 6, 2026

    @mitsuhiko
    Member

    Implemented provider-focused auth preflight and credential export:

    • pi auth check --provider <provider> refreshes expired OAuth by default; --no-refresh remains read-only.
    • --credentials emits the resolved credential, with JSON support through --json.
    • Credential-print commands no longer require --model when --provider is given.
    • Auth subcommands share parsing, validation, help, credential extraction, and package-style unknown-option errors.

    Validated targeted tests and npm run check.

    This comment is AI-generated by /wr

  6. added a commit that references this issue on Aug 6, 2026
    a261366
  7. added a commit that references this issue on Aug 11, 2026
  8. added a commit that references this issue on Sep 11, 2026
    21b3ac6
  9. added a commit that references this issue on Oct 8, 2026
    ac68d0e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions