feat(runtime): warn admins before a Claude Code login expires (v0.450.0) - #846
Merged
Merged
Conversation
Claude Code logins carry a fixed refreshTokenExpiresAt that use does not extend; the expresstech box default died at its date mid-use and was found only by the refusal card. An hourly spawn-free sweep now reads that date for the box default and each enabled pool account and raises one admin card per login at 7/3/1 days and on expiry (superseding, audit-guarded), closing it when the login is renewed. Settings -> Runtime shows the expiry. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Every
claude loginhas a refresh token with a fixed lifetime (claudeAiOauth.refreshTokenExpiresAt), and using the account doesn't extend it. On instapods,toolsrefreshed its access token all day on 10-02 and its expiry didn't move. When that date passes, Claude Code wipes the record and every run is refused.tools2-newpool account died the same way on 09-26.Both were found only by the refusal card, after runs had already stopped, even though the date had been sitting in the credential file all along.
Change
src/edge/login-expiry.ts: an hourly sweep that spawns nothing, run off the scheduler tick. It reads the expiry for the box default and every enabled credential-dir pool account.runtime.login.expiringaudit trail guards against repeats, so a restart doesn't re-alarm.runtime.login.renewed.CLAUDE_CONFIG_DIR=… claude /logincommand, with a Keychain/ssh hint on macOS only.GET /api/runtime-accountsnow returnsloginExpiresAt/loginDeadper account plusboxDefault.Test
New test
scripts/login-expiry-test.cjs(25 checks, file-based credentials, CI-portable), added totest:governance. The full suite and the web build pass.🤖 Generated with Claude Code