howmuchleft v0.14.1 /internal/oauth
On this page

Manages Claude OAuth credentials including token refresh, macOS Keychain fallback, atomic file writes, and subscription tier detection.

#internal/oauth

#internal/oauth

#OAuthClientID

Go go
const OAuthClientID = "9d1c250a-e61b-44d9-88ed-5944d1962f5e"

#Credentials

Go go
type Credentials struct

Credentials holds the minimal token set needed for OAuth operations.

#OAuthData

Go go
type OAuthData struct

OAuthData represents the claudeAiOauth section of the credentials file.

#CredFile

Go go
type CredFile struct

CredFile represents the full .credentials.json structure. RawFields preserves unknown top-level keys for round-trip fidelity.

#AuthInfo

Go go
type AuthInfo struct

AuthInfo describes the authentication method and subscription tier.

#ReadCredentialsFile

Go go
func ReadCredentialsFile(claudeDir string) *CredFile

ReadCredentialsFile reads and parses /.credentials.json. Returns nil on any error (missing file, parse failure). Results are cached per claudeDir for the process lifetime.

#ReadKeychainCredentials

Go go
func ReadKeychainCredentials(claudeDir string) *OAuthData

ReadKeychainCredentials reads OAuth credentials from the macOS Keychain. Returns nil on non-macOS platforms or any error.

#GetAuthInfo

Go go
func GetAuthInfo(oauth *OAuthData) AuthInfo

GetAuthInfo determines auth type and subscription display name from OAuth data.

#ResetCredentialsCache

Go go
func ResetCredentialsCache()

ResetCredentialsCache clears the per-process credentials cache.

#RefreshToken

Go go
func RefreshToken(claudeDir string, credFile *CredFile, oauth *OAuthData) error

RefreshToken refreshes an expired OAuth token and writes updated credentials back to /.credentials.json atomically.

#GetValidToken

Go go
func GetValidToken(claudeDir string) (string, error)

GetValidToken returns a valid access token, refreshing if expired. Falls back to Keychain on macOS if refresh fails.

#WriteFileAtomic

Go go
func WriteFileAtomic(path string, data []byte) error

WriteFileAtomic writes data to a temporary file in the same directory as path, then renames it atomically. This ensures readers see either the complete old or complete new file.

#CredFile.UnmarshalJSON

Go go
func (c *CredFile) UnmarshalJSON(data []byte) error

#CredFile.MarshalJSON

Go go
func (c *CredFile) MarshalJSON() ([]byte, error)
Search