Skip to content

feat: use kody login OAuth as Bearer for execute --local - #14

Merged
kody-bot merged 1 commit into
mainfrom
cursor/local-execute-login-oauth-ef8c
Oct 1, 2026
Merged

kody-bot merged 1 commit into
mainfrom
cursor/local-execute-login-oauth-ef8c

Conversation

@kentcdodds

Copy link
Copy Markdown
Owner

Summary

execute --local no longer requires minting/pasting a temporary KODY_API_TOKEN when the user already has kody login.

Auth priority:

  1. --token / KODY_API_TOKEN (unchanged; still wins)
  2. Else stored CLI OAuth access token as Authorization: Bearer … (no under-the-hood tokenCreate)
  3. Else clear error: run kody login or provide a token

Platform dependency

Open API currently accepts only kody_at_… API tokens (ADR 0053). Live probe: non-kody_at_ Bearer → 401 Invalid API token (credential class rejection, not missing scopes).

Platform issue with the minimal fix: kentcdodds/kody#2812 — accept CLI MCP OAuth on CapabilityProxy + package-graph, gated by the local-execute flag with the full MCP grant.

Until that lands, login-backed --local gets a clear 401 pointing at #2812 and how to mint a scoped token as a workaround. No hosted MCP execute fallback.

Tests

  • Login happy path: OAuth access token sent as Bearer (no API token)
  • Missing login + missing token → clear auth error
  • --token still wins over a stored login session
  • CapabilityProxy 401 for non-kody_at_ names the platform gap

Docs

README, help, and skill updated for the new priority and platform gap.

Open in Web Open in Cursor 

When --token / KODY_API_TOKEN is unset, execute --local now sends the
stored CLI OAuth access token as Authorization Bearer (no tokenCreate
exchange). Documents the Open API gap (kentcdodds/kody#2812) when OAuth
is rejected, and keeps API tokens winning when set.

Co-authored-by: Kent C. Dodds <me+github@kentcdodds.com>
@kody-bot

kody-bot commented Oct 1, 2026

Copy link
Copy Markdown
Owner

@cursor review

@cursor

cursor Bot commented Oct 1, 2026

Copy link
Copy Markdown

Skipping Bugbot: Unable to authenticate your request. Please make sure Bugbot is properly installed and configured for this repository.

@kody-bot
kody-bot merged commit 56436e8 into main Oct 1, 2026
5 checks passed
@kody-bot
kody-bot deleted the cursor/local-execute-login-oauth-ef8c branch October 1, 2026 20:31
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.7.0 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants