Skip to content

fix(auth): point insufficient_scope at cliCredentialBootstrap - #26

Merged
kody-bot merged 3 commits into
mainfrom
fix/bootstrap-scope-error-messages
Oct 9, 2026
Merged

kody-bot merged 3 commits into
mainfrom
fix/bootstrap-scope-error-messages

Conversation

@kody-bot

@kody-bot kody-bot commented Oct 9, 2026

Copy link
Copy Markdown
Owner

Intent

Stop telling agents to use tokenCreate + retired local-execute when CapabilityProxy / Open API returns insufficient_scope. Prefer cliCredentialBootstrap with --lifetime short|long.

Door: two-way

Cleanup: none

Why

Companion to kentcdodds/kody#3112 (restore local-execute parity for bootstrap scopes). Server errors already point at bootstrap; CLI still named tokenCreate.

Summary

  • insufficientScopeMessage / CapabilityProxy 403 prefer cliCredentialBootstrap
  • apiTokenMintInstructions is CI/headless-only and uses org:execute wording
  • Help text updated

Referenced issues and PRs

Related to kentcdodds/kody#3104, kentcdodds/kody#3109, kentcdodds/kody#3112

Testing

npx tsx --test test/capability-proxy.test.ts test/open-api-client.test.ts (23 pass)

CapabilityProxy and Open API insufficient_scope errors told agents to mint via tokenCreate with the retired local-execute scope. Prefer cliCredentialBootstrap --lifetime short|long; keep tokenCreate as the CI/headless path with org:execute wording.

Related to kentcdodds/kody#3104 kentcdodds/kody#3109 kentcdodds/kody#3112
@kody-bot
kody-bot merged commit fce44ca into main Oct 9, 2026
5 checks passed
@kody-bot
kody-bot deleted the fix/bootstrap-scope-error-messages branch October 9, 2026 20:13
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown

🎉 This PR is included in version 1.11.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant