You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Token refresh now happens per request, not just at startup. OpenCode calls
the auth loader only once — when it builds and memoizes the provider's SDK
client — so returning a static { apiKey } froze the access token for the life
of the process. After a long idle (e.g. overnight) that token expired and every
request failed with Unauthorized (401) until OpenCode was restarted — no auth login required, because the stored (offline) refresh token was still
valid. The loader now installs a custom fetch that re-resolves and refreshes
the token on every outgoing request, so freshness no longer depends on how often
OpenCode invokes the loader. Single-flight refresh, rotation handling, and
persistence are preserved.