v0.10.0 — Automatic token refresh
What's new
- Automatic OAuth token refresh — token expires every ~8 hours but the app now self-heals. Before each poll the app checks
expiresAtand, if expired, delegates to the officialclaudeCLI (claude auth status→claude update) to refresh. No credentials are written directly. After a singleclaude login, the app stays logged in indefinitely. - Reactive 401/403 recovery — if the token expires between the expiry check and the HTTP call, the app performs an emergency refresh and retries the fetch automatically. Only shows the "run claude login" balloon if refresh genuinely fails.
- Source priority fix —
CLAUDE_CODE_OAUTH_TOKEN(set viaclaude setup-token) was previously read first and shadowed the working credentials file, causing HTTP 403 (user:profilescope required). Now: Credential Manager → credentials file → env var (last resort, with a scope warning in the log).
Upgrade
If you previously set CLAUDE_CODE_OAUTH_TOKEN, remove it — it's no longer needed and caused HTTP 403 on the usage endpoint:
reg delete "HKCU\Environment" /v CLAUDE_CODE_OAUTH_TOKEN /f
Then restart the app. One claude login is all you need going forward.