Skip to content
internal/oauth
Edit
On this page

Manages Claude OAuth credentials including token refresh, macOS Keychain fallback, atomic file writes, and subscription tier detection.

#internal/oauth

#internal/oauth

Package oauth reads the credentials Claude Code already stores, refreshes an expired access token, and reports whether the session is an OAuth subscription and which tier it is on.

#OAuthClientID

Go go
const OAuthClientID = "9d1c250a-e61b-44d9-88ed-5944d1962f5e"

#Credentials

Go go
type Credentials struct

Credentials holds the minimal token set needed for OAuth operations.

#OAuthData

Go go
type OAuthData struct

OAuthData represents the claudeAiOauth section of the credentials file.

#CredFile

Go go
type CredFile struct

CredFile represents the full .credentials.json structure. RawFields preserves unknown top-level keys for round-trip fidelity.

#AuthInfo

Go go
type AuthInfo struct

AuthInfo describes the authentication method and subscription tier.

#ReadCredentialsFile

Go go
func ReadCredentialsFile(claudeDir string) *CredFile

ReadCredentialsFile reads and parses /.credentials.json. Returns nil on any error (missing file, parse failure). Results are cached per claudeDir for the process lifetime.

#ReadKeychainCredentials

Go go
func ReadKeychainCredentials(claudeDir string) *OAuthData

ReadKeychainCredentials reads OAuth credentials from the macOS Keychain. Returns nil on non-macOS platforms or any error.

#GetAuthInfo

Go go
func GetAuthInfo(oauth *OAuthData) AuthInfo

GetAuthInfo determines auth type and subscription display name from OAuth data.

#ResetCredentialsCache

Go go
func ResetCredentialsCache()

ResetCredentialsCache clears the per-process credentials cache.

#RefreshToken

Go go
func RefreshToken(claudeDir string, credFile *CredFile, oauth *OAuthData) error

RefreshToken refreshes an expired OAuth token and writes updated credentials back to /.credentials.json atomically.

#GetValidToken

Go go
func GetValidToken(claudeDir string) (string, error)

GetValidToken returns a valid access token, refreshing if expired. Falls back to Keychain on macOS if refresh fails.

#WriteFileAtomic

Go go
func WriteFileAtomic(path string, data []byte) error

WriteFileAtomic writes data to a temporary file in the same directory as path, then renames it atomically. This ensures readers see either the complete old or complete new file.

#CredFile.UnmarshalJSON

Go go
func (c *CredFile) UnmarshalJSON(data []byte) error

#CredFile.MarshalJSON

Go go
func (c *CredFile) MarshalJSON() ([]byte, error)

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search