mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
xAI's refresh-token response sometimes omits expires_in. Without it the new access token kept the stale pre-refresh expires_at, so is_valid / --check forever rejected a fresh token — and the refresh loop re-rotated the single-use refresh token every tick, killing the credential (F006). The access token is a JWT whose exp is the authoritative expiry: decode it when expires_in is absent. Fallback to the documented ~6h TTL + a structlog warning when the JWT exp is unreadable, so a fresh token is treated as live instead of stale.