Support updating a session's `gitHubToken` without recreating the session
- Dominant language
- Java
- Stars
- 10.5k
- Forks
- 1.5k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 127
Description
## Problem
`gitHubToken` can only be set at session creation (`SessionConfigBase.gitHubToken`). `session.rpc.options.update()` (rpc.d.ts) has no token/auth field, and no other RPC accepts a replacement token for a live session.
If the token backing a session rotates or is revoked externally, there's no way to refresh it in place — every subsequent turn 401s until the host closes and recreates the session, losing session continuity.
## Request
Support updating a running session's `gitHubToken`, re-resolving the GitHub identity the same way session creation does. Either:
1. Allow `gitHubToken` in `SessionUpdateOptionsParams`, or
2. A dedicated RPC (e.g. `session.rpc.auth.refresh({gitHubToken})`)
Session state (history, mode, loaded skills) should be preserved — that's the point of avoiding close+recreate.
Contributor guide
Research direction
Read rpc.d.ts and SessionConfigBase first, then trace session.rpc.options.update() and the token handling used during session creation. Define and implement one supported live-session update path, re-resolve the GitHub identity, and verify that history, mode, and loaded skills remain intact.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github, typescript
- Domain
- api, authentication, backend
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 52/100