Skip to content

feat(core): tell users how to sign back in to OpenCode Console - #51847

Merged
vimtor merged 1 commit into
v2from
console-sso-prompt
Sep 29, 2026
Merged

vimtor merged 1 commit into
v2from
console-sso-prompt

Conversation

@vimtor

@vimtor vimtor commented Sep 28, 2026

Copy link
Copy Markdown
Collaborator

Issue for this PR

Closes #

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

When an OpenCode Console account can no longer be used, users currently get a generic model error such as "Workspace access denied" or "Invalid credential", with no hint about what to do. This happens when:

  • the organization enforces SSO and the user's SSO sign-in is missing or expired (Console returns 403 SsoRequired), or
  • the Console session was revoked or expired (401 Unauthorized from Console, or invalid_grant on refresh).

Now the user is told what to do, where they first see the problem:

  • Model error: when a Console model request is rejected with 401/403, the plugin re-checks the Console right away. If the Console reports a sign-in problem, the error is replaced with "Sign in with SSO again to use Acme: " or "Reconnect OpenCode Console to continue." Other 401/403 causes, like no workspace access, keep the original error, since inference returns the same "Workspace access denied" for all of them.
  • /connect: OpenCode Console and the affected account show "Sign in required →". Enter opens the SSO page, or starts a reconnect when signed out.

For SSO the stored credential stays valid, so after signing in in the browser the next prompt works without reconnecting. The last Console config and organization policy are kept while signed out. Only well-formed Console error bodies change anything; HTML pages, 5xx and network errors are ignored as before.

To support this, integrations can report a runtime status on a connection ({ status: "needs_auth", message, url? }, same shape as MCP's status) through ctx.integration.connection.status(...). It is kept in memory, attached to connections in the integration API, and available to both plugin APIs, so other integrations can report the same thing.

How did you verify your code works?

  • bun run check
  • New tests in packages/core/test/plugin/provider-opencode.test.ts for SSO required (status set, config and policy kept, cleared on recovery), the model error rewrite, non-SSO 403s being ignored, a rejected refresh token, and a Console 401.
  • Manually against a fake Console with the TUI: SSO required, recovery after SSO sign-in, revoked session, and the /connect rows.

Screenshots / recordings

hello
Error: Sign in with SSO again to use Acme: https://opencode.ai/console/auth/sso/<connection>/start?redirectTo=%2Fconsole%2F

hello again
Error: Reconnect OpenCode Console to continue.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

@vimtor
vimtor merged commit d76f968 into v2 Sep 29, 2026
14 of 15 checks passed
@vimtor
vimtor deleted the console-sso-prompt branch September 29, 2026 08:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant