You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Follow-up to #490. Slice 2 (#490) makes forge auth login a first-class OIDC login yielding a short-lived IdP token cached under ~/.forge. This slice reuses that identity so a developer's local agent brokers managed MCP tokens as themselves, identical to a deployed run — no separate CLI, no hand-pasted tokens.
Automatic, file-based delivery (chosen approach).forge auth login + forge mcp connect persist resolved MCP state (platform base_url + token/refresh + resolved connections) under ~/.forge/…. Both forge-core and the initializ Strands SDK read it as a fallback source; precedence is env > file so CI/deploy still win via env. After login + connect, running the agent "just works" — no eval, no export — and the file is re-read each run so token refresh is never stale. forge mcp env remains the CI / other-shell escape hatch (a child process can't mutate the parent shell's env, which is why the file is the automatic path).
forge mcp list / forge mcp connect — list shows the dev's workspace-granted connections from the platform (merged with local forge.yaml, tagged by source + mode). connect reuses forge mcp login's browser/PKCE machinery but targets the platform connect flow so the refresh token is vaulted platform-side, not stored locally.
Direct-vs-platform switch — no platform URL → direct types only (oauth/bearer/static, works standalone/OSS); platform URL set → workspace grants resolve platform/user via the managed resolver. auth.type stays the per-connection signal; platform-config presence gates the platform modes (a direct block remains usable as an OSS fallback).
Platform-side dependency (tracked separately)
The type: user (delegated) tokens for a developer's own identity are minted by the managed platform, not by forge. That platform-side work — accepting a verified developer identity and minting a delegated token scoped to the caller's own grant — is tracked in the platform (agent-builder) backlog and has its own authorization prerequisite that must land first. It is out of scope for this forge issue beyond the client contract (endpoints + request shape) that #490 already establishes. This issue can be built and merged against a stub/mock of that endpoint; end-to-end delegated dev flow lights up once the platform side ships.
Platform-side managed delegated-token endpoint for developer identity + its authz prerequisite (tracked in the platform backlog) — required for the end-to-end delegated dev flow
Follow-up to #490. Slice 2 (#490) makes
forge auth logina first-class OIDC login yielding a short-lived IdP token cached under~/.forge. This slice reuses that identity so a developer's local agent brokers managed MCP tokens as themselves, identical to a deployed run — no separate CLI, no hand-pasted tokens.Parent: #455. Base: #490 (native OIDC
GatewayTokenProvider+ interactiveforge auth login).Scope (forge side)
Platform settings block (parallel to
settings.ModelGateway's OIDC fields from feat(#455 slice 2): native OIDC GatewayTokenProvider (auth-code+PKCE / device-code / client_credentials) #490):platform.base_urlfor the managed token/consent/grants endpoints, user + managed layers resolved viaTrustedGatewayLayers. Issuer is shared with the gateway; only the audience differs (gateway vs platform).Platform-audience token from the feat(#455 slice 2): native OIDC GatewayTokenProvider (auth-code+PKCE / device-code / client_credentials) #490
GatewayTokenProvider— reuse the cached refresh to acquire a token the managed platform accepts (add a platform aud/scope to the login, or a siblingPlatformTokenProviderover the same store). feat(#455 slice 2): native OIDC GatewayTokenProvider (auth-code+PKCE / device-code / client_credentials) #490's "openai-only, never sign in against the anthropic public URL" guardrail is gateway-specific and does not constrain a platform-aud token.Automatic, file-based delivery (chosen approach).
forge auth login+forge mcp connectpersist resolved MCP state (platform base_url + token/refresh + resolved connections) under~/.forge/…. Both forge-core and the initializ Strands SDK read it as a fallback source; precedence is env > file so CI/deploy still win via env. Afterlogin+connect, running the agent "just works" — noeval, no export — and the file is re-read each run so token refresh is never stale.forge mcp envremains the CI / other-shell escape hatch (a child process can't mutate the parent shell's env, which is why the file is the automatic path).forge mcp list/forge mcp connect—listshows the dev's workspace-granted connections from the platform (merged with localforge.yaml, tagged by source + mode).connectreusesforge mcp login's browser/PKCE machinery but targets the platform connect flow so the refresh token is vaulted platform-side, not stored locally.Direct-vs-platform switch — no platform URL → direct types only (
oauth/bearer/static, works standalone/OSS); platform URL set → workspace grants resolveplatform/uservia the managed resolver.auth.typestays the per-connection signal; platform-config presence gates the platform modes (a direct block remains usable as an OSS fallback).Platform-side dependency (tracked separately)
The
type: user(delegated) tokens for a developer's own identity are minted by the managed platform, not by forge. That platform-side work — accepting a verified developer identity and minting a delegated token scoped to the caller's own grant — is tracked in the platform (agent-builder) backlog and has its own authorization prerequisite that must land first. It is out of scope for this forge issue beyond the client contract (endpoints + request shape) that #490 already establishes. This issue can be built and merged against a stub/mock of that endpoint; end-to-end delegated dev flow lights up once the platform side ships.Acceptance criteria
forge auth login(feat(#455 slice 2): native OIDC GatewayTokenProvider (auth-code+PKCE / device-code / client_credentials) #490) →forge mcp connect X→ running the agent brokersXas the developer, with no env export (against the managed endpoint or a mock).platform(agent-principal) and asserted-subject deployed paths are unchanged (regression-tested).~/.forgefile as a fallback; env wins when set.forge mcp listshows workspace-granted connections when a platform URL + login are present.oauth/bearer/staticconnections unchanged.Touch points (forge)
forge-core/llm/oauth+ settings (built in feat(#455 slice 2): native OIDC GatewayTokenProvider (auth-code+PKCE / device-code / client_credentials) #490)forge-cli/cmd/{auth_gateway,mcp_list,mcp_login}.go(+ amcp connectand the~/.forgefile persistence)initializStrands SDK config loader (~/.forgefallback) — external repo, coordinatedDepends on