emma-hermes/website/docs/guides
Jaaneek 5ef0b8acb0 feat(auth): make xAI Grok OAuth device-code-only, drop loopback login
Replace the loopback/PKCE-callback server and manual-paste fallback with
the RFC 8628 device-code flow as the only xAI Grok OAuth login path. The
flow works in headless/SSH/container sessions with no 127.0.0.1 listener,
shrinking the local attack surface.

- Poll the token endpoint with server-provided interval, honoring
  slow_down and expires_in; store tokens with auth_mode
  oauth_device_code.
- Adaptive proactive refresh skew for short-lived device-code JWTs;
  rotated tokens sync back to auth.json, the global root store, and the
  credential pool (no refresh-token replay).
- Clear source suppression on successful re-login (CLI + dashboard) and
  drop the duplicate dashboard pool entry so exactly one seeded
  device_code entry exists.
- Use the shared device_code source name for consistency with the
  nous/codex device-code providers.
- Desktop: remove the loopback OAuth flow states and dead type variants;
  pkce providers' sign-in URL selection is unchanged.
- Docs (EN + zh-Hans) rewritten for device-code login; drop the deleted
  --manual-paste flag from documented commands.
2026-07-02 13:17:41 -07:00
..
_category_.json
automate-with-cron.md
automation-blueprints.md
aws-bedrock.md
azure-foundry.md
build-a-hermes-plugin.md
cron-script-only.md
cron-troubleshooting.md
daily-briefing-bot.md
delegation-patterns.md
github-pr-review-agent.md
google-gemini.md
google-vertex.md
local-llm-on-mac.md
local-ollama-setup.md
microsoft-graph-app-registration.md
migrate-from-openclaw.md
minimax-oauth.md
oauth-over-ssh.md
operate-teams-meeting-pipeline.md
pipe-script-output.md
python-library.md
run-hermes-with-nous-portal.md
run-nemotron-3-ultra-free.md
team-telegram-assistant.md
tips.md
use-mcp-with-hermes.md
use-soul-with-hermes.md
use-voice-mode-with-hermes.md
webhook-github-pr-review.md
work-with-skills.md
xai-grok-oauth.md