SpyBara
Go Premium

Documentation 2026-07-30 16:57 UTC to 2026-08-03 20:59 UTC

1 file changed +3 −1. View all changes and history on the product overview
2026
Wed 19 18:02 Thu 13 07:01 Wed 12 16:01 Tue 11 17:57 Sat 8 23:00 Mon 3 20:59

enterprise.md +3 −1

Details

104auth_provider_command = "/usr/local/bin/your-auth-provider"104auth_provider_command = "/usr/local/bin/your-auth-provider"

105```105```

106 106 

107The command must print either a bare token string or JSON: `{"access_token": "...", "refresh_token": "...", "expires_in": 3600}` (`refresh_token` and `expires_in` are optional). When the token expires, Grok re-runs the command with `GROK_AUTH_EXPIRED=1` set. Interactive login allows up to 300 seconds for the command to complete. Background token refresh uses a 10-second timeout; if the command hangs (e.g., waiting for interactive input), Grok kills it and reports the failure.107The command must print either a bare token string or JSON: `{"access_token": "...", "refresh_token": "...", "expires_in": 3600}` (`refresh_token` and `expires_in` are optional).

108 

109Grok runs the command on two contracts and sets `GROK_AUTH_EXPIRED` to tell them apart. It is `1` on a background refresh over a credential Grok already holds: nobody is watching, and the command has a few seconds before Grok kills it — so mint silently or exit non-zero, never wait for input. It is unset on a sign-in, where a user is attached, the command's stderr is shown to them, and there are up to 300 seconds for a browser round trip or a device code. A command that exits promptly on `GROK_AUTH_EXPIRED=1` rather than prompting is what makes the handover to the sign-in screen fast.

108 110 

109### API key111### API key

110 112