2.0.17's login-store fallback (cloudConnection in packages/sdk/src/cloud-http.ts) refuses an expired ~/.agentworkforce/relay/cloud-auth.json access token with "The agent-relay cloud login has expired. Run agent-relay cloud login again, or set FLOWS_CLOUD_TOKEN." — correct, but the store also carries refreshToken / refreshTokenExpiresAt, and agent-relay cloud whoami renews the access token in place through POST /api/v1/auth/token/refresh (seen today: expiry moved from 2026-09-18 to 2026-09-19 with one whoami).
flows should do the same before refusing: when the access token is expired and a refresh token is not, call the refresh endpoint, rewrite the store atomically (same shape the relay CLI writes, see relay/packages/cloud/src/* for the exact file contract), and proceed; only refuse when the refresh token is also expired or the refresh fails. Keep the explicit-credential precedence (token option, then FLOWS_CLOUD_TOKEN) untouched.
🤖 Generated with Claude Code
2.0.17's login-store fallback (
cloudConnectioninpackages/sdk/src/cloud-http.ts) refuses an expired~/.agentworkforce/relay/cloud-auth.jsonaccess token with "The agent-relay cloud login has expired. Runagent-relay cloud loginagain, or set FLOWS_CLOUD_TOKEN." — correct, but the store also carriesrefreshToken/refreshTokenExpiresAt, andagent-relay cloud whoamirenews the access token in place throughPOST /api/v1/auth/token/refresh(seen today: expiry moved from 2026-09-18 to 2026-09-19 with onewhoami).flowsshould do the same before refusing: when the access token is expired and a refresh token is not, call the refresh endpoint, rewrite the store atomically (same shape the relay CLI writes, seerelay/packages/cloud/src/*for the exact file contract), and proceed; only refuse when the refresh token is also expired or the refresh fails. Keep the explicit-credential precedence (tokenoption, thenFLOWS_CLOUD_TOKEN) untouched.🤖 Generated with Claude Code