{"record":{"id":"ceefc5c5d01a0703","repo":"ruvnet/ruflo","slug":"cognitum-auth-service-returned-an-unexpected-respo","errorCode":null,"errorMessage":"Cognitum auth service returned an unexpected response: ${e.message}","messagePattern":"Cognitum auth service returned an unexpected response: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"v3/@claude-flow/cli/src/auth/client.ts","lineNumber":221,"sourceCode":" * Refreshes an access token. Classifies failure into network-unreachable\n * vs. a reachable-but-erroring server so callers can print an honest\n * message instead of collapsing both into \"offline\" (ADR-308 failure\n * policy: local ruflo functionality is never affected by auth being\n * unavailable, but the diagnostic should say WHY it's unavailable).\n */\nexport async function refreshAccessToken(refreshTokenValue: string): Promise<OAuthTokenResponse> {\n  const sec = await loadSecurityOAuth();\n  try {\n    return await sec.refreshToken(refreshTokenValue);\n  } catch (e) {\n    if (e instanceof sec.OAuthError) {\n      if (e.code === 'network') {\n        throw new Error(\n          'Could not reach the Cognitum auth service. ruflo core functionality is unaffected — ' +\n            'sign-in is not required for local use.',\n        );\n      }\n      throw new Error(`Cognitum auth service returned an unexpected response: ${e.message}`);\n    }\n    throw e;\n  }\n}\n\n/**\n * Returns an access token suitable for an authenticated call.\n *\n * Fast path: a process-memory token with more than one minute remaining.\n * Slow path: load the profile's refresh token from the OS keychain, perform\n * one refresh, persist a rotated refresh token BEFORE exposing the new access\n * token, then update metadata and the process cache. Refresh is deliberately\n * demand-driven: offline-safe commands such as plain `auth status` never call\n * this function and therefore never create background traffic or retry loops.\n */\nexport async function getValidAccessToken(profileName = 'default'): Promise<string> {\n  const profile = getProfile(profileName);\n  if (!profile) throw new NotLoggedInError(profileName);","sourceCodeStart":203,"sourceCodeEnd":239,"githubUrl":"https://github.com/ruvnet/ruflo/blob/fa13ee4ad60ac2090b1480656eb233521790d640/v3/@claude-flow/cli/src/auth/client.ts#L203-L239","documentation":"refreshAccessToken() rethrows an OAuthError from the security package whose code is NOT 'network' — i.e. the Cognitum auth service was reachable but the refresh failed for a protocol/server reason (invalid_grant, server error, malformed token response). The original message from @claude-flow/security is embedded verbatim.","triggerScenarios":"Calling getValidAccessToken() or refreshAccessToken() when: the persisted refresh token was revoked or expired server-side (invalid_grant); the refresh token was already spent (Cognitum rotates tokens with reuse detection, so a replayed/stale token fails); the server returned 5xx; or the token endpoint responded with an unexpected body/status.","commonSituations":"Refresh token rotated on another machine sharing the same profile store, so this machine's copy is stale; server-side revocation of old tokens; auth service deployed a breaking change; clock skew or malformed responses via an intercepting proxy.","solutions":["Re-authenticate: run `ruflo auth login --profile <profile>` to obtain fresh tokens (most invalid_grant cases)","If multiple machines share credentials, stop doing that — rotation with reuse detection will keep invalidating the loser","Check the embedded e.message: 'invalid_grant' means re-login; HTTP 5xx means wait and retry later","If it persists after a fresh login, check the auth service status and any proxy between you and auth.cognitum.one"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  token = await getValidAccessToken(profile);\n} catch (e) {\n  if (e instanceof Error && e.message.startsWith('Cognitum auth service returned an unexpected response')) {\n    // e.message suffix is the server's OAuthError text: invalid_grant => re-login, 5xx => retry later\n    if (e.message.includes('invalid_grant')) await promptRelogin(profile);\n    else await retryLater();\n  } else throw e;\n}","preventionTips":["Never share one profile's refresh token across machines — rotation with reuse detection will invalidate copies","Log the embedded server message; it distinguishes revoked tokens from outages","On invalid_grant, delete local profile state and re-login rather than retrying the stale token"],"tags":["auth","oauth","refresh-token","server-error"],"backgroundTag":"oauth-refresh-failed","analyzedSha":"fa13ee4ad60ac2090b1480656eb233521790d640","analyzedAt":"2026-08-18T21:34:22.708Z","contentChangedAt":"2026-08-18T21:34:22.708Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}