zed-industries/zed · error
{e}
Error message
{e} What it means
This error wraps the failure of an already-in-flight shared token-refresh task. When an access token is expired and another task is already refreshing the SuperGrok credentials, get_fresh_credentials awaits that shared task instead of starting a second refresh; if the shared refresh fails (fatally, e.g. revoked refresh token, or transiently, e.g. network error), its Arc<anyhow::Error> is converted into LanguageModelCompletionError::Other via anyhow!("{e}"). It exists so concurrent requesters don't each hit the token endpoint; they instead receive the original refresh failure.
Solutions
- Read last_auth_error on the State entity (set on fatal refresh) and prompt the user to sign in again if the failure was fatal.
- Inspect the wrapped Arc<anyhow::Error> to distinguish transient (retry after backoff) from fatal (re-authentication required) failures.
- Retry the request after a short delay if the underlying failure was transient — a subsequent get_fresh_credentials will start a fresh refresh since refresh_task is cleared.
- Check network/proxy configuration if failures cluster in restricted environments.
Example fix
// before
let creds = get_fresh_credentials(&state, &http_client, cx).await?;
// after
let creds = match get_fresh_credentials(&state, &http_client, cx).await {
Ok(creds) => creds,
Err(LanguageModelCompletionError::Other(e)) if is_transient(&e) => {
backoff_retry(|| get_fresh_credentials(&state, &http_client, cx)).await?
}
Err(e) => {
prompt_reauthentication();
return Err(e);
}
}; Defensive patterns
Strategy: retry
Validate before calling
let state_ref = state.upgrade().ok_or_else(|| anyhow!("state dropped"))?;
let (creds, refresh_in_flight) = state_ref.read_with(&*cx, |s, _| (s.credentials.clone(), s.refresh_task.is_some()))?;
if creds.as_ref().map_or(true, |c| c.is_expired()) && refresh_in_flight {
log::info!("token refresh already running; failure will surface as Other error");
} Type guard
fn is_refresh_failure(err: &LanguageModelCompletionError) -> Option<&anyhow::Error> {
match err {
LanguageModelCompletionError::Other(e) => Some(e),
_ => None,
}
} Try / catch
match get_fresh_credentials(&state, &http_client, cx).await {
Ok(creds) => creds,
Err(LanguageModelCompletionError::Other(e)) => {
log::warn!("shared token refresh failed: {e:#}");
return Err(anyhow!("SuperGrok auth refresh failed: {e:#}"));
}
Err(e) => return Err(e.into()),
} Prevention
- Check last_auth_error before issuing completion requests after a period of idleness
- Distinguish fatal vs transient refresh failures before deciding to retry
- Add exponential backoff on transient token-endpoint failures
- Monitor network reachability to the OAuth token endpoint in restricted environments
When it happens
Trigger: Calling stream_open_ai_completion while the stored SuperGrok access token is expired AND s.refresh_task is Some (another caller already started a refresh), and that shared refresh task completes with an Err — either RefreshError::Fatal (refresh token rejected/invalid_grant) or RefreshError::Transient (HTTP/network failure against the token endpoint).
Common situations: User's refresh token expired or was revoked server-side; corporate proxy or offline network blocks the OAuth token endpoint; the token server returns 4xx/5xx during a burst of completion requests after the access token lapsed.
Related errors
- Token refresh failed
- Could not fetch Authorization Server Metadata for
- Could not fetch Protected Resource Metadata for
- OAuth callback was cancelled
- Sign-out occurred during token refresh
AI-assisted analysis of zed-industries/zed@916fc2b8cb (2026-09-19).
Data as JSON: /api/errors/1431e4e31954b3af.
Report an issue: GitHub.
Appendix: source
Thrown at crates/x_ai_subscribed/src/x_ai_subscribed.rs:601
http_client: &Arc<dyn HttpClient>,
cx: &mut AsyncApp,
) -> Result<SuperGrokCredentials, LanguageModelCompletionError> {
let (creds, existing_task) = state
.read_with(&*cx, |s, _| (s.credentials.clone(), s.refresh_task.clone()))
.map_err(LanguageModelCompletionError::Other)?;
let creds = creds.ok_or(LanguageModelCompletionError::NoApiKey {
provider: PROVIDER_NAME,
})?;
if !creds.is_expired() {
return Ok(creds);
}
if let Some(shared_task) = existing_task {
return shared_task
.await
.map_err(|e| LanguageModelCompletionError::Other(anyhow!("{e}")));
}
let http_client_clone = http_client.clone();
let state_clone = state.clone();
let previous_refresh_token = creds.refresh_token.clone();
let previous_email = creds.email.clone();
let generation = state
.read_with(&*cx, |s, _| s.auth_generation)
.map_err(LanguageModelCompletionError::Other)?;
let shared_task = cx
.spawn(async move |cx| {
let result = refresh_token(&http_client_clone, &previous_refresh_token).await;
match result {
Ok(tokens) => {
let persist_result: Result<SuperGrokCredentials, Arc<anyhow::Error>> = async {View on GitHub (pinned to 916fc2b8cb)