Check CLI and ADC logins across providers: expiry, scopes, re-login commands.
Pro shows the line behind each finding and how to fix it
Scanned 10/6/2026
npx -y skills add fmind/dot --skill auth-status --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Auth Status?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/fmind-auth-status)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: auth-status
description: "Check CLI and ADC logins across providers: expiry, scopes, re-login commands."
license: MIT
metadata:
kind: task
author: Médéric HURIER (Fmind)
source: github.com/fmind/dot/tree/main/skills/auth-status
created: "2026-10-04"
updated: "2026-10-05"
---
# Auth Status
Answer "am I logged in, until when, and what must I run?" with read-only probes, then hand the user the exact interactive command. `dot doctor --deep` owns the workstation probes; this skill adds the remaining connectors, scope coverage, and recovery. [dot-cli authentication](../dot-cli/references/authentication.md) owns login policy, scopes, and account overrides; each connector skill owns its provider's account selection.
## Workflow
1. **Run the workstation probes**: `dot doctor --deep --json` checks GitHub, the gcloud CLI, ADC, and Workspace with bounded probes and never prints tokens. Read only the auth group; `condition` distinguishes `unauthenticated` from `broken` (state unknown) and flags `insecure` when gh keeps its token in plaintext `hosts.yml`.
```bash
dot doctor --deep --json | jq -c '.checks[] | select(.group == "auth") | {name, status, condition, details}'
```
1. **Check scope coverage**: compare granted scopes with the configured policy (`dot config show`, keys `auth.github.scopes`, `auth.workspace.scopes`, and `auth.gcp.adc_scopes`). GitHub lists them in `gh auth status --active --hostname github.com` (the token is masked); Workspace in `gws auth status | jq '{user, token_valid, has_refresh_token, scopes}'`. A missing scope needs a new login even when the probe passes.
1. **Probe other named connectors**: only those the task or user names, each read-only with its exit status checked:
| Provider | Probe | Recovery |
| ------------ | ------------------------------------------------------------------------------------------- | -------------------------------------------------------- |
| Colab | `colab --auth adc sessions` (allocates no VM; inspect stderr before trusting an empty list) | `dot login colab` |
| Hugging Face | `hf auth whoami` | `hf auth login` |
| Kaggle | `kaggle competitions list --page-size 1 >/dev/null` | `kaggle auth login` |
| AWS SSO | `aws sts get-caller-identity --profile <profile> --no-cli-pager` | `aws sso login --profile <profile>` |
| Databricks | `databricks auth profiles` (validates each profile) | `databricks auth login --host <url> --profile <profile>` |
| Atlassian | `acli auth status`; API-token Jira: `acli jira auth status` | `acli auth login` |
1. **Report only provider-exposed expiry**: AWS SSO sessions: `jq -r '.expiresAt // empty' ~/.aws/sso/cache/*.json` (never print the file). Google access tokens refresh hourly; `invalid_grant` or "reauthentication" means the refresh token expired or an organization session policy requires login. Hugging Face tokens do not expire unless revoked. Otherwise write "unknown"; never infer expiry from file dates.
1. **Check environment overrides**: environment credentials win over stored logins. Report presence only, never values:
```bash
for name in GH_TOKEN GITHUB_TOKEN GOOGLE_APPLICATION_CREDENTIALS CLOUDSDK_AUTH_ACCESS_TOKEN_FILE \
GOOGLE_WORKSPACE_CLI_TOKEN GEMINI_API_KEY GOOGLE_API_KEY HF_TOKEN KAGGLE_API_TOKEN \
AWS_PROFILE AWS_ACCESS_KEY_ID AWS_SESSION_TOKEN DATABRICKS_HOST DATABRICKS_TOKEN DATABRICKS_CLIENT_SECRET; do
[ -n "$(printenv "$name")" ] && echo "$name is set"
done
```
1. **Report and hand off**: one table of provider, account (no token), status, scopes gap, expiry, and next action. Browser logins are interactive: give each as `! <command>` for the user to run in the session, preferring `dot login all` or `dot login github|workspace|gcp|colab` over native commands. When the user says they logged in, re-run only the failed probes.
## Gotchas
- **Never print secrets**: no `print-access-token`, `hf auth token`, `kaggle auth print-access-token`, `kaggle config view`, `aws configure export-credentials`, or `--show-token` in a transcript; dot's probes capture token output internally.
- **Exit 0 is not proof**: `gh auth status --json` and Colab can succeed while reporting a failure; read the state and stderr.
- **Native ADC logins drop configured scopes**: a native ADC login (`gcloud auth application-default login`, `gcloud auth login --update-adc`) replaces the grant and drops the Colab and BigQuery read-only scopes; `dot login gcp|colab` request `auth.gcp.adc_scopes`, which keeps them. Run `dot login colab` to restore them ([Colab ADC](../dot-cli/references/authentication.md#colab-adc)).
- **Probing is read-only**: logging in, switching accounts, adding scopes, or editing `dot` configuration needs the user.
## Documentation
- [gh auth status](https://cli.github.com/manual/gh_auth_status) · [gcloud auth](https://cloud.google.com/sdk/gcloud/reference/auth) · [AWS SSO](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-sso.html)
- Companion skills: [dot-cli](../dot-cli/SKILL.md) (login and setup), [gcloud](../gcloud/SKILL.md), [gh](../gh/SKILL.md), [gws](../gws/SKILL.md), [colab](../colab/SKILL.md).
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!