Skip to content

feat(llm): Anthropic OAuth Bearer auth support - #43

Merged
ALuhning merged 8 commits into
masterfrom
feat/anthropic-oauth-bearer
Mar 9, 2026
Merged

ALuhning merged 8 commits into
masterfrom
feat/anthropic-oauth-bearer

Conversation

@jim-agent

Copy link
Copy Markdown
Collaborator

Summary

  • Backend now correctly sends Anthropic OAuth tokens via Authorization: Bearer header + anthropic-beta: oauth-2025-04-20 (matching nearai/ironclaw#384)
  • Previously OAuth tokens were sent as x-api-key which Anthropic rejects with 401

Changes

  • llm-factory.ts: Uses createClient() to bypass LangChain's apiKey handling for OAuth tokens
  • anthropic-provider.ts: Auto-detects OAuth tokens by sk-ant-oat prefix and configures SDK with authToken
  • admin.ts: Model-fetch endpoint uses Bearer auth when key is an OAuth token

Test plan

  • TypeScript build passes
  • OAuth token works for agent LLM calls (LangChain path)
  • OAuth token works for extraction provider calls (direct SDK path)
  • Standard API keys still work unchanged

🤖 Generated with Claude Code

jim-agent and others added 3 commits March 8, 2026 23:20
The token-sync entrypoint.sh was excluded by the wildcard ignore rule,
causing Docker build to fail with "not found" error.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Add a simpler alternative to the full OAuth authorization code flow:
admins can paste an OAuth token (from `claude login` or `claude setup-token`)
directly in the LLM Config panel. The token is encrypted in the config DB
and synced to the shared volume for Ironclaw.

The full OAuth client ID/secret flow is preserved under an "Advanced" toggle.

Also fixes .dockerignore excluding entrypoint.sh from the Ironclaw build.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Anthropic OAuth tokens (sk-ant-oat*) require Authorization: Bearer +
anthropic-beta: oauth-2025-04-20 header instead of x-api-key.

- LLM factory: use createClient() to bypass LangChain's apiKey handling
  for OAuth tokens, passing authToken + beta header directly
- AnthropicProvider: auto-detect OAuth tokens by prefix and configure
  SDK with authToken instead of apiKey
- Admin API: use Bearer auth when validating/fetching models with OAuth tokens

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@jim-agent
jim-agent requested a review from ALuhning March 9, 2026 09:59
jim-agent and others added 5 commits March 9, 2026 06:24
Replace docked sidebar + per-tab AI panel variants with a single
floating, draggable, resizable panel accessible from all tabs via
an "AI" button in the top bar.

- AIStaffPanel: always renders floating variant (no more docked/floating split)
- AIStaffFloating: removed FAB button, added resize handle, close via context
- ProblemSetTabContainer: lifted AIStaffProvider to wrap nav bar, added
  AIActivityButton with unread badge next to Invite button
- COPTab: removed agent-status sidebar item (now global)

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Override react-d3-tree default label styles to use light text
colors that are readable on the dark theme background.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Problem-framing, CoG analysis, LOE gap analysis, and narrative synthesis
agents now use createLLMForAgent() with context-aware prompts built from
agent character definitions. Each falls back to rule-based stub on error.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds an Override Validation button to the admin dashboard that:
- Enables override: reinstates all disabled agents, prevents circuit
  breaker from auto-disabling agents while active
- Disables override: re-enables validation enforcement, triggers a
  validation run so agents that still fail get disabled again
- Requires justification for audit trail, logged as circuit events

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
… fix

Add AgentTeamComposer component to Design tab AI panel allowing users to
augment default section agents with additional agents from the registry.
Backend runs supplementary agents in parallel using their character personas.
Re-surface document-level agent assignment on Understand tab cards with
visible "Assign Agent" button and fix AgentBadges crash on undefined agentId.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@ALuhning
ALuhning merged commit 7a37d26 into master Mar 9, 2026
2 checks passed
@ALuhning
ALuhning deleted the feat/anthropic-oauth-bearer branch March 9, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants