Authentication and Credential Recovery

Authentication and Credential Recovery An architecture diagram generated by Archify. Keepalive · _auth/keepalive.py · Architecture component · 60s slot Keepalive _auth/keepalive.py 60s slot PSIDTS Recovery · load → heal → retry · Architecture component · L2 inline PSIDTS Recovery load → heal → retry L2 inline Headless Re-auth · _auth/headless_reauth · Architecture component · opt-in Headless Re-auth _auth/headless_reauth opt-in Browser Sources · Playwright · cookies · CDP · Architecture component Browser Sources Playwright · cookies · CDP Client Runtime · AuthRefreshCoordinator · Architecture component Client Runtime AuthRefreshCoordinator Refresh Driver · _auth/refresh.py · Architecture component · single flight Refresh Driver _auth/refresh.py single flight Cold Recovery · L2.5 → L3 → L4 · Architecture component · one shot Cold Recovery L2.5 → L3 → L4 one shot Master Token · bootstrap · remint · Architecture component · L4 Master Token bootstrap · remint L4 Google OAuth · MergeSession · Rotate · Architecture component Google OAuth MergeSession · Rotate AuthTokens · _auth/tokens.py · on-disk credential authority AuthTokens _auth/tokens.py ProfileStore · storage_state.json · on-disk credential authority ProfileStore storage_state.json Storage Locks · 4 advisory lockfiles · on-disk credential authority Storage Locks 4 advisory lockfiles Android Bearer · labs-tailwind scopes · Architecture component Android Bearer labs-tailwind scopes keepalive task refresh_auth inline heal escalate mutate in place L3 headless L4 remint typed merge gpsoauth launch load bootstrap lock file lock Android scopes on-disk credential authority Legend Backend Database Cloud Security External

Refresh path

  • • Live RPC refreshes coalesce per AuthRefreshCoordinator instance
  • • Cold SingleFlight keys canonical path + rung policy; cancellation spares leader
  • • AuthTokens is mutated in place; collaborators alias it rather than copying

Recovery ladder

  • • L2 inline PSIDTS heal runs outside the cold single flight
  • • L3 headless re-auth is opt-in and never the remote or MCP auth path
  • • L4 remints from a stored gpsoauth master token

Persistence

  • • One path derivation backs all four lock files
  • • credential_io.py is the sole unchecked-atomic writer
  • • Keepalive stamps its claim before the POST, so failure consumes the slot