403 concurrency caps bypass credential rotation in stream and auth-retry paths; snake-case concurrency codes classify; a session-level test covers the Copilot credential-removal gate.
(cherry picked from commit aca348e797ed987750a14ecf625952b6b971f7a5)
- Treat `403 Forbidden` errors as retryable credential-rotation triggers similar to usage limits.
- Skip refresh-same detours for 403 responses and cycle directly through the sibling credential pool.
- Implement `isInvalidatedOAuthTokenError` to identify specific upstream auth failures.
- Enable automatic credential rotation in `AuthStorage` and stream retries when an invalidated token is detected.
- Update `proxy.test.ts` to correctly handle `NO_PROXY` and `no_proxy` environment variables during testing.
Keep ordinary 401 retries bounded while replay-safe quota failures
walk every distinct eligible credential. Anchor blocks to the failed
credential and stop on cycles, aborts, or 64 attempts.
xAI returns HTTP 403 with "run out of credits" / spending-limit when an
account is parked. Classify that as a usage limit so multi-account pools
switch siblings instead of sticking to the exhausted credential.
- Added a read-link probe test that renders text and image paths with active hyperlinks.
- Updated ai auth retry tests for revised static-key validation and rotation behavior.
- Added `ApiKeyResolver`/`ApiKey` types and exported auth-retry helpers.
- Changed stream and gateway auth retry handling to use resolver steps.
- Added initial-key, force-refresh, and rotate credential retries for auth failures.
- Updated agent and coding-agent integrations to use context-aware API-key resolvers.