Codex review round 9 on 0dbab2ec3:
- matchesReplacementCredential: a same-org incoming credential now also
claims a row whose STORED credential shares a base identity
(email/account/project) with it, so a later login that loses the email
but keeps the account updates its row instead of duplicating the
subscription. Different orgs still never match; org-less logins keep
exact-key matching only.
- #buildUsageCacheIdentity: treat orgId as a stable identifier so
org-only credentials no longer fall back to a rotating token hash that
churned their usage cache keys on every OAuth refresh and fragmented
usage history.
One Anthropic account email can hold multiple organizations (a Team seat
plus a personal Max plan), each with its own org-scoped OAuth token and
independent 5h/7d limit pools. Credentials were deduped by bare email, so
logging in with the second subscription silently replaced the first, and
usage reports from the two pools merged into one row with mixed numbers.
- capture organization uuid/name at login (token exchange response, with
a claude_cli/bootstrap fallback); token refreshes never rewrite it
- key anthropic credential identity as email + org; a legacy email-keyed
row is claimed in place by the first org-scoped login with the same
email, and org-less credentials never clobber org-scoped rows
- partition usage-report dedupe and the per-credential usage cache by
org so the two subscriptions' limit pools stay distinct for rotation
- show the organization in omp usage (redaction-safe) and name the
stored account/org in the login success message
- Added client-side usage overlays to the auth broker to support granular, credential-specific usage reporting.
- Integrated Fable weekly usage windows and limits into the Claude rate-limiting and ranking strategies.
- Optimized rate-limit handling by caching null results during backoff and disabling retries for 429 status codes.
- Updated credential storage to ingest and persist overlay-based usage data for improved account selection.
- Added `parseClaudeRateLimitHeaders` to extract 5h/7d utilization from `anthropic-ratelimit-unified-*` response headers.
- Added `AuthStorage.ingestUsageHeaders` to warm the per-credential usage cache from headers, throttled to 60s per key.
- Merges header-derived limits onto the last full usage report, preserving per-tier data not present in headers.
- Wires ingestion into `AgentSession` on each Anthropic response to reduce direct OAuth `/usage` probes.
- Replaced inline definitive-failure checks with shared isDefinitiveOAuthFailure in auth-storage and refresher.
- Disabled credentials during definitive OAuth refresh failures and captured the disabling cause on the credential row.
- Wrote null usage-cache entries with expiresAt set to 0 when credentials were disabled to prevent stale reports.
- Added tests for invalid_grant and transient OAuth refresh outcomes, including cache and credential-state assertions.
- Updated Unreleased changelog notes to document OAuth refresh fixes and stale usage-cache clearing behavior.
- Added `providerRetryWait` and `retryWait` hooks to stream/usage options so tests bypass real scheduler delays.
- Parameterized GitHub Copilot poll intervals and Copilot model retry base delay for fast test execution.
- Replaced `Bun.sleep`/`setTimeout` polling loops with `AbortSignal` event listeners in agent session tests.
- Consolidated auth-gateway E2E helpers into a shared `test/helpers` module, eliminating duplicated `checkGatewayAvailable` implementations.
- Migrated credential-disabled tests from SQLite-backed stores to an in-memory store, removing temp-dir lifecycle overhead.
- Migrated per-object caches (chat/tool starts, model fingerprints, validation contexts, provider indexes, render IDs) from WeakMap to Symbol-keyed properties on the objects themselves.
- Rewrote SSE debug tee as a single-pass inline parser, eliminating the body.tee() + readSseEvents re-parse pipeline.
- Refactored MockModel from a factory function + external WeakMap state into a self-contained class.
- Added FIFO memoization caches for heuristic candidate expansion and namespace suffix lookups.
- Added `omp auth-gateway serve/token/status` — a forward-proxy injecting broker credentials for OpenAI Chat, Anthropic Messages, and OpenAI Responses wire formats.
- Added `GET /v1/usage` to auth-broker and auth-gateway; usage cache switched to 5-min per-credential TTL with jitter and last-good fallback on failure.
- Added `AuthStorage.setConfigApiKey/removeConfigApiKey/clearConfigApiKeys` so `models.yml` `apiKey` beats OAuth tokens without overriding `--api-key`.
- Added `omp auth-broker migrate --from-local` for idempotent upload of local SQLite/env credentials to the broker.