When an HTTP MCP server returns invalid_grant (or invalid_token / revoked / plain 401 from the token endpoint) during OAuth refresh, MCPManager previously logged "MCP OAuth refresh failed, using existing token" and re-attached the stale access token as Authorization: Bearer on every subsequent request. The next tool-load 401'd with invalid_token, future sessions repeated the loop, and the only recovery was to hand-clear the credential row in agent.db. Reported with Logfire as the trigger; any remote HTTP MCP that rotates / revokes refresh tokens is affected. #resolveAuthConfig now reuses pi-ai's isDefinitiveOAuthFailure classifier (same one auth-broker and AuthStorage use for first-party providers): on a definitive failure it calls AuthStorage.remove(credentialId), drops the Bearer entirely, and the next request surfaces a clean auth error so the user can /mcp reauth <server> (or /mcp unauth) to recover. Transient failures (network/fetch failed/ECONNREFUSED) still fall back to the existing token to ride out blips. Verified with new mcp-manager-oauth-refresh.test.ts (invalid_grant, 401, transient fallback, happy-path rotation). The full mcp-* test set (45 tests across 5 files) still passes. Fixes #1908
@oh-my-pi/pi-coding-agent
Core implementation package for the omp coding agent in the oh-my-pi monorepo.
For installation, setup, provider configuration, model roles, slash commands, and full CLI reference, see:
Package-specific references:
- CHANGELOG
- MCP configuration guide
- MCP runtime lifecycle
- MCP server/tool authoring
- DEVELOPMENT
- RenderMermaid guide
Memory backends
The agent supports three mutually-exclusive memory backends, selected via the memory.backend setting (Settings → Memory tab, or ~/.omp/config.yml):
off(default) — no memory subsystem runs.local— existing rollout-summarisation pipeline; writesmemory_summary.mdand consolidated artifacts under the agent dir.hindsight— talks to a Hindsight server (Cloud or self-hosted Docker), retains transcripts every Nth user turn, recalls memories on the first turn of a session, and exposesretain,recall, andreflect.
Hindsight quickstart
- Run a Hindsight server (Cloud or
docker run -p 8888:8888 ghcr.io/vectorize-io/hindsight:latest). - Set
memory.backend = "hindsight"andhindsight.apiUrl = "http://localhost:8888"(or your Cloud URL). - Optional environment overrides (env wins over settings):
HINDSIGHT_API_URL,HINDSIGHT_API_TOKEN— connectionHINDSIGHT_BANK_ID,HINDSIGHT_DYNAMIC_BANK_ID,HINDSIGHT_AGENT_NAME— bank addressingHINDSIGHT_AUTO_RECALL,HINDSIGHT_AUTO_RETAIN,HINDSIGHT_RETAIN_MODE— lifecycleHINDSIGHT_RECALL_BUDGET,HINDSIGHT_RECALL_MAX_TOKENS— recall sizingHINDSIGHT_BANK_MISSION,HINDSIGHT_DEBUG
Switching backends mid-session is honoured on the next system-prompt rebuild and the next /memory slash command. Existing users with memories.enabled = true|false are migrated to memory.backend = "local"|"off" exactly once on first launch.