Skip to content

Add experimental Grok consumer account sign-in and verified weekly usage #108

Description

@HemSoft

Add experimental Grok consumer account sign-in and verified weekly usage

Parent and priority

HemSoft/codexbar#70

P2 after native auth and account foundations. This is a planning issue, held out of automation with no-agent until its prerequisites and provider decisions are ready.

Verified gap

Grok consumer usage is implemented in iOS and absent from Windows provider registration and backlog. API spending and Cursor's Grok Bot allowance are different ledgers and cannot fill this gap.

Comparison uses iOS commit 8ebadd77becafb53342ef185202c2162ffa84bd7 and Windows commit 556322132cc60a38e061a329567c18ae84d30f20. Checked the full open and closed Windows issue list before filing. Upstream implementation is evidence of behavior, not proof of Windows or live-provider verification.

Acceptance criteria

  • Add browser-guided device approval with provider polling rules, expiry, cancellation, and account verification through OIDC userinfo before securely saving a token. No cookie extraction, pasted credentials, inference, or purchase is part of connection or refresh.
  • Use the verified first-party CLI consumer billing contract only after documenting the Windows client decision. Verify a current weekly unified paid period before displaying shared-pool percent and reset.
  • Display Extra Usage Credits separately when supplied for verified unified billing. Never merge API/developer-team spend, monthly billing dates, product shares, or Cursor Grok Bot allowances into the consumer weekly meter.
  • Handle absent, present-zero, explicit null, malformed, and conflicting usage fields separately. The narrowly supported omitted-usage zero convention requires a verified known paid plan, current unified weekly period, and no alternative usage fields, with the message No included usage reported by Grok.
  • Use verified plan names for generated label suggestions only. Never overwrite custom labels or infer an entitlement from authorization, a percentage, or a balance.
  • Renewal retains the verified subject. Removed or replaced accounts cannot regain old credentials or cached usage; failed persistence never establishes a connection. Disconnect describes local removal rather than remote revocation.
  • Mark the integration experimental, retain unsupported/unavailable states, and record human review of the Windows client registration or permitted CLI-client use before release.

Tests and verification

Add device-flow and identity fixtures, polling denial/expiry/slow-down, token renewal and removal races, weekly eligibility, paid-plan mapping, omitted zero versus null, product fields, independent balance, expired and monthly windows, and secure persistence failures. Keep an owner-run live comparison of weekly usage/reset and credits pending until actually performed.

Boundaries

The CLI proxy is a first-party implementation contract, not a published third-party API guarantee. Do not treat HTTP 200 as sufficient success or automatically reuse an upstream CLI public client without a recorded owner decision.

Dependencies

Evidence

Validation gates

Implementation must pass dotnet build with zero warnings, dotnet format --verify-no-changes, dotnet test, and dotnet list package --vulnerable. Coverage must meet or exceed the current repository threshold using dotnet test --collect:"XPlat Code Coverage" --settings src/CodexBar.Core.Tests/coverage.runsettings; exclude generated *.g.cs and GeneratedRegex output as required by AGENTS.md. Validate changed Markdown.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent:human-requiredFix exceeds safe automation boundary — human must own thisenhancementNew feature or requestfeature-requestRequested feature or product enhancementno-agentExclude this issue from autonomous processingrisk:highHigh-risk: auth, payments, data migrationssource:manualManually created by developer

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions