Relationships
↔ sibling #2954#2928 auth whoami says the stored API key is no longer valid when auth.json only holds an env-key identity cache
Opened by hammz · 10/1/2026· Shipped 10/2/2026
Description
A run authenticated with SWAMP_API_KEY caches its identity in auth.json (serverUrl, username, collectives, apiKeyFingerprint) with an empty apiKey. A later run in the same config dir with no credential (for example a nested swamp in a workflow shell step, which gets no SWAMP_* credential) runs swamp auth whoami and reports:
Stored API key is no longer valid. Run 'swamp auth login' to re-authenticate.Nothing was revoked. There is simply no key, and the message should be the plain no-credential one (Not authenticated. Run 'swamp auth login' to sign in.).
Steps to reproduce
- With HOME and XDG_CONFIG_HOME pointing at an empty dir, run any gated command with SWAMP_API_KEY set (for example swamp model search). This writes auth.json with apiKey empty.
- Unset SWAMP_API_KEY and run swamp auth whoami --json against the same config dir.
Expected: Not authenticated. Run 'swamp auth login' to sign in. Actual: Stored API key is no longer valid. Run 'swamp auth login' to re-authenticate.
Reproduced on 20261001.202145.0-sha.a3515474. Found while verifying swamp-club#2924.
Shipped
Click a lifecycle step above to view its details.