openclaw/docs
Ayaan Zaidi 63239351ed
fix(auth): use activated credentials for automatic chats (#144975)
Related: #136257

## What Problem This Solves

Fixes an issue where activating a verified replacement sign-in left existing and fresh chats using the old credential, even after a restart. An operator report on September 11 also found misleading model-access feedback, a “Replace key” action that could add an account, and missing command-line activation after unattended setup.

## Why This Change Was Made

The shared credential selector now resolves the activated account for normal replies, `/btw` side questions, and worker inference, preserving explicit account choices and different-model behavior. Duplicate caller logic is removed. Activation also compares normalized runtime settings consistently, so omitted optional model fields do not cause a false connection-change error after saving. The existing setup owner also serves the new `openclaw models auth activate` command; both activation prompts default to Yes after verification. Saved model access is reported separately from application by the running Gateway, and the provider-wide key action is labeled accurately.

## User Impact

- Automatic chats and `/btw` side questions use the activated account; explicit account pins retain precedence.
- Unattended replacement setup prints a command that tests and activates the saved sign-in.
- Enter accepts a successfully verified connection.
- Saved-but-unapplied settings include recovery guidance instead of a failed-save message.

## Evidence

- Real Gateway and recording-provider requests: old credential before; replacement afterward in existing and fresh chats. Explicit pins and a different model retain their expected account selection.
- Real Telegram `/btw`: the activated replacement handles an existing automatic chat, while an explicit old-account pin still uses the old account. The same flow first exposed a false activation error for sparse saved model settings; the corrected flow succeeds.
- Independent public CLI/browser validation confirms the printed activation command, Enter-to-activate, and the key editor.
- Real Telegram Test Server: “Show all” saves the choice in both cases; disabled reload reports saved/unconfirmed, while enabled reload reports visible models.
- The initial fixes passed 377 focused tests across nine files. The caller correction passed 309 tests across five files, including `/btw`, normal replies, worker inference, and person-linked account pins. The configured-account regression fails on the pinned base. A further 17 activation/acknowledgement tests pass, including sparse saved settings and rejection of real concurrent changes.
- All 17 sanitized operator-config shapes reach Gateway readiness. The Tailscale-dependent fixture uses the supported per-run exposure override on the Linux test host; Tailscale Serve itself is not claimed.
- Synthetic provider credentials only. No database, migration, configuration-key, or protocol changes in this PR.

| Before | After |
| --- | --- |
| ![Provider-wide action labeled Replace key](https://gist.githubusercontent.com/obviyus/57fc0c9b946b3c97a4f2fbc140481547/raw/a43eb632a535af7090cbe79dda6056fe2479ec23/before.png) | ![Provider-wide action labeled Set API key](https://gist.githubusercontent.com/obviyus/57fc0c9b946b3c97a4f2fbc140481547/raw/9d7505ede3ec0fbc62442b5ce10c640dc394e032/after.png) |

Captures are cropped to the changed control and exclude account identifiers.

Additional catalog check: sign-in completes through the real xAI plugin against a simulated provider, but its existing endpoint metadata blocks live OAuth catalog discovery. That plugin is unchanged here. New-model discovery, first-account onboarding, and real vendor entitlement are not claimed by this PR.

Co-authored-by: Ayaan Zaidi <hi@obviy.us>
2026-09-11 21:09:48 +05:30
..
.generated fix(models): require explicit GitHub Copilot activation (#144749) 2026-09-11 13:51:44 +05:30
.i18n docs: fix 20 link defects confirmed live in the verified backlog (#144133) 2026-09-11 03:48:10 +08:00
announcements docs: STE pass on terminology consistency and run-on sentences (#143770) 2026-09-10 15:51:49 +09:00
assets
automation docs: close the remaining ia and ste findings (#144089) 2026-09-10 22:28:26 +08:00
channels fix(matrix): preserve unrelated files when migration fails (#144883) 2026-09-11 06:30:18 -07:00
ci docs(ci): correct Windows project concurrency (#144684) 2026-09-11 08:15:36 -07:00
cli fix(auth): use activated credentials for automatic chats (#144975) 2026-09-11 21:09:48 +05:30
concepts feat(ui): offer suggested-task launch choices (#145019) 2026-09-11 08:21:56 -07:00
diagnostics docs: scope version-locked claims across plugins, platforms, providers, and gateway (#144032) 2026-09-10 21:33:28 +08:00
gateway feat(ui): dismiss failed cloud worker snapshot builds (#144671) 2026-09-11 08:18:58 -07:00
help fix(models): require explicit GitHub Copilot activation (#144749) 2026-09-11 13:51:44 +05:30
images
install fix(update): unblock pnpm 12 global updates (#144713) 2026-09-11 01:13:44 -07:00
maturity docs(maturity): restore Windows taxonomy links (#144067) 2026-09-10 06:35:36 -07:00
nodes docs(install,providers,platforms,web): fix 17 concrete defects from the ux audit (#144085) 2026-09-10 22:54:38 +08:00
platforms fix(macos): recover from local Gateway setup errors (#144554) 2026-09-10 20:47:44 -06:00
plugins feat(codex): answer async questions while agents keep working (#144664) 2026-09-11 08:31:25 -07:00
providers fix(models): require explicit GitHub Copilot activation (#144749) 2026-09-11 13:51:44 +05:30
reference fix(update): resolve compatibility bridges within the runtime graph (#144831) 2026-09-11 04:09:42 -07:00
releases docs: make v2026.9.4 release notes easier to read (#144693) 2026-09-11 05:41:49 +00:00
security docs: fix 16 secops-owned audit findings across gateway, cli, and security pages (#144030) 2026-09-10 20:28:21 +08:00
snippets/plugin-publish chore(deps): refresh seven-day eligible packages (#135177) 2026-09-02 18:43:03 -07:00
specs docs: close the remaining ia and ste findings (#144089) 2026-09-10 22:28:26 +08:00
start docs: align model catalog and provider login guides (#144591) 2026-09-11 08:08:13 +05:30
tools fix: dismiss expired Skill Workshop notices (#145015) 2026-09-11 08:22:32 -07:00
web fix: retain plugin detail tab selections while inspection loads (#144647) 2026-09-11 04:17:29 -07:00
agent-runtime-architecture.md docs: close the remaining ia and ste findings (#144089) 2026-09-10 22:28:26 +08:00
AGENTS.md docs: remove duplicate secret placeholder guidance (#144407) 2026-09-10 18:32:49 -03:00
auth-credential-semantics.md fix(auth): use activated credentials for automatic chats (#144975) 2026-09-11 21:09:48 +05:30
ci.md docs: close the remaining ia and ste findings (#144089) 2026-09-10 22:28:26 +08:00
CLAUDE.md
date-time.md
docs.json docs: publish release notes for v2026.9.4 (#144665) 2026-09-10 23:09:00 -06:00
docs_map.md docs: replace private paths and document the ClawHub docs source (#140227) 2026-09-06 23:48:33 +08:00
index.md docs: close the remaining ia and ste findings (#144089) 2026-09-10 22:28:26 +08:00
logging.md fix: distinguish SQLite integrity check time from gate waiting (#144746) 2026-09-11 02:59:54 -07:00
nav-tabs-underline.js
network.md docs: close remaining cross-link gaps across concepts, gateway, and security (#143923) 2026-09-10 18:34:34 +08:00
openclaw-agent-runtime.md docs: close remaining cross-link gaps across concepts, gateway, and security (#143923) 2026-09-10 18:34:34 +08:00
prose.md docs: replace private paths and document the ClawHub docs source (#140227) 2026-09-06 23:48:33 +08:00
style.css
vps.md docs(gateway,concepts,install,help): fix information-architecture findings (#143977) 2026-09-10 19:20:49 +08:00
whatsapp-openclaw.jpg