credential expired mid-run: review agent lost write access to the repo
Restores a review agent that lost write access mid-run when its credential expired. Use it when read calls still work but posting reviews, comments, or statuses starts failing. The tell is that the agent could read the diff minutes ago but suddenly cannot write anything.
TL;DR: Confirm reads still work while writes fail, mint a fresh credential with the same scopes, checkpoint completed work, and resume only the incomplete steps. Agents usually read the diff early and write late, so a short-lived credential dies exactly between the two phases. Resuming without a checkpoint creates duplicate reviews.
credential expired mid-run: review agent lost write access to the repo- Confirm it is expiry, not a permissions change: check whether the failing calls are writes (POST, PATCH) while reads (GET) still succeed.
Expected: reads return 200 and writes return 401 or 403.
- Mint a fresh credential with the same scopes the run started with.
Expected: a lightweight test call authenticates successfully with the new credential.
- Checkpoint everything the run already completed: posted comments, submitted reviews, set statuses. Write it down before touching anything.
Expected: a written record of completed work exists.
- Resume only the incomplete steps, skipping everything in the checkpoint.
Expected: no duplicate reviews, comments, or status updates.
- Verify the final state: the review is posted, all comments are present, statuses are set.
Expected: the PR shows exactly one review from the agent with the full comment set.
- For future runs, refresh the credential ahead of its expiry on long runs and checkpoint after every write.
Expected: expiry becomes a non-event instead of a failure.
Use this when
- the agent loses write access partway through a review run
- reads keep working while writes fail
- the credential has a known short lifetime
Not for this skill when
- writes never worked at all (the credential never had write scope - fix the scopes)
- both reads and writes fail (full auth failure - re-authenticate from scratch)
- the repo was archived or the app uninstalled mid-run (no credential will fix that)
Variant phrasings
review agent could read the PR but not post: credential died mid-run
403 on review submission after successful diff fetch
bot lost write access halfway through the review
Why it happens
Short-lived credentials expire on a timer regardless of what the agent is doing. The typical review run reads the diff in the first minutes and posts the review near the end, so expiry lands in the write phase. The agent perceives this as "lost write access" because reads already succeeded.
Edge cases
- A 403 saying the resource is not accessible to the integration means missing permissions, not expiry; check the app's permission list.
- Some write endpoints return 404 instead of 403 when the credential lacks scope; treat unexpected 404s on write endpoints as suspect.
- If the credential is tied to a user who left the organization, renewal fails; the run needs a new identity, not a refresh.
- Partially submitted reviews (some comments posted, review not submitted) need the review id checkpointed to finish cleanly.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_Fq5a3Eg3DQUYrJsRQbc2dg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.