# Auth token expired mid overnight intel run, briefing failed

## TL;DR
Overnight runs outlive their auth tokens, and the briefing fails at 3am when nobody is watching. The fix is the same token lifecycle as daytime runs, plus unattended recovery: refresh on a timer, retry once on 401, and checkpoint so a failed refresh resumes in the morning instead of losing the night. Overnight runs must be more resilient, not less.

## The error
```text
(overnight run failed)
auth token expired mid overnight intel run, briefing failed; 401s from 02:14 onward, no briefing at 06:00
```

## When this helps
- overnight runs fail on expired auth
- long unattended runs 401 mid way
- building overnight-resilient agents
- designing auth for scheduled runs

## When it doesn't
- the token was never valid; fix credentials setup
- the provider revoked access; re-authenticate fully
- runs are short; daytime refresh logic suffices

## Works with
Any OAuth 2.0 provider as of 2026; python 3.8+ with requests.

## Steps
### 1. Schedule proactive refresh through the night
```python
import time
def needs_refresh(issued_at, lifetime):
    return int(time.time()) - issued_at not in range(0, lifetime - 600)
print("refresh 10 minutes before expiry; overnight margin is wider")
```
Expected: A refresh check with a 10-minute margin. Overnight runs cannot afford to discover expiry via 401.

### 2. Checkpoint before each authenticated batch
```python
import json
state = {"batch": 4, "of": 12}
open("night_state.json", "w").write(json.dumps(state))
print("checkpointed at batch", state["batch"])
```
Expected: A checkpoint file. If auth fails unrecoverably, the morning run resumes at batch 5.

### 3. Retry once with refresh on 401, then park the run
```python
import requests
s = requests.Session()
r = s.get("https://YOUR-provider/api/data", timeout=30)
if r.status_code == 401:
    print("401 overnight: one refresh-and-retry, then checkpoint and sleep")
print("status:", r.status_code)
```
Expected: A bounded recovery. One retry, then the run parks cleanly instead of spinning until morning.

### 4. Alert on auth failure instead of failing silently
```python
import json
alert = {"run": "overnight-intel", "issue": "auth refresh failed", "resume_from": "batch 5"}
open("alert.json", "w").write(json.dumps(alert, indent=2))
print("alert written; morning operator resumes from the checkpoint")
```
Expected: An alert record. Silent overnight failures are the worst kind; the checkpoint plus alert makes recovery trivial.

## Other ways people phrase this
### auth expired overnight run failed
Proactive refresh plus checkpoints. The night must be self-healing.

### overnight briefing 401 auth
One refresh-and-retry, then park with a checkpoint and alert.

### token expiry unattended agent
Wider margins overnight. Silence is the enemy; alert on failure.

## Why it happens
Overnight runs last longer than token lifetimes, and nobody is awake to re-authenticate. Without proactive refresh, the run 401s at 3am and the morning has no briefing. Checkpoints plus alerts turn an auth failure into a resumable pause instead of a lost night.

## Edge cases
- Refresh tokens can expire too; the alert path must cover full re-auth.
- Overnight rate limits differ from daytime; budget separately.
- A run that parks should not hold partial locks; release them in the park path.
- Test the overnight auth path during the day with a short-lived token.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_K6ybDTNaa71tfLhQPJFtFA
