Repository navigation
Document managed auth verification before tasks - #678
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
masnwilliams
left a comment
There was a problem hiding this comment.
lgtm, one note on framing: worth saying up front that this is a pre-task auth check, not a replacement for the normal login flow. .login() first checks whether the profile is still signed in, and if it is, it reaches SUCCESS without submitting anything. if it isn't, kernel logs in again with the saved credentials. if that needs the user (MFA, missing credentials, a captcha), the flow pauses on AWAITING_INPUT/AWAITING_EXTERNAL_ACTION, and at that point you're back to the regular login flow: send the user to the hosted_url from this .login() call. don't call .login() again, because that cancels the flow in progress. the samples should stop at that point and return or throw with hosted_url instead of following the stream until it expires.
|
addressed the pre-task framing and fallback behavior:
updated the TypeScript, Python, and Go samples and re-ran the docs checks. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Want higher recall? High effort reviews run extra passes and find more bugs. A team admin can switch effort levels in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit dab983d. Configure here.
| Call `.login()` immediately before work that requires an authenticated session. Use this as a pre-task authentication check, not a replacement for the normal login flow. Don't rely only on the connection's current `status`: it reflects the latest completed health check, and the website session can expire after that check. | ||
|
|
||
| This is useful when your workflow needs to ensure a connection is authenticated *right now*: | ||
| For a connection with a previous successful login and saved auth check URL, `.login()` runs the verifier first. If the profile is still signed in, the flow reaches `SUCCESS` without submitting anything. If it isn't, KERNEL starts the normal login flow and uses saved credentials when available. |
There was a problem hiding this comment.
Auth-check URL is executor-internal
Medium Severity
The new copy gates verifier-first .login() behavior on a saved auth check URL and names the verifier. That artifact and component are CUA-TS internals, not part of the public connection contract, so readers cannot observe or configure them.
Additional Locations (1)
Triggered by learned rule: Managed Auth docs use the canonical interaction model
Reviewed by Cursor Bugbot for commit dab983d. Configure here.
| ## How do I verify a connection before starting a task? | ||
|
|
||
| Call `.login()` on the connection to trigger auth immediately. See [Triggering re-auth manually](/auth/connection-lifecycle#triggering-re-auth-manually) for the pattern. | ||
| call `.login()` as a pre-task authentication check, then follow the connection until the flow reaches `SUCCESS`. when the connection has a saved auth check url, KERNEL verifies the existing session before attempting a login. if the flow pauses for user action, continue the same flow through the returned `hosted_url`; don't call `.login()` again, because that cancels the flow in progress. don't gate the task only on the connection's current `status`, which reflects its latest completed health check. see [verify authentication before starting work](/auth/connection-lifecycle#verify-authentication-before-starting-work) for the full pattern. |
There was a problem hiding this comment.
FAQ restates lifecycle guidance
Low Severity
The FAQ answer now restates verifier-first behavior, hosted_url handoff, and the warning not to call .login() again, which already live on the lifecycle page, instead of a short pointer plus link.
Triggered by learned rule: Single source of truth — no deep content duplication across pages
Reviewed by Cursor Bugbot for commit dab983d. Configure here.


summary
.login()immediately before authenticated workSUCCESSbefore creating a profile-backed browservalidation
npx -y mint@4.2.930 broken-links/auth/connection-lifecycleand/auth/faqlocally and verified HTTP 200 responsesNote
Low Risk
Documentation-only changes to auth guides; no runtime or API behavior changes.
Overview
Docs now recommend verifying auth immediately before authenticated work instead of framing
.login()mainly as manual re-auth ahead of the next health check.The Connection Lifecycle section is retitled to Verify authentication before starting work and explains that connection
statusonly reflects the last health check, that.login()can verify an existing session first when an auth check URL exists, and that callers should follow the connection stream untilSUCCESSbefore creating a profile-backed browser. It adds end-to-endensureAuthenticatedexamples (TypeScript, Python, Go) that handleAWAITING_INPUT/AWAITING_EXTERNAL_ACTIONviahosted_urlwithout calling.login()again.The FAQ renames the related question and points to the new anchor with the same pre-task verification guidance.
Reviewed by Cursor Bugbot for commit dab983d. Bugbot is set up for automated code reviews on this repo. Configure here.