Skip to content

Add token lifecycle management to client.tokens (refresh/revoke/scopes/copy) - #34

Open
sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2266-token-lifecycle-management
Open

sandshoes wants to merge 1 commit into
mainfrom
tommy/protm-2266-token-lifecycle-management

Conversation

@sandshoes

Copy link
Copy Markdown
Contributor

Summary

  • The SDK can create JWTs and declare static tokens (define_token) but had no way to manage tokens it created afterward. Extends the existing TokensNamespace (client.tokens) with list(), get(name), scopes(name), refresh(name), revoke(name), and copy(name), matching tb token ls/rm/refresh/scopes/copy.
  • Adds TinybirdApi.list_tokens(), get_token(), refresh_token(), revoke_token() wrapping GET /v0/tokens, GET/DELETE /v0/tokens/{name}, and POST /v0/tokens/{name}/refresh, following the existing create_token request-building conventions.
  • Closes https://linear.app/tinybird/issue/PROTM-2266/python-sdk-add-token-lifecycle-management-refreshrevokescopescopy

Verified the real contract instead of guessing: read the vendored Forward CLI client (tinybird/tb/client.py / tinybird/tb/modules/token.py in this project's own dependency tree) to confirm endpoint paths, methods, and — importantly — what tb token copy actually does.

Note on copy: tb token copy copies the token's value to the system clipboard via pyperclip — it does not duplicate a token under a new name, as the ticket's phrasing might suggest. A library has no clipboard, so client.tokens.copy(name) returns the token's current value instead (same underlying data tb token copy puts on the clipboard), for the caller to use or store as needed. Documented clearly in the README so no one goes looking for clipboard behavior.

revoke maps to DELETE /v0/tokens/{name} — there's no separate "revoke" endpoint distinct from delete in the real API; named revoke per the ticket's own wording since that's the more accurate verb for a bearer token (there's nothing to restore).

Checklist

  • CI is green (lint, typecheck, test, secrets)
  • pre-commit run --all-files passes locally (gitleaks step fails in this sandbox on an unrelated SSL/network error fetching its environment — not a code issue)
  • Tests were added or updated when behavior changed
  • Public API / typing changes were reviewed
  • Documentation was updated (README.md / CONTRIBUTING.md) if needed
  • Breaking changes are clearly documented (none — purely additive)
  • CHANGELOG.md was updated when user-facing behavior changed

…s/copy)

Extends the existing TokensNamespace (JWT creation, static token
declaration) with operations on tokens the SDK already references:
list, get, scopes, refresh, revoke, and copy, matching
tb token ls/rm/refresh/scopes/copy. Verified the real endpoint contract
(GET/DELETE /v0/tokens/{name}, POST /v0/tokens/{name}/refresh) against
the vendored Forward CLI client rather than guessing.

tb token copy writes the token value to the system clipboard, which
has no equivalent in a library; client.tokens.copy() returns the same
underlying value instead.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant