-
-
Notifications
You must be signed in to change notification settings - Fork 2
Plugins AI OAuth
Reference for re-authorizing Gemini accounts in the GFP (Gemini Free Pool) after token expiry, scope changes, or account rotation.
The Gemini Free Pool manages OAuth-connected Google accounts to provide free or near-free Gemini API capacity. Tokens expire, scopes sometimes change, and accounts occasionally need rotation. This page explains when re-auth is needed and how to do it.
Four situations require re-authenticating a Gemini account:
Token expiry. Google OAuth refresh tokens can be revoked by Google after 6 months of inactivity, after a password change, or when the account exceeds the concurrent-session limit. The pool detects this on the next key test and marks the key as expired.
Scope change. If the required OAuth scopes for the Gemini API change (for example, adding https://www.googleapis.com/auth/generative-language), existing tokens may not carry the new scope. The pool marks affected keys as scope_mismatch.
Account rotation. You may want to remove a compromised or cancelled Google account from the pool and replace it with a new one.
invalid_grant errors. A 401 response with error: invalid_grant from Google's token endpoint means the refresh token is no longer valid. The pool logs this and marks the key invalid.
To check current pool status and see which keys need attention:
nself ai pool status --verbosenself ai pool status --verbose --jsonLook for keys with status: expired, status: invalid, or status: scope_mismatch. Note the account field (Google account email) and key_id.
nself ai pool remove --account user@example.comOr by key index:
nself ai pool remove --key-id 3This soft-revokes the key in the pool and optionally deletes the GCP API key (you are prompted). It does not delete the Google account.
nself ai pool init --oauthThis opens your browser to a Google OAuth consent page. Sign in with the same (or a new) Google account. After consent, the pool:
- Stores the refresh token locally (encrypted via
nself secrets) - Creates a new GCP project under the account (or reuses an existing one)
- Enables the Generative Language API
- Issues a new API key
- Registers the key in the pool with status
active
The --oauth flag forces the browser-based flow. Without it, nself ai pool init uses any stored credentials first.
nself ai pool test --allOr test just the new key:
nself ai pool test --key-id <new-id>A passing test sends a 1-token Gemini request and confirms the key is live.
The pool runs a background goroutine that refreshes tokens before they expire. The rotation schedule:
- Active check interval: every 12 hours
- Token refresh window: 7 days before expiry
-
Quota reset trigger: daily at midnight UTC (
nself ai pool daily-reset) -
Failure threshold: 3 consecutive failures on a key mark it
degraded; 5 failures mark itexpiredand alert via thenotifyplugin (if installed)
Token storage uses AES-256-GCM encryption via the nself secrets manager. Refresh tokens never appear in logs or the pool status output (only the first 8 characters of the key ID are shown).
When nself build runs, the pool configuration is written to the AI plugin's environment as GFP_POOL_CONFIG (base64-encoded JSON). The plugin reads this at startup and manages the active key selection. If all pool keys are exhausted for the day, the plugin falls back to GEMINI_API_KEY (the static key in .env.dev), then to Ollama if configured.
The refresh token is revoked. Follow the re-auth steps above. Common causes: Google account password changed, account security event, or the token was unused for 6 months.
error: token refresh failed for user@example.com: invalid_grant
Fix: nself ai pool remove --account user@example.com then nself ai pool init --oauth.
The API key itself may be deleted on the GCP side (not the OAuth token). Check the GCP console for the project associated with the account.
Fix: nself ai pool remove --key-id <id> then nself ai pool init --oauth to issue a fresh key.
The new account's free-tier quota is already exhausted (possible if the GCP project was reused and had prior usage). Add a different Google account or wait for the daily quota reset.
nself ai pool daily-reset --dry-run # check what would reset
nself ai pool daily-reset # reset countersRun nself ai pool init --oauth for the affected account. The OAuth consent page will request the updated scopes. Accept them. The pool updates the stored token automatically.
The CLI tries xdg-open (Linux) or open (macOS). If neither works, the command prints the authorization URL for manual opening:
Open this URL in your browser to continue:
https://accounts.google.com/o/oauth2/auth?...
Copy and open it. After authorizing, paste the resulting code at the prompt.
nself ai pool status --verboseAll keys should show status: active and a last_tested timestamp within the past hour. Quota counters should be below their daily limits.
Run a quick end-to-end smoke test:
nself ai chat "hello" --model gemini-1.5-flashA successful response confirms the pool is routing correctly.
-
cmd-ai, full
nself aicommand reference, includingpoolsubcommands -
cmd-oauth,
nself oauth refreshfor non-Gemini OAuth token refresh - plugin-nself-ai-gateway, AI gateway configuration and supported providers
← plugin-nself-ai-gateway | Home →
ɳSelf CLI v1.0.9. MIT licensed. Docs CC BY 4.0.
GitHub · Issues · Discussions · nself.org · nself.org/docs
Getting Started
Commands
- Commands, Overview
- Lifecycle: cmd-init · cmd-build · cmd-start · cmd-stop · cmd-restart · cmd-dev
- Monitoring: cmd-status · cmd-logs · cmd-health · cmd-urls · cmd-doctor · cmd-monitor · cmd-alerts · cmd-sentry · cmd-watchdog
- Data: cmd-db · cmd-backup · cmd-dr · cmd-queue · cmd-webhooks
- Config: cmd-config · cmd-service · cmd-env · cmd-promote
- Networking: cmd-ssl · cmd-trust · cmd-dns-setup
- Security: cmd-access · cmd-security · cmd-secrets
- Tenancy: cmd-tenant · cmd-billing
- Plugins: cmd-plugin · cmd-license · cmd-dogfood (extracted, CLI-R11) · cmd-k8s (extracted, CLI-R11) · cmd-encryption (extracted, CLI-R11) · cmd-waf (extracted, CLI-R11) · cmd-federation (extracted, CLI-R11) · cmd-mail (extracted, CLI-R11) · cmd-dlq (extracted, CLI-R11)
- AI: cmd-ai · cmd-claw · cmd-model
- Templates: cmd-template
- Utilities: cmd-exec · cmd-clean · cmd-reset · cmd-update · cmd-upgrade · cmd-version · cmd-admin · cmd-migrate · cmd-migrate-firebase · cmd-migrate-supabase · cmd-completion
Features
- Features, Overview
- Feature-Auth
- Feature-Storage
- Feature-Search
- Feature-Functions
- Feature-Email
- Feature-Monitoring
- Feature-Plugins
- Feature-nClaw, AI Assistant
- Feature-nChat, Messaging
- Feature-nTV, Media Player
- Feature-nFamily, Family Social
- Feature-nCloud, Managed Hosting
- Feature-Memory-Rooms, Knowledge Organization
- Feature-Agent-Dashboard, Agent Metrics
- Feature-Image-Generation, AI Image Generation
Configuration
- Configuration, Overview
- Config-Env-Vars
- Config-Postgres
- Config-Hasura
- Config-Auth
- Config-Nginx
- Config-Optional-Services
- Config-Custom-Services
- Config-System
Plugins (87 + 10 monitoring)
Free (25)
- plugin-backup
- plugin-content-acquisition
- plugin-content-progress
- plugin-cron
- plugin-donorbox
- plugin-feature-flags
- plugin-github
- plugin-github-runner
- plugin-invitations
- plugin-jobs
- plugin-link-preview
- plugin-mdns
- plugin-mlflow
- plugin-monitoring
- plugin-notifications
- plugin-notify
- plugin-paypal
- plugin-search
- plugin-shopify
- plugin-stripe
- plugin-subtitle-manager
- plugin-tokens
- plugin-torrent-manager
- plugin-vpn
- plugin-webhooks
Pro (62)
- plugin-access-controls
- plugin-activity-feed
- plugin-admin-api
- plugin-nself-ai-gateway
- plugin-nself-ai-mcp
- plugin-nself-ai-mcp
- plugin-analytics
- plugin-auth
- plugin-backup-pro
- plugin-bots
- plugin-browser
- plugin-calendar
- plugin-cdn
- plugin-chat
- plugin-claw
- plugin-claw-budget
- plugin-claw-news
- plugin-claw-web
- plugin-cloudflare
- plugin-cms
- plugin-compliance
- plugin-cron-pro
- plugin-ddns
- plugin-devices
- plugin-documents
- plugin-donorbox-pro
- plugin-entitlements
- plugin-epg
- plugin-file-processing
- plugin-game-metadata
- plugin-geocoding
- plugin-geolocation
- plugin-google
- plugin-home
- plugin-idme
- plugin-knowledge-base
- plugin-linkedin
- plugin-livekit
- plugin-media-processing
- plugin-meetings
- plugin-moderation
- plugin-mux
- plugin-notify-pro
- plugin-object-storage
- plugin-observability
- plugin-paypal-pro
- plugin-photos
- plugin-podcast
- plugin-post
- plugin-realtime
- plugin-recording
- plugin-retro-gaming
- plugin-rom-discovery
- plugin-shopify-pro
- plugin-social
- plugin-sports
- plugin-stream-gateway
- plugin-streaming
- plugin-stripe-pro
- plugin-support
- plugin-tmdb
- plugin-voice
- plugin-web3
- plugin-workflows
Planned (26)
plugin-auditplugin-blogplugin-checkoutplugin-commerceplugin-drmplugin-exportplugin-flowplugin-importplugin-ldapplugin-mailgunplugin-mediaplugin-oauth-providersplugin-pagesplugin-postmarkplugin-rate-limitplugin-reportsplugin-samlplugin-schedulerplugin-sendgridplugin-ssoplugin-subscriptionplugin-thumbplugin-transcoderplugin-twilioplugin-wafplugin-watermark
Guides
- Guide-Production-Deployment
- Guide-SSL-Setup
- Guide-Multi-Tenancy
- Guide-Security-Hardening
- Guide-Monitoring-Setup
- Guide-Backup-Restore
- Guide-Custom-Services
- Guide-Migration-from-v1
Architecture
Reference
- API-Reference
- error-codes, Error Codes
Licensing
Security
Brand
Operations
- operations/release-cascade, Release Cascade
- operations/self-healing, Self-Healing Schema
- operations/redis-tuning, Redis Pool Tuning
- operations/meilisearch-warmup, MeiliSearch Warm-Up
- operations/jwt-rotation, JWT Key Rotation
- operations/windows-wsl2-setup, Windows / WSL2 Setup
- operations/gemini-oauth-reauth, Gemini OAuth Reauth
Contributing
Admin
- USER-ACTION-QUEUE, Pending Admin Actions
All commands (52)
- A: cmd-access · cmd-account · cmd-admin
- B: cmd-backup · cmd-build · cmd-bundle
- C: cmd-ci · cmd-clean · cmd-completion · cmd-config
- D: cmd-db · cmd-deploy · cmd-dev · cmd-doctor
- E: cmd-env · cmd-exec
- F: cmd-functions
- G: cmd-generate
- H: cmd-health · cmd-help-topics
- I: cmd-init · cmd-install
- L: cmd-license · cmd-login · cmd-logout · cmd-logs
- M: cmd-man · cmd-mcp · cmd-migrate
- O: cmd-oauth · cmd-ops
- P: cmd-plugin · cmd-promote
- R: cmd-remove · cmd-reset · cmd-restart · cmd-runner
- S: cmd-secrets · cmd-security · cmd-self-heal · cmd-server · cmd-service · cmd-start · cmd-status · cmd-stop
- T: cmd-telemetry · cmd-template · cmd-trust
- U: cmd-update · cmd-urls
- V: cmd-verify-sbom · cmd-version