Description
Fresh install of deer + deerbox (same install.sh run). Running deerbox first results in a 401 authentication error. Running deer (TUI) first succeeds. After that, deerbox works too.
No macOS Keychain access dialog was shown in either case.
Reproduction
- Fresh install via
curl -fsSL https://raw.githubusercontent.com/zdavison/deer/main/install.sh | bash
- Run
deerbox in a repo - auth fails with 401
- Run
deer in same repo - auth succeeds
- Run
deerbox again - auth succeeds
Environment
- macOS (Darwin 24.5.0, arm64)
- Credentials stored in macOS Keychain under
Claude Code-credentials
- No
~/.claude/agent-oauth-token file, no CLAUDE_CODE_OAUTH_TOKEN env var
Analysis
Both binaries use security find-generic-password -s "Claude Code-credentials" -w to read the Keychain. Possible causes:
- Cold-start race in Bun's subprocess spawning of
security
- Keychain access grant is shared between the two binaries (same codesign/install), but requires one successful access before the other works
Description
Fresh install of deer + deerbox (same
install.shrun). Runningdeerboxfirst results in a 401 authentication error. Runningdeer(TUI) first succeeds. After that,deerboxworks too.No macOS Keychain access dialog was shown in either case.
Reproduction
curl -fsSL https://raw.githubusercontent.com/zdavison/deer/main/install.sh | bashdeerboxin a repo - auth fails with 401deerin same repo - auth succeedsdeerboxagain - auth succeedsEnvironment
Claude Code-credentials~/.claude/agent-oauth-tokenfile, noCLAUDE_CODE_OAUTH_TOKENenv varAnalysis
Both binaries use
security find-generic-password -s "Claude Code-credentials" -wto read the Keychain. Possible causes:security