Skip to content
Proposals/Re-sign out of Cline and Cline Pass so classic e
proposaldeveloperP5Worth a lookCline

Re-sign out of Cline and Cline Pass so classic extension credentials stop re-importing

Cline desktop-v0.0.27 makes sign-out stick, surfaces one Sign in to Cline action on expired tokens, and reports a rejected refresh as signed out. Re-clear Cline/Cline Pass and use Settings → API Providers so stale browser-session status and dead Retry loops do not persist.

Why this loop

Before desktop-v0.0.27, signing out of Cline removed the provider entry but the runtime re-imported missing providers from the classic extension’s stored credentials on every command, so you appeared signed back in. Cline Pass sign-out did nothing because its credentials live under the Cline provider entry rather than its own. A rejected refresh fell back to a persisted access token that was dead too, so the account request 401’d and Account Retry failed the same way. Settings treated a stale token as Signed in via browser, and a pre-runtime failure stacked a detail-less run.failed bubble on the real error banner. After upgrade, sign-out of Cline and Cline Pass sticks, a rejected refresh reports as signed out (transient refresh failures still fall back), the Account page offers a sign-in prompt, credential failures carry Sign in to Cline / Open model settings / CLI, and the failure renders once in place. Manage credentials under Settings → API Providers, not Models.

Proposed actions

  1. Upgrade Cline Desktop to v0.0.27, open Settings → API Providers (renamed from Models), sign out of both Cline and Cline Pass, then run any command and confirm neither provider reappears from classic extension credentials.
  2. If the Account page shows a rejected Cline refresh token, use the sign-in prompt — do not click Retry. Treat the session as signed out; only transient refresh failures should still fall back to the persisted access token.
  3. When a turn fails before the runtime takes the prompt, keep the single in-place error. Click Sign in to Cline for the Cline provider (ignore Signed in via browser), Open model settings for other hosted providers, or follow the local-CLI pointer.
  4. Retry OpenCode Go models that failed with missing x-opencode-session or internal server errors: send x-opencode-session, preserve per-model adapters so Muse Spark/GPT/Grok use /responses and MiniMax/Qwen use /messages, and reuse the same session identity on retries.
  5. On microphone failure, stay in the current chat, read the Speech input failed toast for the actual error, and retry from the microphone button; do not open Settings → Voice unless it is a permission issue.

Agent prompt

Paste into your agent or query via MCP (get_agent_prompt) — free, no extra AI cost

Cline / .clinerules task

DevAgentRadar → Cline

You are helping me adopt a real coding-assistant change. Work only from the facts below. Do not invent features.

Context

Assistant: Cline Proposal: Re-sign out of Cline and Cline Pass so classic extension credentials stop re-importing Summary: Cline desktop-v0.0.27 makes sign-out stick, surfaces one Sign in to Cline action on expired tokens, and reports a rejected refresh as signed out. Re-clear Cline/Cline Pass and use Settings → API Providers so stale browser-session status and dead Retry loops do not persist. Primary source: https://github.com/cline/cline/releases/tag/desktop-v0.0.27

Why it matters

Before desktop-v0.0.27, signing out of Cline removed the provider entry but the runtime re-imported missing providers from the classic extension’s stored credentials on every command, so you appeared signed back in. Cline Pass sign-out did nothing because its credentials live under the Cline provider entry rather than its own. A rejected refresh fell back to a persisted access token that was dead too, so the account request 401’d and Account Retry failed the same way. Settings treated a stale token as Signed in via browser, and a pre-runtime failure stacked a detail-less run.failed bubble on the real error banner. After upgrade, sign-out of Cline and Cline Pass sticks, a rejected refresh reports as signed out (transient refresh failures still fall back), the Account page offers a sign-in prompt, credential failures carry Sign in to Cline / Open model settings / CLI, and the failure renders once in place. Manage credentials under Settings → API Providers, not Models.

Suggested actions

  1. Upgrade Cline Desktop to v0.0.27, open Settings → API Providers (renamed from Models), sign out of both Cline and Cline Pass, then run any command and confirm neither provider reappears from classic extension credentials.
  2. If the Account page shows a rejected Cline refresh token, use the sign-in prompt — do not click Retry. Treat the session as signed out; only transient refresh failures should still fall back to the persisted access token.
  3. When a turn fails before the runtime takes the prompt, keep the single in-place error. Click Sign in to Cline for the Cline provider (ignore Signed in via browser), Open model settings for other hosted providers, or follow the local-CLI pointer.
  4. Retry OpenCode Go models that failed with missing x-opencode-session or internal server errors: send x-opencode-session, preserve per-model adapters so Muse Spark/GPT/Grok use /responses and MiniMax/Qwen use /messages, and reuse the same session identity on retries.
  5. On microphone failure, stay in the current chat, read the Speech input failed toast for the actual error, and retry from the microphone button; do not open Settings → Voice unless it is a permission issue.

After you finish

Do not report this as applied to DevAgentRadar. You cannot write the visitor's loop.

Tell the human: open https://devagentradar.com/proposals/cline-desktop-v0-0-27-re-sign-out-of-cline-and-cline-pass-so-classic-ext and mark Applied, Skipped, or Failed. Proposal id: ae13440f-082c-442c-af11-0441d6b0edea

Your job

  1. Restate the change in one sentence.
  2. Propose a minimal plan for my repo (or a throwaway pilot).
  3. Implement only what I approve; prefer small diffs and tests.
  4. Call out risks (permissions, breaking APIs, cost).

Start by confirming you understood the proposal.

modelsecurityideclibreakingRelease source ↗

Your loop

This browser · no sign-in · not shared as “you”

After you run the prompt

Only you can mark this. Agents cannot write your loop.

Your decision stays on this device. A public tally appears after a few votes.

Originating release signal

ClineDesktop 0.0.27Sep 13, 2026

desktop-v0.0.27 Desktop v0.0.27

An expired Cline sign-in now produces one actionable error instead of two dead ends. · A turn that fails before the runtime takes the prompt was reported twice — the hub's detail-less run.failed appended a bubble, then the send RPC resolved with the real error and overwrote the error banner underneath it — so you got a vague bubble stacked on a detailed banner. · The failure now renders exactly once, upgrading in place when the detailed report arrives. · +18 more changes
Verified excerpt — the source's own words
  • An expired Cline sign-in now produces one actionable error instead of two dead ends. A turn that fails before the runtime takes the prompt was reported twice — the hub's detail-less run.failed appended a bubble, then the send RPC resolved with the real error and overwrote the error banner underneath it — so you got a vague bubble stacked on a detailed banner. The failure now renders exactly once, upgrading in place when the detailed report arrives. Credential failures also carry a fix button: Sign in to Cline for the Cline provider (Settings → API Providers reads a stale token as "Signed in via browser", so there is nothing to fix there), Open model settings for others, and local-CLI providers keep pointing at their CLI. Sessions that fail to start over credentials get the same hint and action
  • The Account page now offers a sign-in prompt when your Cline refresh token is rejected, instead of an error card whose Retry failed the same way. A rejected refresh was falling back to the persisted access token, which is dead too, so the account request 401'd; a rejected refresh now reports as signed out. Transient refresh failures still fall back

Excerpt ends here — this release continues at the source ↗.

Primary source ↗