gog-auth-tokens-export

gog-auth-tokens-export is a command for coding agents from openclaw/gogcli. It costs 0 tokens per session (895 once invoked), scanned A, original, MIT.

A command that writes a stored Google refresh token to a file. A refresh token is a secret that can obtain new access tokens after short-lived access tokens expire.

In plain words
What is it for?
Use it to export the token for an account to a specified file.
Why use it?
It lets you move or back up a saved login, but the exported file must be protected because it contains a secret.

Command

About the project

gog is a command-line client for Google Workspace services such as Gmail, Calendar, Drive, Docs, and Sheets. It is used by people, scripts, continuous-integration jobs, and coding agents that need account selection, structured output, and permission controls from a terminal.

openclaw/gogcli · 8,365 stars · on GitHub

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/openclaw/gogcli/gog-auth-tokens-export
Clone the repo
git clone --depth 1 https://github.com/openclaw/gogcli

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for gog-auth-tokens-export

README.md
[![agentmods](https://agentmods.dev/badge/commands/openclaw/gogcli/gog-auth-tokens-export.svg)](https://agentmods.dev/commands/openclaw/gogcli/gog-auth-tokens-export)
Your own site
<a href="https://agentmods.dev/commands/openclaw/gogcli/gog-auth-tokens-export"><img src="https://agentmods.dev/badge/commands/openclaw/gogcli/gog-auth-tokens-export.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 895 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00895
Opus 5 $0.00000 $0.00447
Sonnet 5 $0.00000 $0.00179
Haiku 4.5 $0.00000 $0.00089

Measured today against content hash 11740745e7ca, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

gog-auth-tokens-export scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/commands/gog-auth-tokens-export.md · 50 lines

How it starts

The opening of the file, as written. The whole thing — 50 lines — stays where its author put it; the contents beside it link to each section on GitHub.

gog auth tokens export

Generated from gog schema --json. Do not edit this page by hand; run make docs-commands.

Export a refresh token to a file (contains secrets)

Usage

gog auth tokens export <email> [flags]

Parent

Flags

Flag Type Default Help
--access-token string Use provided access token directly (bypasses stored refresh tokens; token expires in ~1h)
-a--account--acct string Account email, alias, or auto for authenticated Google API commands
--client string OAuth client name (selects stored credentials + token bucket)
--color string auto Color output: auto|always|never
--disable-commands string Comma-separated list of disabled commands; dot paths allowed
-n--dry-run--dryrun--noop--preview bool Do not make changes; print intended actions and exit successfully
--enable-commands string Comma-separated list of enabled command prefixes; dot paths allowed (restricts CLI)
--enable-commands-exact string Comma-separated list of exact enabled commands; dot paths allowed and parent commands do not enable children
-y--force--assume-yes--yes bool Skip confirmations for destructive commands
--gmail-no-send bool false Block Gmail send operations (agent safety)
-h--help kong.helpFlag Show context-sensitive help.
--home string Override gogcli config/data/state/cache root (equivalent to GOG_HOME)
-j--json--machine bool false Output JSON to stdout (best for scripting)
--no-input--non-interactive--noninteractive bool Never prompt; fail instead (useful for CI)
--out--output string Output file path (required)
--overwrite bool Overwrite output file if it exists
-p--plain--tsv bool false Output stable, parseable text to stdout (TSV; no colors)
--quota-project string Google Cloud project to bill for API usage (sent as X-Goog-User-Project; some APIs require it with --access-token or ADC)
--readonly bool false Block mutating API requests at runtime; auth add also requests read-only OAuth scopes
--results-only bool In JSON mode, emit only the primary result (drops envelope fields like nextPageToken)
--select--pick--project string In JSON mode, select comma-separated fields (best-effort; supports dot paths). Desire path: use --fields for most commands.
-v--verbose bool Enable verbose logging
--version kong.VersionFlag Print version and exit
--wrap-untrusted bool false In JSON/raw output, wrap fetched text fields in external untrusted-content markers

Read the full file on GitHub · 50 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. today Changed · +1 lines 11740745e7ca
  2. 2d ago First seen · 49 lines · 0 tokens per session scan A aebc088fe4d9

Subscribe to this mod's changes

gog-auth-tokens-export is a command published in the GitHub repository openclaw/gogcli (8,365 stars, last pushed today), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 895 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.