chart/scripts
Chris Amow bffd7faead Validate Schwab credentials before sending anyone to a browser
The first attempt failed with invalid_client and no way to tell why: the key,
the secret, the callback, or an app not yet propagated all look identical from
the browser, which shows raw JSON. It turned out to be a key clipped by one
character on paste.

Two preflight checks now say which. The authorize endpoint is asked whether it
recognises the key. The token endpoint is asked to exchange a deliberately
invalid code, which separates bad credentials from a bad grant — it
authenticates the key and secret over HTTP Basic before it looks at the code, so
invalid_client means the pair is wrong and invalid_grant means the pair is fine.

That second check matters more than it sounds. The secret is not used at all
during login, so a truncated one survives the whole browser round trip and only
surfaces at the exchange, by which point the authorisation code has been spent
and the flow has to start over.

Neither check can tell a wrong value from an app that is not live yet — an
invented key produces the identical response, verified — and both say so rather
than guessing.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-10 05:02:04 -05:00
..
calibrate_alerts.py Add prior-day levels and session VWAP; fix alert repetition they exposed 2026-08-10 00:36:21 -05:00
check_schwab.py Validate Schwab credentials before sending anyone to a browser 2026-08-10 05:02:04 -05:00