Skip to content

createTokenRecovery

createTokenRecovery(onTokenRejected): StreamErrorHandler

Defined in: packages/client/src/circuits/stream-source.ts:81

The token-recovery policy the reader applies to every request: one re-mint per rejection.

On a 401/403 the handler asks onTokenRejected for a fresh token and answers with it; if the fresh token is refused too, it answers undefined and the error stands. The second consecutive rejection is the answer — the token was refreshed and still refused, so this is a revocation, not an expiry — and retrying past it would turn a revoked entitlement into a hot loop of refused requests. A revocation must instead surface as an error the caller can act on: truncate the scope and unsubscribe (ADR-0055 decision 6).

Stateful and single-shot: one handler re-mints once. The reader makes a new one for each request, so a read that lives for hours can re-mint many times, but no request is retried on a second rejection. Errors that are not 401/403 are not the handler’s to recover and answer undefined.

(status) => string | Promise<string | null> | null

StreamErrorHandler