Constructs a refresh coordinator from the wiring's fields.
The provider descriptor, the client credentials, the stored refresh token, the diagnostics names, the auth-swap callback, the optional persistence and failure callbacks, and the diagnostics mode.
Runs one operation attempt under the automatic refresh lifecycle.
A 401 from the first attempt, or an AniLinkAuthError raised
before any request because no access token is configured, which lets
a persisted refresh token bootstrap the client, triggers exactly one
refresh (concurrent failures share the in-flight refresh) followed by
a single replay with the new auth material. Any other failure, a
non-401 first attempt, a failed refresh, or a replay that fails again,
surfaces unchanged. A failed refresh grant is reported to
onHookError (under the coordinator's hookName) before the
sanitized error rethrows, so the grant failure is observable through
the same channel as every other lifecycle failure. The
onTokenRefreshError callback (when configured) fires once per failed
grant with the same sanitized error.
The first successful attempt's result.
Coordinates the automatic token-refresh lifecycle for one client.
The wiring seam constructs one coordinator per provider facade when refresh credentials are present and wraps every facade method with TokenRefresher.executeWithRefresh. The coordinator owns the mutable refresh state (the current refresh token, honoring the provider's rotation semantics) and deduplicates concurrent 401s into a single refresh call.
See
TokenGrantDescriptor