ReadonlyerrorThe context label prefixed to sanitized grant failures (for example "AniList token request").
ReadonlyproviderThe provider identity for diagnostics, bound together by TokenRefreshProvider.
ReadonlystripHeaders removed from auth material when the replay rewrites it: MAL drops X-MAL-CLIENT-ID, AniList drops nothing.
ReadonlytokenThe OAuth token endpoint grants POST to (for example https://anilist.co/api/v2/oauth/token).
The provider-specific facts behind every token grant and the post-refresh replay: the token endpoint the grant posts to, the label grant failures are sanitized under, the headers the replay drops, and the diagnostics identity the coordinator reports under. Each provider declares one descriptor; the shared transport, the auth rewrite, and the refresh coordinator read their behaviour from it, so a provider shell carries data instead of logic.
See
TokenRefreshProvider