Swaps the fresh access token onto the operation instances. Called between the refresh and the replay so the replayed request carries the new auth material. The callback must write through the wiring's live auth cell (not a construction-time snapshot) so both already- constructed operations and instances built later see the refreshed token.
The application client ID sent on the refresh grant.
OptionalclientThe application secret sent on the refresh grant, when the provider's grant accepts one.
The provider descriptor behind the grant, the diagnostics identity, and the replay's strip rule: token endpoint, sanitize label, header rule, and hook identity.
OptionaldiagnosticsHow a throwing onTokenRefresh callback with no observer is reported; defaults to "warn".
OptionalonOptional observer for onTokenRefresh failures, mirroring the transport hooks.
OptionalonOptional callback invoked once after every successful refresh.
OptionalonOptional callback invoked once when a refresh grant fails.
The stored refresh token exchanged for new access tokens.
Builds the coordinator's dependencies: the shared option shape plus the provider descriptor the coordinator's grant, diagnostics, and replay rewrite read.
See
TokenRefresher