Gateway origin, e.g. https://127.0.0.1:8443. No trailing slash required.
OptionalcorrelationInjectable correlation id generator; defaults to crypto.randomUUID().
OptionalfetchInjectable for tests; defaults to global fetch.
Optionalinit: RequestInitOptionalinit: RequestInitOptionalgetReturns the current bearer token, or null/undefined when signed out.
OptionalgetReturns the current access token's expiry as epoch milliseconds (a Session's
getTokens()?.expiresAt). When set together with refreshAccessToken, a token that
expires within the next 30 seconds is refreshed before the request is sent, so a request
never reaches a service with a token that dies in flight (a module that forwards the bearer
to another service would otherwise answer 503, which no 401 retry can recover).
OptionalrefreshCalled on a 401 response. Should perform (or await an in-flight) token refresh and return the new access token, or null/undefined if refresh failed. The client retries the request exactly once when this resolves to a token — never more (avoids refresh loops on a persistently-401ing endpoint). Session single-flight refresh coordination lives in auth/session.ts; this hook just needs to return a fresh token.
Construction options for createApiClient.