Builds the login redirect URL and records the PKCE transaction, without navigating — useful for tests and for hosts that want to control navigation themselves.
Current access token, or null when signed out. Synchronous — never triggers a refresh;
pair with an ApiClient's refreshAccessToken hook (this session's refresh) for
401-triggered refresh.
Current TokenSet (all three tokens + expiry), or null when signed out. Synchronous, like
getAccessToken().
Handles the OIDC callback URL (must contain code and state). Idempotent: a second
invocation with the same code (React StrictMode double-effect) returns the same result
instead of re-exchanging an already-consumed authorization code.
True when there is a current TokenSet that is still usable: its access token has not passed
expiry (with a small clock-skew allowance), OR it carries a refresh token (an expired access
token is refreshed by the next 401 — only an IdP-rejected refresh or logout() ends the
session). Presence alone is not enough: an expired set without a refresh token is not
authenticated. Synchronous, like getAccessToken(); never triggers a refresh.
Redirects the browser to Keycloak's authorization endpoint (PKCE S256).
Clears session state (tokens; the host app's own SessionContext, if any, is its own
responsibility to clear) and redirects to Keycloak's RP-initiated logout endpoint. A
refresh() still in flight at that moment is abandoned: its result is never stored.
Refreshes the access token using the stored refresh token. Single-flight: concurrent
callers share one in-flight network call. Resolves to the new access token, or null if
refresh is impossible or fails. Only an IdP-rejected refresh (invalid/expired/revoked
refresh token) clears the session; a network-failure rejection resolves to null but leaves
the existing session state (including the refresh token) intact for a later retry. A
successful refresh response that omits refresh_token keeps the previous one instead of
discarding it.
OIDC/PKCE session handle returned by createSession.