Gateway origin, e.g. https://127.0.0.1:8443. All OIDC endpoints are relative to this —
the SDK never talks to Keycloak directly.
Public OIDC client id.
OptionalfetchInjectable for tests; defaults to global fetch.
Optionalinit: RequestInitOptionalinit: RequestInitOptionalnavigateNavigation hook for login()/logout(); defaults to window.location.assign. Injectable
so tests never actually navigate.
OptionalnowClock injection for tests.
OptionalpersistAlso persist the current TokenSet to storage (survives a page refresh) in addition to
keeping it in memory. Still never localStorage — storage here is the same
sessionStorage-or-injected adapter used for the PKCE transaction. Defaults to false
(memory-only, the safer default). A persisted entry is only hydrated back if it still has
the right shape and is still usable: not expired (a small clock-skew allowance applies), or
expired but carrying a refresh token (the next 401 refreshes it); anything else is dropped
rather than trusted.
OptionalpostWhere the browser lands after RP-initiated logout. Defaults to the app ORIGIN ROOT (derived
from redirectUri's origin, e.g. https://app.test/) — never redirectUri itself, which
is the login callback route and cannot handle a logout redirect (no code/state params).
Keycloak realm name.
Where the browser lands after a successful login. Must be registered as a redirect URI on the client; same-origin/return-path sanitization is the host app's concern, not the SDK's.
OptionalscopeDefaults to "openid".
OptionalstorageInjectable transaction/token storage; defaults to sessionStorage (or an in-memory
fallback when unavailable). Never defaults to localStorage.
Construction options for createSession.