OAuth in the SDK
First install the SDK and obtain application tokens. Client Secret and refresh token must stay on the server.
Automatic OAuth token refresh
Automatic refresh is intended for a server-side OAuth integration. Provide all three values, refreshToken, clientId, and clientSecret, and persist the new tokens in onTokenRefreshed:
const client = new AiSenlerClient({
accessToken: "access_token",
refreshToken: "refresh_token",
clientId: "client_id",
clientSecret: process.env.SENLER_CLIENT_SECRET!,
onTokenRefreshed: async (newAccessToken, newRefreshToken) => {
await saveTokensAtomically(newAccessToken, newRefreshToken);
},
});
After a 401 response, the SDK calls POST /api/apps/oauth/token once, updates the tokens, waits for onTokenRefreshed, and retries the original request. It does not refresh a token proactively based on its expiration time. A partial refresh configuration is rejected by the TypeScript types.
The token endpoint rotates the refresh token after a successful refresh, so persist the access token and refresh token together. Client Secret and the refresh token must remain on the server.
Replace the Token Manually
If the token is refreshed outside the SDK, replace it before the next request:
client.accessToken = newAccessToken;
Failed request causes are described in SDK errors.