[T3 Connect] TypeScript SDK: let short-lived auth tokens survive reconnects - #6011
Draft
bradleyshep wants to merge 1 commit into
Draft
bradleyshep wants to merge 1 commit into
bradleyshep wants to merge 1 commit into
Conversation
bradleyshep
force-pushed
the
bradley/ts-sdk-token-provider
branch
from
September 30, 2026 17:38
3470ea4 to
bc7709b
Compare
`withToken` only took a string, and the ConnectionManager re-applies the session's token on every automatic rebuild. For third-party OIDC tokens such as Clerk session JWTs (about a minute of lifetime) that token is the original JWT, so once it expired every reconnect failed with 401 and retried forever. React apps also had no way to switch identity while mounted: `retain()` ignores a new builder once a connection is live. `withToken` now also accepts a `TokenProvider`, a sync or async function that is called on every connection attempt: the initial build, automatic reconnects, resume and zombie revival, and `rebuild()`. Its value is that attempt's token (`undefined` connects anonymously) and `conn.token` reflects it. A throw or rejection reaches `onConnectError`, so the manager retries it with backoff. The manager no longer resumes the session token over a builder with a provider; string tokens resume as before. `TokenProvider` is exported from the package root. The React context gains `reconnect(builder)`, calling `ConnectionManager.rebuild()` like the Svelte provider does. The Clerk guide now passes a provider instead of a token fetched once.
bradleyshep
force-pushed
the
bradley/ts-sdk-token-provider
branch
from
October 1, 2026 17:26
bc7709b to
8ce8ec2
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of Changes
withTokenonly took a string, andConnectionManagerre-applies the session's token on every automatic rebuild. For third-party OIDC tokens such as Clerk session JWTs (about a minute of lifetime), that token is the original JWT. Once it expired, every reconnect failed with 401 and retried forever. React apps also had no way to switch identity while mounted, becauseretain()ignores a new builder once a connection is live.withTokennow also accepts aTokenProvider: a sync or async function called before every connection attempt, including automatic reconnects.useSpacetimeDB()gainsreconnect(builder), which tears down the current connection and rebuilds from a fresh builder, for example after sign-in or sign-out.Where this matters: a client that opens a fresh connection for each short task can fetch a token first and pass a string, so it doesn't need this. It matters for long-lived connections that the SDK reconnects on its own, such as the React provider behind a live dashboard, where the token has usually expired by the time the SDK reconnects. A callback affects the next connection attempt; switching identity on an open connection still needs
reconnect(builder).Split out of #6005 / #6006.
API and ABI breaking changes
None.
withTokenaccepts a function in addition to a string, andreconnectis new.Rollback safety impact
n/a
Expected complexity level and risk
ConnectionManager's rebuild path; the string-token path is unchanged.Worth a reviewer's eye:
undefinedconnects anonymously on every attempt, so a signed-out app gets a new anonymous identity on each reconnect. With a string token or none, the manager still resumes the session's token as before.reconnectis a required member of the ReactConnectionStatetype, matching Svelte's. Code that builds aConnectionStateby hand, such as a test mock, needs to add it.Testing
pnpm testincrates/bindings-typescript(327 passing), including new reconnect and token-provider testsConnectionManagerchange against other auth providers