PortalCredentials

Supplies the credential io.portalhq.android.Portal authenticates its API calls with.

This is the entire contract between Portal and whatever owns the credential: there is no refresh, no polling, and no observers. StaticCredentials implements it for a custodian-issued Client API Key, and so can a host app that manages credentials itself.

Both members are synchronous, and deliberately so. A credential is expected to already be resolved by the time a Portal is built — an authenticated session materializes its token when it is restored or created, not per request. Keeping the contract synchronous is what lets the SDK read a credential from Android lifecycle callbacks, init blocks and the WebSocket upgrade path without either blocking a UI thread or colouring half the public API suspend.

Two constraints follow from that, and implementations must honour both:

  • getToken must not block. It is called on every request, including from the main thread. Read an already-resolved value; never perform I/O or a network call. A host that needs to fetch a token remotely should fetch it up front and hold it.

  • invalidate must be idempotent and must not perform network I/O. Clearing an in-memory field plus a local storage delete is the expected cost.

Inheritors

Functions

Link copied to clipboard
abstract fun getToken(): String

Returns the bearer token to send with the next request.

Link copied to clipboard
abstract fun invalidate()

Called when the backend rejects the credential with a 401, so a dead token is neither handed out again nor restored on the next launch.