invalidateCredentials

Invalidates credentials in response to a 401.

Serializes on the credential's own monitor, so several subsystems reacting to the same rejection cannot run PortalCredentials.invalidate concurrently. Combined with the idempotence the interface requires, the second caller finds an already-cleared credential and returns without issuing a second storage delete — the same observable outcome as the React Native SDK's WeakMap of in-flight invalidations.

Announces nothing to the host: this is the plain operation behind a host-initiated sign-out, and a sign-out is not news to whoever asked for it. A backend rejection goes through reportUnauthorized instead.