resolve Credential Token
The SDK's credential boundary: resolves a token, normalizing every failure to PortalException.Credentials.PortalCredentialError since a host-supplied PortalCredentials can throw anything.
A PortalCredentialError raised by the provider passes through untouched, so a precise reason such as PortalCredentialErrorReason.SESSION_INVALIDATED is never downgraded to PortalCredentialErrorReason.PROVIDER_FAILURE.