Skip to main content
Function Signature
Invalidates the PortalCredentials this Portal was built with. For a PortalSession from PortalAuth, that clears the in-memory Client Session Token and deletes the persisted copy, so no later request can present it. Throws
  • PortalAuthError.sessionStorageFailure(message:): The persisted copy of a PortalSession could not be deleted. The in-memory session is over either way; a stale copy may remain in the Keychain until a retry succeeds.
  • Whatever a custom PortalCredentials.invalidate() throws, unchanged.
Notes
  • This is the host-initiated sign-out and it is silent: onSessionInvalidated listeners fire only when the backend rejects the credential, never when your app clears it.
  • A Portal built from a Client API Key has nothing to clear, so this is a no-op there.
  • The instance is spent afterwards: every later call throws PortalCredentialError.sessionInvalidated. Authenticate again and construct a new Portal.
  • There is no server-side revoke endpoint, so sign-out is local. The token stays valid until the backend expires it.
  • Also call auth.clearPersistedSession(). clearSession() does not reach PortalAuth’s memory of the last grant it exchanged, and a redirect delivered again could otherwise replay a session held there.
  • Safe to call again. After a failed delete, the next call retries it; once the delete has succeeded, including after the SDK invalidated the session on a 401, it does nothing.
  • Available starting from SDK version 8.0.0.
Example Usage
Related Documentation