PortalCredentials this Portal was built with. For a PortalSession from PortalAuth, that clears the in-memory Client Session Token and deletes the persisted copy, so no later request can present it.
Throws
PortalAuthError.sessionStorageFailure(message:): The persisted copy of aPortalSessioncould not be deleted. The in-memory session is over either way; a stale copy may remain in the Keychain until a retry succeeds.- Whatever a custom
PortalCredentials.invalidate()throws, unchanged.
- This is the host-initiated sign-out and it is silent:
onSessionInvalidatedlisteners fire only when the backend rejects the credential, never when your app clears it. - A
Portalbuilt from a Client API Key has nothing to clear, so this is a no-op there. - The instance is spent afterwards: every later call throws
PortalCredentialError.sessionInvalidated. Authenticate again and construct a newPortal. - There is no server-side revoke endpoint, so sign-out is local. The token stays valid until the backend expires it.
- Also call
auth.clearPersistedSession().clearSession()does not reachPortalAuth’s memory of the last grant it exchanged, and a redirect delivered again could otherwise replay a session held there. - Safe to call again. After a failed delete, the next call retries it; once the delete has succeeded, including after the SDK invalidated the session on a
401, it does nothing. - Available starting from SDK version 8.0.0.