listener after the backend rejects this Portal’s credential (an HTTP 401 on a Portal-owned request, or an MPC AUTH_FAILED) and the SDK has invalidated it.
Parameters
listener: Called at most once, on the main actor. This is your cue to clear local state and show the sign-in screen. It is retained until it runs or the credential is deallocated, so captureselfweakly.
PortalSessionInvalidationHandle: Callcancel()to remove the listener.cancel()also suppresses a delivery that is already queued but has not run, and it is safe to call more than once or from inside the listener. The handle is not cancelled on deallocation, so you only need to keep it if you intend to unsubscribe. APortalbuilt from a Client API Key returns the sharedPortalSessionInvalidationHandle.spent, and the listener never runs.
- A late subscriber does not miss the event.
Portal.initstarts an authenticated request immediately. If the backend rejects it before you subscribe, the rejection is replayed: the listener still runs once, on the main actor. - Do not subscribe again on the same
Portalfrom inside the listener. The instance is spent, and a new subscription would be called as well. - Fires at most once per credential, and never for a host-initiated
clearSession(). - The request that triggered the rejection still fails with its own error, and the listener runs in addition. Every later call on the
PortalthrowsPortalCredentialError.sessionInvalidated, whoserequiresReauthenticationistrue. - Only requests that carried the session to a Portal-owned host count: Portal’s own domains, or a host you configured on
Portal,PortalConnectorPortalAuth. A401from a third-party RPC gateway or Google Drive, or a failed or cancelled passkey, does not invalidate the session. - The session is already invalidated when the listener runs, and its stored copy deleted. Do local cleanup, call
auth.clearPersistedSession()so a re-delivered redirect cannot replay it, and do not callclearSession()again. - Available starting from SDK version 8.0.0.