Web SDK v0.8.0
Configure AptevaClient with auth: { clientId } and projectId to use Auth app login, signup, app requests and logout through one client. Requires Auth v0.12.0 with explicit role bindings and short-lived platform policies.
The SDK manages both Auth and platform credentials, renews platform tokens before requests near expiry, coordinates concurrent refresh rotation, and reconnects managed fetch streams at expiry. Logout clears credentials and streams; late renewal cannot restore the session. Protected requests never fall back to administrator cookies or API keys, and writes are never automatically replayed after a 401.
Existing platform-admin and opaque-token integrations retain their behavior when auth is omitted. New sessions are memory-only: reloads and separate tabs require login. Session callbacks expose metadata without credentials.
Validation: typecheck, 151 tests, build, npm package dry run, and the packed package tested against real Auth login, renewal, app calls, role downgrade and logout.