Skip to main content
Manages the lifecycle of the authenticated session: persists the session across reloads and refreshes it before it expires. The session is the wallet-authorized ed25519 keypair returned by login(); there are no separate access or refresh tokens. Most apps don’t use this hook directly; MonacoProvider wires it up and useAuth drives it. See React SDK setup.

Parameters

MonacoSDK | null
required
Monaco SDK instance from useMonacoSDK()
TokenLifecycleConfig
Session lifecycle options:
  • autoRefresh: boolean (default: true) - automatically extend the session before it expires
  • persistTokens: boolean (default: true) - persist the session in localStorage so it survives reloads
  • refreshBufferSeconds: number (default: 300) - how long before expiry to trigger a refresh
  • onRefreshError: (error: Error) => void - called when a refresh fails
  • onRefreshSuccess: (authState: AuthState) => void - called when a refresh succeeds

Return Values

(authState: AuthState) => void
Start managing a session. Call after a successful login(); persists the session (if enabled) and schedules auto-refresh.
() => void
Stop managing the session, cancel scheduled refreshes, and remove the persisted session. Call on logout.
() => Promise<AuthState | null>
Extend the session’s expiry now (via sdk.refreshAuth()). Returns the updated AuthState, or null if there is no active session or the refresh fails.
(authState: AuthState | null) => boolean
Whether the session is expired or within the refresh buffer of expiry.

Example

How It Works

  1. Auto Refresh: when enabled, schedules a session refresh refreshBufferSeconds before expiry.
  2. Persistence: saves the session to localStorage so it can be restored after a reload.
  3. Deduplication: collapses concurrent refresh calls into a single request.
  4. Cleanup: clears scheduled timers on unmount.
When persistTokens is enabled, the persisted session includes the ed25519 session private key. This credential signs every request. localStorage is readable by any script on your origin, so harden against XSS (e.g. a strict Content Security Policy) and always clearTokens() on logout. Disable persistTokens to keep the session in memory only.
This is an advanced hook. For most apps, MonacoProvider + useAuth manage the session automatically.