@mrzr/api-client
The fetch client that handles your auth tokens
You make requests. It attaches the token, refreshes it when it expires, keeps it away from page scripts and keeps your tabs logged in together. TypeScript, zero dependencies.
import { createClient } from "@mrzr/api-client";export const api = createClient({ baseUrl: "https://api.example.com" });await api.login({ email, password }); // tokens stored for youconst { data } = await api.get<User[]>("/users"); // token attached, refreshed when neededSee it work
This runs the real package in your browser against a small demo API.
One refresh for many requests
Expire the token, then send 8 requests at the same time. Open DevTools → Network to watch it happen.
- 1.The access token is replaced with an expired one.
- 2.8 requests go out at once. The server answers each with 401.
- 3.The client pauses them and sends a single refresh request.
- 4.All 8 requests are retried with the new token and succeed.
Refresh requests sent: –
What it handles
Token refresh
An expired token triggers one refresh, however many requests failed. They all retry by themselves.
Tokens out of reach
Requests run in a Web Worker, so scripts on the page, including injected ones, can’t read the token.
Tabs in sync
Log out in one tab and every tab logs out. Tabs take turns refreshing, so a token is never spent twice.
Cancellation
Cancel what a page or modal started when the user leaves, or drop stale search requests.