Skip to main content

Where you see it

  • Inside the hosted flow, when it starts a link session with an expired client secret.
  • Your app’s result: only after the hosted flow asked your app for a new secret three times and got an expired one every time.
  • In a browser: your user sees “This page was open too long” and starts again from your website.

What it means

A client session opens link sessions for 60 minutes. In the SDK, the hosted flow handles an expired secret by asking your app for a new one: the SDK calls your fetchClientSecret again with the same action.

What to do

  • Create a fresh client session every time fetchClientSecret is called. Don’t cache client secrets in your app.
  • For a browser, create the client session right before you send your user to its web_url.

Example