Where you see it
- Inside the hosted flow, when it starts a link session with an expired client secret.
- Your app’s result: only after the hosted flow asked your app for a new secret three times and got an expired one every time.
- In a browser: your user sees “This page was open too long” and starts again from your website.
What it means
A client session opens link sessions for 60 minutes. In the SDK, the hosted flow handles an expired secret by asking your app for a new one: the SDK calls yourfetchClientSecret again with the same action.
What to do
- Create a fresh client session every time
fetchClientSecretis called. Don’t cache client secrets in your app. - For a browser, create the client session right before you send your user to its
web_url.