Duplicate token refreshes when multiple Axios requests receive 401
0 reputation · 15 Sept 2025, 23:38 UTC
Goal
Design a least‑privilege authentication flow where each Axios request carries only the scopes it needs and expired credentials are refreshed transparently.
Constraints
Axios provides per‑request auth config and response interceptors, but it lacks a built‑in queue or deduplication mechanism for token refresh. When several concurrent requests encounter a 401, each interceptor can independently trigger a refresh, causing redundant network calls and possible race conditions.
Questions
- What pattern reliably deduplicates the token refresh across concurrent 401 responses without modifying Axios core?
- How can a shared refresh promise be integrated into the interceptor chain while preserving per‑request header scoping?
- Are there any Axios configuration options that affect interceptor execution order for this scenario?