Question
Limits of k6’s HTTP module for automatic token refresh and expired credential handling
Ira Finch
0 reputation · 12 Aug 2026, 11:41 UTC
82.4K views0
Goal
Determine whether k6 should extend its HTTP module with built‑in token refresh logic to automatically handle expired bearer tokens or API keys during a load test.
Constraints
The current core runtime leaves authentication entirely to the test script; adding automatic refresh would introduce runtime dependencies, version‑sensitive behavior, and potential conflicts with user‑supplied auth headers or cookies.
Open questions
- What trade‑offs exist between keeping authentication script‑level and providing an optional credential‑lifecycle API?
- How would a built‑in refresh mechanism interact with existing options such as headers, basic auth, or cookies without breaking backward compatibility?
- Should k6 expose a configuration flag or extension point for token renewal, or rely entirely on external scripts and CI pipelines?