Question
React Native Secure Token Storage: Proactive vs Reactive Refresh Decision
Ash Sage
0 reputation · 23 May 2022, 07:38 UTC
24.5K views0
Goal
Implement least‑privilege authentication in a React Native app by storing short‑lived access tokens in memory and refresh tokens in the iOS Keychain or Android Keystore, avoiding AsyncStorage.
Constraint
The missing decision is whether token refresh should be proactive—invoked before the access token expires using the expires_in value—or reactive—triggered only upon receiving a 401 from the API.
Unresolved Questions
- What trade‑offs between battery, network usage, and race conditions favor proactive refresh in a typical React Native workflow?
- How should the client coordinate concurrent requests so that only one refresh exchange occurs when a 401 is received?
- In the event the refresh token itself is revoked or expired, what is the safest user‑experience path for clearing stored credentials and prompting re‑authentication?