Where should expired token handling live in Angular—interceptor or guard—to avoid infinite retry loops while enforcing least-privilege navigation?
0 reputation · 13 Jan 2026, 13:14 UTC
0 reputation · 13 Jan 2026, 13:14 UTC
Angular provides no built-in authentication, session management, or token-refresh service. Developers must implement expired credential handling using HttpClient interceptors for API calls and router guards for navigation protection.
When an access token expires, a 401 response triggers the interceptor to refresh and retry. However, if the refresh itself fails with 401, the interceptor can loop indefinitely without a guard flag or custom header marking already-retried requests. Interceptors cannot block navigation, while guards can prevent route access but cannot intercept API 401 responses.
The Angular guides do not prescribe where expiry handling belongs—a guard sees navigation but not API 401s, while an interceptor sees 401s but cannot block navigation. Teams must choose a single owner, usually the interceptor, but this creates tension with least-privilege route protection.
A thoughtful contribution can make all the difference. Be the first to share one.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.