auth-service.tsmiddleware.ts
401 — even when the user still held a valid refresh token. This document describes the silent-refresh flow we just shipped and how we're rolling it out.validateToken() throws TokenExpiredError401 — refreshToken() is never reachedTokenExpiredError specifically and attempts a silent refresh before rejecting. On success it reissues an access token and continues the request; on failure it falls back to 401.401| Scenario | Expected |
|---|---|
| Valid token passes through | 200 |
| Expired token, valid refresh | 200 + new access token |
| Expired token, invalid refresh | 401 |
| Malformed token | 401 |
silent_refresh flag at 5% of trafficauth.refresh.success and auth.refresh.failure counters