Exceptions
All exceptions live in RoundlyConsulting\RefreshTokens\Exceptions and extend RefreshTokenException. redeem() never throws for an unknown, expired, revoked or replayed token — it returns null:
| Exception | When |
|---|---|
RefreshTokenException | Base class — catch it for the whole family. |
InvalidTokenConfigurationException | Unsafe hash.algo, token_length out of bounds, a malformed or out-of-range integer setting, a non-string table, device_type_cast or hash.key, a per-issue ttl < 1 / absoluteTtl < 0, or prune(0) (unsupportedAlgorithm, tokenLengthTooShort, tokenLengthTooLong, invalidTtl, invalidAbsoluteTtl, invalidPruneWindow, notAString). The message names the key. |
InvalidTokenFamilyException | An invalid familyId / newFamilyId on issue (unknownForOwner, reuseRevoked, ended, malformed, alreadyExists, ambiguous). |
SessionNotFoundException | session() was given a key that doesn’t exist — thrown when you enrich() or revoke() it. |
RevokerAssertionFailedException | A FakeAccessTokenRevoker assertion failed. |
An invalid key_type or a model that is not RefreshToken or a subclass of it throws the toolkit’s RoundlyConsulting\PackageToolkit\Exceptions\InvalidConfigurationException instead, which is not a RefreshTokenException. Its message names the key.
Show your open-source love
This package is free and MIT-licensed. If it saves you time, a one-off donation or a Patreon membership keeps it maintained, tested and documented.
More ways to support, including cryptoBy donating, you agree to our donation terms.
Want this built into your product?
We integrate our packages into custom Laravel and AI builds. Tell us what you're working on and we'll reply within 48 hours.