Skip to content
IC Reactor

AuthState

Defined in: core/src/client.ts:117

Who a client calls as, and why. Client.authState returns it.

principal is always the principal calls go out as, the same text Client.caller returns: the signed-in user’s when status is "signed-in", and the anonymous principal (2vxsx-fae) in every other state. An expired session, or one signed in on a sibling origin that this origin holds no credential for, cannot sign a call, so it does not name its principal here either: a check such as principal !== anonymous means what it looks like it means. To say whose session ended, read the auth’s own getStatus(), which keeps the principal in those states.

A client built with an identity reports "signed-in" with that identity’s principal, or "anonymous" for identity: "anonymous" and for an explicit AnonymousIdentity. A client on a server reports "anonymous".

readonly status: "signed-in" | "signed-in-elsewhere" | "expired" | "anonymous"

Defined in: core/src/client.ts:126

  • anonymous: nobody is signed in (the auth says signed-out), the client runs on a server, or it was built anonymous.
  • signed-in: calls are signed by principal.
  • expired: the session ended; calls are anonymous until a sign-in.
  • signed-in-elsewhere: someone is signed in on this domain but this origin holds no credential for them yet; calls are anonymous.

readonly principal: string

Defined in: core/src/client.ts:128

The principal calls go out as, as text.