dotnet/aspnetcore · error · Error

Cannot refresh authentication when the connection is not…

Error message

Cannot refresh authentication when the connection is not active.

What it means

Thrown by HubConnection.refreshAuthentication when `_connectionState` is not `Connected`. The refresh flow needs a live transport to round-trip a new token request; calling it before the connection is fully established, or after it has dropped, is rejected up front rather than producing a confusing transport error.

Solutions

  1. Gate refreshAuthentication on the Connected state (check `hubConnection.state === 'Connected'`).
  2. Drive the refresh from the library's automatic refresh scheduling rather than calling it manually.
  3. Subscribe to onreconnected/onclose and disable manual refresh when not Connected.

Example fix

// before
await hubConnection.refreshAuthentication(); // may throw if disconnected
// after
if (hubConnection.state === HubConnectionState.Connected) {
  await hubConnection.refreshAuthentication();
}
Defensive patterns

Strategy: validation

Validate before calling

import { HubConnectionState } from "@microsoft/signalr";
function canRefresh(hub: { state: HubConnectionState }): boolean {
  return hub.state === HubConnectionState.Connected;
}

Type guard

function isConnected(state: HubConnectionState): boolean {
  return state === HubConnectionState.Connected;
}

Prevention

When it happens

Trigger: Invoking `await hubConnection.refreshAuthentication()` while the connection is Disconnected, Reconnecting, or Disconnecting — e.g. immediately after start() has not yet resolved, or after an onclose handler has fired.

Common situations: Calling refreshAuthentication from a token-expiry handler that fires asynchronously after the connection has already dropped, or wiring it to a timer that races the connection lifecycle.

Understand the failure class

Related errors


AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11). Data as JSON: /api/errors/e534a6921eaf09db. Report an issue: GitHub.

Appendix: source

Thrown at src/SignalR/clients/ts/signalr/src/HubConnection.ts:620

    }

    /** Registers a handler that will be invoked when the connection successfully reconnects.
     *
     * @param {Function} callback The handler that will be invoked when the connection successfully reconnects.
     */
    public onreconnected(callback: (connectionId?: string) => void): void {
        if (callback) {
            this._reconnectedCallbacks.push(callback);
        }
    }

    /** Refreshes the authentication state for this connection.
     *
     * @returns A Promise that resolves with the new server-reported token lifetime in seconds, or undefined when the server does not report one.
     */
    public async refreshAuthentication(): Promise<number | undefined> {
        if (this._connectionState !== HubConnectionState.Connected) {
            throw new Error("Cannot refresh authentication when the connection is not active.");
        }

        const authenticationRefreshFeature = this.connection.features.authenticationRefresh as IAuthenticationRefreshFeature | undefined;
        if (!authenticationRefreshFeature) {
            throw new Error("Authentication refresh is only supported with HTTP-based connections.");
        }

        let newTokenLifetimeInSeconds: number | undefined;
        try {
            newTokenLifetimeInSeconds = await authenticationRefreshFeature.refreshAuthentication();
        } catch (e) {
            await this._invokeAuthenticationRefreshFailed(e);
            throw e;
        }

        if (this._connectionState === HubConnectionState.Connected &&
            this.connection.features.authenticationRefresh === authenticationRefreshFeature &&
            this._isAutoAuthenticationRefreshEnabled() &&

View on GitHub (pinned to 3600ca084e)