> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # CredentialRefreshFallbackWarning > Emitted when the SDK falls back to the developer-provided refresh. Emitted when the SDK falls back to the developer-provided [`CredentialProvider.refresh`](/docs/browser-sdk/v4/reference/interfaces/credential-provider) because the Client Bound SAT path could not take over. Common causes: * The minted SAT lacks `sat:refresh` scope (`reason: 'no-scope'`). * The `/devices/token` exchange failed transiently (`reason: 'endpoint-failed'`; see [`DeviceTokenError`](/docs/browser-sdk/v4/reference/errors/device-token-error)). Subscribe via [`client.warnings$`](/docs/browser-sdk/v4/reference/signalwire/warnings\$) to detect: * SDKs running with plain SATs that rely on developer-managed refresh * Deployments expected to use bound tokens that silently downgraded to bearer (a security-relevant signal for fleet observability) ## **Properties** **`code`** `"credential_refresh_fallback"` — required Discriminant identifying this warning. --- **`source`** `"CredentialProvider"` — required The SDK subsystem that emitted the warning. --- **`reason`** `CredentialRefreshFallbackReason` — required Why the fallback occurred. See [`CredentialRefreshFallbackReason`](/docs/browser-sdk/v4/reference/type-aliases/credential-refresh-fallback-reason). --- **`message`** `string` — required Human-readable description of the fallback. --- > Emitted when the SDK falls back to the developer-provided refresh.