NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev
A thin, testable layer over Dio for Flutter apps - bearer-token auth, automatic token refresh with retry, secure token storage, and friendly error handling.
Last release today
07 Oct 2026
Too new to tell
only 2 release windows
Most releases are documented
notes for 6 of 7 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
7 releases · first in 2023
One column per quarter.
A rewrite focused on making token auth actually work and the package easy to test and use. Breaking changes are listed at the bottom - most apps only…
A rewrite focused on making token auth actually work and the package easy to test and use.
Breaking changes are listed at the bottom - most apps only need the RefreshTokenProvider change.
RefreshTokenProvider was never called, and the interceptor reacted to status 360
instead of 401. Failed requests are replayed with the new token, keeping method, body, query and cancel token.delete() now honours the cancelToken you pass (it was replaced by a fresh one).onRefresh() no longer hangs forever; it fails with the 401.Dio you pass in keeps its own timeouts and response type instead of being overwritten.dart:io import.get/post/... return a properly typed Response<T> instead of an unchecked cast.hasAuthToken() on start-up no longer makes every request fail.authTokenListenable - react to sign-in, refresh and sign-out (go_router's refreshListenable,
ValueListenableBuilder).RefreshTokenProvider.from(() async => ...) - no subclass needed.authHeader / authScheme - send Token abc, X-Api-Key: abc, etc. instead of Authorization: Bearer abc.ApiErrorMessages - translate the userMessage texts (ApiErrorMessages.current = ... or userMessageWith(...)),
or turn off server messages with preferServerMessage: false.serverMessage also understands OAuth (error_description), JSON:API / GraphQL errors arrays,
Laravel/Rails field errors and FastAPI detail[].msg; HTML error pages are ignored.isBadRequest, isConflict, isRateLimited (with a friendly 429 message), isClientError.TokenStorage (+ SecureTokenStorage, MemoryTokenStorage) - plug in your own storage or fake it in tests.ApiProvider options: headers, connectTimeout/sendTimeout/receiveTimeout, enableLogging, interceptors,
refreshOnStatusCodes, onUnauthorized, and your own dio instance.skipAuth() to mark public endpoints (login, register) without touching extra by hand.DioException helpers: userMessage, serverMessage, statusCode, isUnauthorized, isTimeout,
isNetworkError, isCancelled, isMissingToken, ...ApiProvider.authToken, isAuthenticated, dio, head(), download(), close().MissingAuthTokenException instead of the string 'Invalid Auth Object'.Options, CancelToken, DioException, FormData, interceptor and
handler types, HttpClientAdapter/ResponseBody for tests, ...) - no separate dio import needed.llms.txt - an AI-readable usage guide, so coding assistants integrate the package correctly.AuthManager is no longer a global singleton - every ApiProvider has its own token.Dio the
package creates; pass connectTimeout etc. to override.dio ^5.9, flutter_secure_storage ^10, flutter_lints ^6).
flutter_secure_storage stays on 10.x on purpose: 11.x can't read data written by 9.x (what 1.x used), and 10.x
migrates it, so upgrading users stay signed in.RefreshTokenProvider.onRefresh() is now Future<String?> onRefresh() and must return the new token (or null).AuthManager's constructor is no longer a singleton factory; its methods were renamed
(persistInteractObj -> setToken, hasauthToken -> load, deleteauthToken -> clear, updateAuthToken -> replaceToken).
The ApiProvider methods (persistToken, hasAuthToken, deleteAuthToken, updateAuthToken) are unchanged.BaseProvider.name is optional; BaseApiClient no longer exposes a fixed Dio configuration.isSaved flag key is no longer written to secure storage. Tokens saved by 1.x are still read.Removing and handling old dart versions.
Nothing published for this version
Rethrowing Dio Exception for manual handling of exception according to your needs.
You can add your custom RefeshTokenProvider for refreshing token.
BaseProvider throws the error with error and cause.
Initial release for Api Provider many more to come.
Your coding agent can read these notes before it upgrades. Set up the MCP server →