Under the hood
Presence heartbeats are skipped for non-first-party auth and retried once after a 401 credential refresh.
The client presence heartbeat now checks whether the auth provider is first-party before sending a pulse, skipping it otherwise. On a 401 response, it retries once after attempting a credential refresh via onUnauthorized.