Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If Apollo Client keeps showing the previous tenant’s data after an account switch, the likely issue is that the same client still has cached results from the prior identity. Apollo recommends clearing cached results when login state changes. For permission-sensitive data, client.resetStore() clears the cache and refetches active queries; client.clearStore() clears it without refetching.

Why can Apollo Client show the previous tenant’s data?

Apollo Client stores query results in a local normalized cache and can serve a read from that cache rather than make a network request. That behavior makes repeat reads faster, but it can produce stale UI if a client instance survives a tenant or account switch: a component may render data fetched under the previous identity before new requests have replaced it. Apollo documents the cache behavior and separately advises clearing results when login state changes; this is a plausible failure mode inferred from that guidance, not evidence of an Apollo tenant-isolation defect or a verified production incident. Apollo Client caching overview Apollo authentication guidance

Should you call resetStore or clearStore after login?

Choose based on whether mounted, active queries should run again immediately under the current identity. Apollo’s authentication guidance recommends resetStore() after a login or logout transition when cached results may reflect different permissions.

Method What happens When it fits
client.resetStore() Clears the store and refetches active queries. Use when active queries should reload against the current identity after the transition.
client.clearStore() Clears the store without refetching active queries. Use when queries should not run immediately; the application must decide when they resume and under which identity.

These methods manage client-side cached state; they do not choose a universal tenant-switch sequence for every application. Account for the identity transition and any outstanding requests in the app’s own flow. Apollo authentication guidance ApolloClient API reference

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should a tenant switch be handled?

  1. Complete the identity transition. Ensure the application has moved to the new login state before refetching identity-sensitive data.
  2. Clear results from the prior identity. Use client.resetStore() when active queries should refetch, or client.clearStore() when they should remain idle until the application resumes them.
  3. Resume queries only for the intended identity. The timing of outstanding requests and query resumption is application-specific; Apollo’s cited guidance does not specify one sequence for every tenant-switch implementation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does clearing Apollo’s cache provide tenant security?

No. Cache clearing helps prevent stale client state from being reused or rendered in the browser, but authorization must be enforced by the server. Apollo Server’s security guide describes deriving authenticated user information for each request and using request context to make authorization decisions about resolver results. A client-side reset is not a substitute for those checks. Apollo Server authentication and authorization

What if the wrong data remains visible?

  • Check the transition path. Confirm the cache-clearing call occurs after login state changes and before the application treats old results as belonging to the new tenant.
  • Check query activity. resetStore() refetches active queries; clearStore() does not. Verify that the chosen behavior matches whether mounted components should reload immediately.
  • Check server authorization separately. Confirm each request is authorized for the identity that made it; a clean client cache cannot correct an authorization error.
  • Review cache identity rules if records can overlap. Apollo supports configuring cache identifiers and field policies, but cache configuration does not replace clearing permission-sensitive results when identity changes. Apollo cache configuration

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.