Question

Recovering from invalid refresh tokens

  • 4 April 2024
  • 1 reply
  • 16 views

Badge

On making a refresh token request, a new refresh token is generated and the old refresh token is invalidated. If the new refresh token is somehow lost, there’s no way to recover. Is it possible to make the old refresh token stay valid for a grace period after it is used in making a refresh token call? 


1 reply

Userlevel 6
Badge +1

Hi there @Shaan Vaidya — to my knowledge, this is not currently possible. I’m CCing @BridgetFinegan for any additional context here.

Reply