Why Does OAuth v2 Have Both Access and Refresh Tokens?

后端 未结 14 2327
情话喂你
情话喂你 2020-11-22 12:36

Section 4.2 of the draft OAuth 2.0 protocol indicates that an authorization server can return both an access_token (which is used to authenticate oneself with a

14条回答
  •  渐次进展
    2020-11-22 13:08

    To further simplify B T's answer: Use refresh tokens when you don't typically want the user to have to type in credentials again, but still want the power to be able to revoke the permissions (by revoking the refresh token)

    You cannot revoke an access token, only a refresh token.

提交回复
热议问题