A refresh token in Auth0 never expires. If someone finds one left over from another user, that someone can get a new auth token no matter how long it\'s been. That\'s not okay.