logoalt Hacker News

hvb2yesterday at 8:10 PM1 replyview on HN

One time use of refresh tokens is really common? Where each refresh will get you a new access token AND a new refresh token?

That's standard in oidc I believe


Replies

mooredsyesterday at 8:25 PM

I don't have data on whether it is common, but I know a few OAuth vendors support it.