Having a refresh token valid for a couple of years is definitely not a secure option. Can you tell me more about what part of our stack you use? Any docs , quickstarts? Thanks!
Related topics
Topic | Replies | Views | Activity | |
---|---|---|---|---|
Refresh token not generating id_token | 2 | 3721 | March 2, 2018 | |
Auth0.AuthenticationApi .NET - Using AuthenticationApiClient to refresh token | 5 | 6874 | March 2, 2018 | |
How to generate New Token from refresh Token? | 2 | 3484 | August 29, 2019 | |
Do refresh tokens from legacy /ro endpoint work with new /token endpoint? | 4 | 4544 | March 2, 2018 | |
Refresh-tokens should be handled more gracefully | 4 | 5215 | June 14, 2019 |